|
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 1m9s
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834 |
||
|---|---|---|
| .claude/rules | ||
| .forgejo/workflows | ||
| docs | ||
| migrations | ||
| registry | ||
| scripts | ||
| src/sbom_nexus | ||
| tests | ||
| workplans | ||
| .custodian-brief.md | ||
| .dockerignore | ||
| .gitignore | ||
| .repo-classification.yaml | ||
| AGENTS.md | ||
| alembic.ini | ||
| CLAUDE.md | ||
| Containerfile | ||
| INTENT.md | ||
| LICENSE | ||
| Makefile | ||
| ProductRequirementsDocument.md | ||
| pyproject.toml | ||
| README.md | ||
| SCOPE.md | ||
| uv.lock | ||
| WORK-RECORDS.md | ||
sbom-nexus
SBOM Nexus is the dedicated software-bill-of-materials service for the Coulomb fleet. It captures dependency evidence from repositories, keeps immutable snapshots, evaluates licence risk and freshness, and provides a bounded catch-up queue for automation.
The product direction is defined in INTENT.md. The first delivery contract is in ProductRequirementsDocument.md.
Development
uv sync --dev
uv run pytest
uv run ruff check src tests
uv run sbom-nexus serve --reload
The default API listens on http://127.0.0.1:8010. Local development uses
SQLite through SBOM_NEXUS_DATABASE_PATH; production uses
SBOM_NEXUS_DATABASE_URL_FILE=/var/run/secrets/.../url and make migrate.
The direct SBOM_NEXUS_DATABASE_URL variable remains available for disposable
development environments; mounted secret files are preferred for production.
Initial API surface
GET /state/healthPUT /repositories/{repo_slug}GET /sbom/catch-up?limit=3POST /sbom/{repo_slug}/ingest- State Hub-compatible
/sbom/snapshot, entry, repository, and licence routes
See docs/state-hub-sbom-extraction-review.md for the extraction inventory and cutover dispositions.