activity-core/workplans/ACTIVITY-WP-0034-sbom-controlled-source-reference.md
tegwick e6901705be
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 20s
feat: carry controlled SBOM source refs
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b22-9638-76d2-bbff-b7ea1770b118
2026-08-22 23:57:48 +02:00

1.5 KiB

id type title domain repo status owner topic_slug created updated quality_dor quality_dor_at quality_dor_by quality_dor_note parent_workplan related
ACTIVITY-WP-0034 workplan Freeze controlled SBOM source references across retries infotech activity-core active codex infotech 2026-08-22 2026-08-22 DoR-Ok 2026-08-22 codex CUST-WP-0064 selected a reviewable full-SHA source_ref contract; Nexus owns fetch/scan, Activity Core retains the existing bounded target and stable operation identity, and rollout waits on the new Nexus/package digest. CUST-WP-0064
SBOM-WP-0003
ACTIVITY-WP-0033

Freeze controlled SBOM source references across retries

Carry the immutable source reference

id: ACTIVITY-WP-0034-T01
status: done
priority: high

Validate and retain Nexus's forgejo-archive-v1 source reference in the ranked selection, send it on ingest, reuse it with the existing stable operation key, and report additive source failure outcomes without selecting a replacement target.

Completed in the resolver/apply adapter and daily definition with focused tests for normalization, POST payload, retry identity, and terminal reasons.

Promote after the Nexus dark canary

id: ACTIVITY-WP-0034-T02
status: wait
priority: high

After SBOM-WP-0003 and RAPP-SBOM-NEXUS-WP-0002 migrate and pass the attended one-repository canary, project this revision to Railiance, sync the existing schedule without widening its limit, and capture the first normal scheduled controlled-source result.