activity-core/workplans/ACTIVITY-WP-0034-sbom-controlled-source-reference.md
tegwick e6901705be
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 20s
feat: carry controlled SBOM source refs
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b22-9638-76d2-bbff-b7ea1770b118
2026-08-22 23:57:48 +02:00

51 lines
1.5 KiB
Markdown

---
id: ACTIVITY-WP-0034
type: workplan
title: "Freeze controlled SBOM source references across retries"
domain: infotech
repo: activity-core
status: active
owner: codex
topic_slug: infotech
created: "2026-08-22"
updated: "2026-08-22"
quality_dor: DoR-Ok
quality_dor_at: "2026-08-22"
quality_dor_by: codex
quality_dor_note: "CUST-WP-0064 selected a reviewable full-SHA source_ref contract; Nexus owns fetch/scan, Activity Core retains the existing bounded target and stable operation identity, and rollout waits on the new Nexus/package digest."
parent_workplan: CUST-WP-0064
related:
- SBOM-WP-0003
- ACTIVITY-WP-0033
---
# Freeze controlled SBOM source references across retries
## Carry the immutable source reference
```task
id: ACTIVITY-WP-0034-T01
status: done
priority: high
```
Validate and retain Nexus's `forgejo-archive-v1` source reference in the
ranked selection, send it on ingest, reuse it with the existing stable
operation key, and report additive source failure outcomes without selecting a
replacement target.
Completed in the resolver/apply adapter and daily definition with focused
tests for normalization, POST payload, retry identity, and terminal reasons.
## Promote after the Nexus dark canary
```task
id: ACTIVITY-WP-0034-T02
status: wait
priority: high
```
After `SBOM-WP-0003` and `RAPP-SBOM-NEXUS-WP-0002` migrate and pass the
attended one-repository canary, project this revision to Railiance, sync the
existing schedule without widening its limit, and capture the first normal
scheduled controlled-source result.