Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a028de-e2c8-7732-8521-46a7fc5db82f
79 lines
2.7 KiB
Markdown
79 lines
2.7 KiB
Markdown
---
|
|
id: weekly-sbom-staleness
|
|
name: Weekly SBOM Staleness Check
|
|
enabled: false
|
|
owner: custodian-agent
|
|
governance: custodian
|
|
status: paused
|
|
trigger:
|
|
type: cron
|
|
cron_expression: "0 9 * * 1"
|
|
timezone: Europe/Berlin
|
|
misfire_policy: skip
|
|
context_sources:
|
|
- type: state-hub
|
|
query: repo_sbom_status
|
|
params:
|
|
repos: all
|
|
bind_to: context.repos
|
|
# Resolver returns a summary keyed off the worst repo so the rule expression
|
|
# below can match without comprehensions (the sandboxed evaluator does not
|
|
# support them). See _repo_sbom_status in context_resolvers/state_hub.py.
|
|
---
|
|
|
|
# Weekly SBOM Staleness Check
|
|
|
|
> **Emergency-paused 2026-08-20 (ACTIVITY-WP-0031).** The 2026-08-17 fire
|
|
> emitted 75 independent rescan tasks while the bounded replacement in
|
|
> ACTIVITY-WP-0030 is blocked on CUST-WP-0062. Keep this definition disabled in
|
|
> source and production. Its deterministic weekly summary is not sufficient
|
|
> reason to retain the unbounded `for_each` task fan-out.
|
|
|
|
When enabled, this runs every Monday at 09:00 Berlin time. It checks all
|
|
tracked repositories for SBOM staleness and flags any repository whose SBOM is
|
|
older than 30 days.
|
|
|
|
ACTIVITY-WP-0021: the fleet no longer treats Forgejo issues as the primary
|
|
landing zone for automated tasks. The deterministic **state-hub-progress**
|
|
instruction report below is the operator-visible evidence path. Task emission
|
|
via IssueSink remains optional and only fires when `ISSUE_SINK_TYPE` points at
|
|
a healthy sink (rest/state-hub); a broken Forgejo backend must not be required
|
|
for a green weekly completion.
|
|
|
|
```instruction
|
|
id: weekly-sbom-staleness-report
|
|
trusted_fields: []
|
|
model: deterministic
|
|
temperature: 0
|
|
max_tokens: 1
|
|
prompt: |
|
|
Deterministic SBOM staleness report from context.repos (no LLM).
|
|
output_schema: ""
|
|
review_advisory: false
|
|
report_sinks:
|
|
- type: state-hub-progress
|
|
event_type: sbom_staleness
|
|
author: activity-core
|
|
topic_id: cee7bedf-2b48-46ef-8601-006474f2ad7a
|
|
```
|
|
|
|
Task emission uses the fleet default sink (`ISSUE_SINK_TYPE=state-hub` —
|
|
ACTIVITY-WP-0022): stale repos spawn `activity_task_spawn` progress events,
|
|
not Forgejo issues. The deterministic instruction always posts a
|
|
`sbom_staleness` summary for operators.
|
|
|
|
```rule
|
|
id: flag-stale-sbom
|
|
for_each: context.repos.repos
|
|
bind_as: repo
|
|
condition: 'context.repo.sbom_age_days > 30'
|
|
action:
|
|
task_template: Run SBOM rescan for {context.repo.repo_slug}
|
|
target_repo: context.repo.repo_slug
|
|
priority: medium
|
|
labels: ["sbom", "security", "automated"]
|
|
```
|
|
|
|
The bulk resolver exposes the per-repo entries under `context.repos.repos`.
|
|
The deterministic instruction posts `sbom_staleness` progress with stale repo
|
|
counts and a sample list for operator review.
|