repo-manager/workplans/RMGR-WP-0011-sbom-nexus-production-client.md
tegwick f0200c0434 chore(registrar): assign State Hub identifiers
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 22:26:49 +02:00

3.3 KiB

id type title domain repo status owner topic_slug created updated parent_workplan related state_hub_workstream_id
RMGR-WP-0011 workplan SBOM Nexus production client and explicit preview semantics infotech repo-manager ready codex infotech 2026-08-22 2026-08-22 SBOM-WP-0002
CUST-WP-0062
RMGR-WP-0008
a6cd9248-e591-51fc-82b0-a0f3799c3939

SBOM Nexus production client and explicit preview semantics

Goal

Complete Repo Manager's caller cutover to SBOM Nexus without reintroducing a second SBOM product. Repo Manager retains repository identity, active status, and checkout-path authority; SBOM Nexus owns sbom-nexus.snapshot.v1, ingest outcomes, licence evaluation, freshness, and immutable history.

RMGR-WP-0008 already removed Repo Manager's duplicate scanner and changed the legacy commands into thin delegates to the Nexus CLI. This workplan addresses the remaining production boundary: distinguish a persisted Nexus operation from a local, non-authoritative preview and provide a configured service client for callers that require authoritative state.

Pin the consumer contract

id: RMGR-WP-0011-T01
status: todo
priority: high
state_hub_task_id: "b3b0f4d9-de14-5429-bc4d-a14d014491b0"

Document and test the consumed sbom-nexus.snapshot.v1 fields and the authoritative service routes. Treat additive fields as compatible, reject an unknown schema, and do not couple Repo Manager to Nexus database tables or migration internals.

Add the authoritative Nexus service client

id: RMGR-WP-0011-T02
status: todo
priority: high
state_hub_task_id: "280cfa84-1561-5cb9-8943-aa0775c57be6"

Provide an explicitly configured HTTP client for the Nexus repository projection, ingest, latest-snapshot, and licence-report surfaces needed by Repo Manager. Preserve bounded timeouts and actionable failures; credentials, when introduced through the platform path, must never enter files, output, or logs.

Make local scanning an explicit preview

id: RMGR-WP-0011-T03
status: todo
priority: high
state_hub_task_id: "5cd717de-d696-5676-9abe-f1a701e48e7e"

Keep repository-source scanning usable through the Nexus-owned CLI when the service is unavailable, but mark the result unambiguously as local, non-authoritative, and not persisted. The compatibility aliases must not imply that a preview advanced last_attempt_at, last_success_at, or snapshot history.

Prove cutover and remove ambiguity

id: RMGR-WP-0011-T04
status: todo
priority: medium
state_hub_task_id: "81fed060-3431-5d9b-819b-fcc7d629c364"

Add contract, failure, and CLI compatibility tests; update operator docs; and prove by source inspection that Repo Manager has no scanner implementation, snapshot store, freshness evaluation, catch-up policy, or licence classifier. Capture the exact production handoff evidence required by SBOM-WP-0002.

Acceptance

  • Authoritative mode talks to SBOM Nexus and returns its pinned snapshot contract without local persistence.
  • Preview mode is visibly non-authoritative and cannot be mistaken for an ingest receipt.
  • Existing rmgr sbom scan|licence-report users receive a documented migration path and deterministic errors.
  • Repo Manager remains authoritative only for repository identity and paths; SBOM Nexus remains the sole durable SBOM owner.