activity-core/activity-definitions/weekly-sbom-staleness.md
tegwick 26934e25b9
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 21s
Enforce bounded operation guardrails
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a028de-e2c8-7732-8521-46a7fc5db82f
2026-08-23 12:31:13 +02:00

79 lines
2.7 KiB
Markdown

---
id: weekly-sbom-staleness
name: Weekly SBOM Staleness Check
enabled: false
owner: custodian-agent
governance: custodian
status: paused
trigger:
type: cron
cron_expression: "0 9 * * 1"
timezone: Europe/Berlin
misfire_policy: skip
context_sources:
- type: state-hub
query: repo_sbom_status
params:
repos: all
bind_to: context.repos
# Resolver returns a summary keyed off the worst repo so the rule expression
# below can match without comprehensions (the sandboxed evaluator does not
# support them). See _repo_sbom_status in context_resolvers/state_hub.py.
---
# Weekly SBOM Staleness Check
> **Emergency-paused 2026-08-20 (ACTIVITY-WP-0031).** The 2026-08-17 fire
> emitted 75 independent rescan tasks while the bounded replacement in
> ACTIVITY-WP-0030 is blocked on CUST-WP-0062. Keep this definition disabled in
> source and production. Its deterministic weekly summary is not sufficient
> reason to retain the unbounded `for_each` task fan-out.
When enabled, this runs every Monday at 09:00 Berlin time. It checks all
tracked repositories for SBOM staleness and flags any repository whose SBOM is
older than 30 days.
ACTIVITY-WP-0021: the fleet no longer treats Forgejo issues as the primary
landing zone for automated tasks. The deterministic **state-hub-progress**
instruction report below is the operator-visible evidence path. Task emission
via IssueSink remains optional and only fires when `ISSUE_SINK_TYPE` points at
a healthy sink (rest/state-hub); a broken Forgejo backend must not be required
for a green weekly completion.
```instruction
id: weekly-sbom-staleness-report
trusted_fields: []
model: deterministic
temperature: 0
max_tokens: 1
prompt: |
Deterministic SBOM staleness report from context.repos (no LLM).
output_schema: ""
review_advisory: false
report_sinks:
- type: state-hub-progress
event_type: sbom_staleness
author: activity-core
topic_id: cee7bedf-2b48-46ef-8601-006474f2ad7a
```
Task emission uses the fleet default sink (`ISSUE_SINK_TYPE=state-hub`
ACTIVITY-WP-0022): stale repos spawn `activity_task_spawn` progress events,
not Forgejo issues. The deterministic instruction always posts a
`sbom_staleness` summary for operators.
```rule
id: flag-stale-sbom
for_each: context.repos.repos
bind_as: repo
condition: 'context.repo.sbom_age_days > 30'
action:
task_template: Run SBOM rescan for {context.repo.repo_slug}
target_repo: context.repo.repo_slug
priority: medium
labels: ["sbom", "security", "automated"]
```
The bulk resolver exposes the per-repo entries under `context.repos.repos`.
The deterministic instruction posts `sbom_staleness` progress with stale repo
counts and a sample list for operator review.