feat(sbom): project immutable Forgejo source refs
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
This commit is contained in:
parent
b068e9da42
commit
e6cc18bf18
6 changed files with 543 additions and 3 deletions
|
|
@ -126,6 +126,23 @@ commit uncertainty, idempotency headers, and revision mismatch. Remaining is
|
|||
the production consumer handoff and final source/ownership inspection after the
|
||||
controlled source-input topology is available.
|
||||
|
||||
**Controlled-source projection (2026-08-22):** Custodian decision
|
||||
`c67833d0-62a9-4d14-9d74-4693cc0c497d` selected the
|
||||
`forgejo-archive-v1` contract. `rmgr sbom source-ref` now normalizes only the
|
||||
canonical public `coulomb/<slug>` Forgejo identity, observes the default branch
|
||||
and full SHA through the anonymous Forgejo API, records `observed_ref` and
|
||||
canonical UTC `observed_at`, and returns no source reference for missing,
|
||||
private, non-Coulomb, mismatched, or unresolvable sources. Local `HEAD` and
|
||||
workstation paths never supply the production revision.
|
||||
|
||||
The explicit `--project --confirm-authoritative` path submits
|
||||
`checkout_path: null` and the structured reference through the T02 client.
|
||||
Projection passes only when Nexus echoes the exact reference, so the current
|
||||
pre-contract service cannot silently discard it. Live read-only proof resolved
|
||||
`coulomb/repo-manager@b068e9da421332f99eaa24a811887f9a5d85a478` from
|
||||
`refs/heads/main`. Remaining T04 work is the Nexus/package/Activity Core
|
||||
implementation and attended production proof owned through `CUST-WP-0064`.
|
||||
|
||||
## Acceptance
|
||||
|
||||
- Authoritative mode talks to SBOM Nexus and returns its pinned snapshot
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue