docs: close SBOM-WP-0002 T05

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834
This commit is contained in:
tegwick 2026-08-22 20:24:06 +02:00
parent 6bab4fca9a
commit 4b497d9e7b
2 changed files with 43 additions and 1 deletions

View file

@ -0,0 +1,35 @@
# SBOM-WP-0002 T05 — Repo Manager scanner handoff evidence
Date: 2026-08-22
Repo Manager commit `ad0ba6f` removes its duplicate SBOM scanner and leaves
SBOM Nexus as the single scanner/snapshot product owner.
Changes:
- deleted `src/repo_manager/sbom.py` (326 lines of parser, source detection,
licence triage, and snapshot rendering);
- replaced parser-specific tests with compatibility-delegation tests;
- retained `rmgr sbom scan` and `rmgr sbom licence-report` as thin aliases;
- invokes `sbom-nexus` directly with `shell=False`, discovered on `PATH` or via
`SBOM_NEXUS_CLI`;
- preserved scan output-file refusal and `--force` behavior;
- pinned authority in JSON with `schema=sbom-nexus.snapshot.v1`,
`product_owner=sbom-nexus`, and `delegated_by=repo-manager`;
- corrected Repo Manager's earlier interim-scanner workplan/evidence and placed
the direct `sbom-nexus scan` command first in operator documentation.
Verification:
- Repo Manager Ruff: passed;
- Repo Manager complete test suite: 87 passed;
- real `rmgr sbom scan` delegation: 39 entries, Git revision present, no errors;
- real `rmgr sbom licence-report` without an environment override: 39 entries,
copyleft direct count 0, no errors;
- the local SBOM Nexus package was installed as an operator tool so the
compatibility aliases work on the default PATH.
Repo Manager retains file-backed `sbom-inventory` register representation as a
repository concern, but it no longer evaluates sources or owns product
snapshots. Detailed owner-side evidence is in
`repo-manager/docs/evidence/RMGR-WP-0008-sbom-authority-handoff-2026-08-22.md`.

View file

@ -117,7 +117,7 @@ read or write rollback trigger a real pod rollout. See
```task ```task
id: SBOM-WP-0002-T05 id: SBOM-WP-0002-T05
status: todo status: done
priority: medium priority: medium
state_hub_task_id: "59f83f01-13bc-5a63-bb0b-bf527047762e" state_hub_task_id: "59f83f01-13bc-5a63-bb0b-bf527047762e"
``` ```
@ -125,6 +125,13 @@ state_hub_task_id: "59f83f01-13bc-5a63-bb0b-bf527047762e"
Depends on dark deployment. Preserve CLI usability while removing competing Depends on dark deployment. Preserve CLI usability while removing competing
SBOM product authority and pinning the Nexus contract. SBOM product authority and pinning the Nexus contract.
Completed: Repo Manager's 326-line duplicate scanner was removed. Its existing
`rmgr sbom scan|licence-report` commands are deprecated, shell-free delegates
to the installed `sbom-nexus` CLI, emit `sbom-nexus.snapshot.v1`, and identify
`product_owner=sbom-nexus`. The full Repo Manager suite passed (87 tests), lint
passed, and both aliases succeeded against the actual Nexus executable. See
`docs/evidence/SBOM-WP-0002-T05-repo-manager-handoff-2026-08-22.md`.
## Enable bounded Activity Core ingest ## Enable bounded Activity Core ingest
```task ```task