docs: close stale repo manager work
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
This commit is contained in:
parent
a2c9d7fbeb
commit
d63f8b27e7
7 changed files with 126 additions and 18 deletions
|
|
@ -4,12 +4,19 @@ type: workplan
|
|||
title: "SBOM Nexus production client and explicit preview semantics"
|
||||
domain: infotech
|
||||
repo: repo-manager
|
||||
status: active
|
||||
status: finished
|
||||
owner: codex
|
||||
topic_slug: infotech
|
||||
quality_dor: DoR-Ok
|
||||
created: "2026-08-22"
|
||||
updated: "2026-08-22"
|
||||
updated: "2026-08-31"
|
||||
quality_dod: DoD-Ok
|
||||
quality_dod_at: "2026-08-31"
|
||||
quality_dod_by: codex
|
||||
quality_dod_note: >-
|
||||
Contract, failure semantics, explicit preview mode, controlled source
|
||||
projection, and live authoritative Nexus reads are evidenced; durable SBOM
|
||||
ownership remains solely with SBOM Nexus.
|
||||
parent_workplan: SBOM-WP-0002
|
||||
related:
|
||||
- CUST-WP-0062
|
||||
|
|
@ -109,7 +116,7 @@ contract tests carry the same semantics.
|
|||
|
||||
```task
|
||||
id: RMGR-WP-0011-T04
|
||||
status: progress
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "81fed060-3431-5d9b-819b-fcc7d629c364"
|
||||
```
|
||||
|
|
@ -143,13 +150,23 @@ pre-contract service cannot silently discard it. Live read-only proof resolved
|
|||
`refs/heads/main`. Remaining T04 work is the Nexus/package/Activity Core
|
||||
implementation and attended production proof owned through `CUST-WP-0064`.
|
||||
|
||||
**Done 2026-08-31.** `CUST-WP-0064` is finished and production Nexus is
|
||||
healthy on the controlled-source implementation. Repo Manager's own
|
||||
`source-ref --project --confirm-authoritative` command resolved the exact
|
||||
Forgejo `main` revision, projected it with `checkout_path: null`, and received
|
||||
the identical source reference from Nexus. Its production client also consumed
|
||||
the latest-snapshot and licence-report routes with explicit
|
||||
`authoritative-service` context. Source inspection confirms Repo Manager holds
|
||||
no scanner, snapshot store, freshness/catch-up policy, or licence classifier.
|
||||
Evidence: `docs/evidence/RMGR-WP-0011-production-client-proof-2026-08-31.md`.
|
||||
|
||||
## Acceptance
|
||||
|
||||
- Authoritative mode talks to SBOM Nexus and returns its pinned snapshot
|
||||
- [x] Authoritative mode talks to SBOM Nexus and returns its pinned snapshot
|
||||
contract without local persistence.
|
||||
- Preview mode is visibly non-authoritative and cannot be mistaken for an
|
||||
- [x] Preview mode is visibly non-authoritative and cannot be mistaken for an
|
||||
ingest receipt.
|
||||
- Existing `rmgr sbom scan|licence-report` users receive a documented migration
|
||||
- [x] Existing `rmgr sbom scan|licence-report` users receive a documented migration
|
||||
path and deterministic errors.
|
||||
- Repo Manager remains authoritative only for repository identity and paths;
|
||||
- [x] Repo Manager remains authoritative only for repository identity and paths;
|
||||
SBOM Nexus remains the sole durable SBOM owner.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue