docs: close SBOM-WP-0002 T05

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834
This commit is contained in:
tegwick 2026-08-22 20:24:06 +02:00
parent 6bab4fca9a
commit 4b497d9e7b
2 changed files with 43 additions and 1 deletions

View file

@ -117,7 +117,7 @@ read or write rollback trigger a real pod rollout. See
```task
id: SBOM-WP-0002-T05
status: todo
status: done
priority: medium
state_hub_task_id: "59f83f01-13bc-5a63-bb0b-bf527047762e"
```
@ -125,6 +125,13 @@ state_hub_task_id: "59f83f01-13bc-5a63-bb0b-bf527047762e"
Depends on dark deployment. Preserve CLI usability while removing competing
SBOM product authority and pinning the Nexus contract.
Completed: Repo Manager's 326-line duplicate scanner was removed. Its existing
`rmgr sbom scan|licence-report` commands are deprecated, shell-free delegates
to the installed `sbom-nexus` CLI, emit `sbom-nexus.snapshot.v1`, and identify
`product_owner=sbom-nexus`. The full Repo Manager suite passed (87 tests), lint
passed, and both aliases succeeded against the actual Nexus executable. See
`docs/evidence/SBOM-WP-0002-T05-repo-manager-handoff-2026-08-22.md`.
## Enable bounded Activity Core ingest
```task