feat(sbom): project immutable Forgejo source refs

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
This commit is contained in:
tegwick 2026-08-22 23:34:01 +02:00
parent b068e9da42
commit e6cc18bf18
6 changed files with 543 additions and 3 deletions

View file

@ -126,6 +126,23 @@ commit uncertainty, idempotency headers, and revision mismatch. Remaining is
the production consumer handoff and final source/ownership inspection after the
controlled source-input topology is available.
**Controlled-source projection (2026-08-22):** Custodian decision
`c67833d0-62a9-4d14-9d74-4693cc0c497d` selected the
`forgejo-archive-v1` contract. `rmgr sbom source-ref` now normalizes only the
canonical public `coulomb/<slug>` Forgejo identity, observes the default branch
and full SHA through the anonymous Forgejo API, records `observed_ref` and
canonical UTC `observed_at`, and returns no source reference for missing,
private, non-Coulomb, mismatched, or unresolvable sources. Local `HEAD` and
workstation paths never supply the production revision.
The explicit `--project --confirm-authoritative` path submits
`checkout_path: null` and the structured reference through the T02 client.
Projection passes only when Nexus echoes the exact reference, so the current
pre-contract service cannot silently discard it. Live read-only proof resolved
`coulomb/repo-manager@b068e9da421332f99eaa24a811887f9a5d85a478` from
`refs/heads/main`. Remaining T04 work is the Nexus/package/Activity Core
implementation and attended production proof owned through `CUST-WP-0064`.
## Acceptance
- Authoritative mode talks to SBOM Nexus and returns its pinned snapshot