feat: add controlled source ingestion and replay
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 38s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 38s
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02b22-9638-76d2-bbff-b7ea1770b118
This commit is contained in:
parent
b95fba9a9f
commit
879012c776
16 changed files with 1156 additions and 154 deletions
87
workplans/SBOM-WP-0003-controlled-source-and-replay.md
Normal file
87
workplans/SBOM-WP-0003-controlled-source-and-replay.md
Normal file
|
|
@ -0,0 +1,87 @@
|
|||
---
|
||||
id: SBOM-WP-0003
|
||||
type: workplan
|
||||
title: "Controlled Forgejo source ingestion and durable operation replay"
|
||||
domain: infotech
|
||||
repo: sbom-nexus
|
||||
status: active
|
||||
owner: codex
|
||||
topic_slug: infotech
|
||||
created: "2026-08-22"
|
||||
updated: "2026-08-22"
|
||||
quality_dor: DoR-Ok
|
||||
quality_dor_at: "2026-08-22"
|
||||
quality_dor_by: codex
|
||||
quality_dor_note: "CUST-WP-0064 selected a full-SHA public Forgejo archive contract with bounded extraction, explicit provenance, owner handoffs, idempotency, failure semantics, acceptance evidence, and rollback."
|
||||
parent_workplan: CUST-WP-0064
|
||||
related:
|
||||
- CUST-IN-0013
|
||||
- ACTIVITY-WP-0033
|
||||
- RMGR-WP-0011
|
||||
---
|
||||
|
||||
# Controlled Forgejo source ingestion and durable operation replay
|
||||
|
||||
## Implement durable operation receipts
|
||||
|
||||
```task
|
||||
id: SBOM-WP-0003-T01
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
Enforce supplied `Idempotency-Key` / `X-Activity-Core-Operation-ID` values on
|
||||
repository ingest and skip. Persist a request fingerprint and snapshot link in
|
||||
the same transaction, replay the original terminal outcome, and reject key
|
||||
reuse for a different operation.
|
||||
|
||||
Completed with migration `0002`, transactional operation receipts, early
|
||||
replay before source work, request-conflict HTTP 409 behavior, and ingest/skip
|
||||
tests proving one snapshot across duplicate requests.
|
||||
|
||||
## Add controlled full-SHA source ingestion
|
||||
|
||||
```task
|
||||
id: SBOM-WP-0003-T02
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
Consume the `forgejo-archive-v1` source reference selected in
|
||||
`the-custodian/docs/sbom-controlled-scan-input-contract-v1.md`. Validate the
|
||||
identity, stream and safely extract within fixed limits, pass the explicit
|
||||
revision into the scanner, persist archive provenance, and always clean up.
|
||||
|
||||
Completed with strict Coulomb identity/full-SHA validation, same-host fetches,
|
||||
streaming compressed limits, safe regular-file-only extraction, one scan slot,
|
||||
subprocess scan timeout, explicit revision override, archive provenance, and
|
||||
temporary-directory cleanup. A real Forgejo archive scan produced 33 entries
|
||||
from one manifest with zero errors.
|
||||
|
||||
## Extend repository projection and outcomes
|
||||
|
||||
```task
|
||||
id: SBOM-WP-0003-T03
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
Store and return source references in repository/catch-up projections. Add
|
||||
terminal `source-unavailable` and `source-rejected` outcomes without changing
|
||||
oldest-N ranking or success-time semantics.
|
||||
|
||||
Completed in the repository projection, API model, storage schema, catch-up
|
||||
response, and additive skip handling. Legacy checkout scanning remains
|
||||
available for local/operator compatibility while the production flag is dark.
|
||||
|
||||
## Prove package integration and production behavior
|
||||
|
||||
```task
|
||||
id: SBOM-WP-0003-T04
|
||||
status: wait
|
||||
priority: high
|
||||
```
|
||||
|
||||
Coordinate the schema migration, ephemeral volume, Forgejo-only egress, and
|
||||
feature flag with `rapp-sbom-nexus`; then pass unit/integration tests and the
|
||||
attended plus scheduled production proof owned by CUST-WP-0064.
|
||||
Loading…
Add table
Add a link
Reference in a new issue