2.7 KiB
| id | name | enabled | owner | governance | status | trigger | context_sources | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| weekly-sbom-staleness | Weekly SBOM Staleness Check | false | custodian-agent | custodian | paused |
|
|
Weekly SBOM Staleness Check
Emergency-paused 2026-08-20 (ACTIVITY-WP-0031). The 2026-08-17 fire emitted 75 independent rescan tasks while the bounded replacement in ACTIVITY-WP-0030 is blocked on CUST-WP-0062. Keep this definition disabled in source and production. Its deterministic weekly summary is not sufficient reason to retain the unbounded
for_eachtask fan-out.
When enabled, this runs every Monday at 09:00 Berlin time. It checks all tracked repositories for SBOM staleness and flags any repository whose SBOM is older than 30 days.
ACTIVITY-WP-0021: the fleet no longer treats Forgejo issues as the primary
landing zone for automated tasks. The deterministic state-hub-progress
instruction report below is the operator-visible evidence path. Task emission
via IssueSink remains optional and only fires when ISSUE_SINK_TYPE points at
a healthy sink (rest/state-hub); a broken Forgejo backend must not be required
for a green weekly completion.
id: weekly-sbom-staleness-report
trusted_fields: []
model: deterministic
temperature: 0
max_tokens: 1
prompt: |
Deterministic SBOM staleness report from context.repos (no LLM).
output_schema: ""
review_required: false
report_sinks:
- type: state-hub-progress
event_type: sbom_staleness
author: activity-core
topic_id: cee7bedf-2b48-46ef-8601-006474f2ad7a
Task emission uses the fleet default sink (ISSUE_SINK_TYPE=state-hub —
ACTIVITY-WP-0022): stale repos spawn activity_task_spawn progress events,
not Forgejo issues. The deterministic instruction always posts a
sbom_staleness summary for operators.
id: flag-stale-sbom
for_each: context.repos.repos
bind_as: repo
condition: 'context.repo.sbom_age_days > 30'
action:
task_template: Run SBOM rescan for {context.repo.repo_slug}
target_repo: context.repo.repo_slug
priority: medium
labels: ["sbom", "security", "automated"]
The bulk resolver exposes the per-repo entries under context.repos.repos.
The deterministic instruction posts sbom_staleness progress with stale repo
counts and a sample list for operator review.