Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834
1.3 KiB
sbom-nexus
SBOM Nexus is the dedicated software-bill-of-materials service for the Coulomb fleet. It captures dependency evidence from repositories, keeps immutable snapshots, evaluates licence risk and freshness, and provides a bounded catch-up queue for automation.
The product direction is defined in INTENT.md. The first delivery contract is in ProductRequirementsDocument.md.
Development
uv sync --dev
uv run pytest
uv run ruff check src tests
uv run sbom-nexus serve --reload
The default API listens on http://127.0.0.1:8010. Local development uses
SQLite through SBOM_NEXUS_DATABASE_PATH; production uses
SBOM_NEXUS_DATABASE_URL_FILE=/var/run/secrets/.../url and make migrate.
The direct SBOM_NEXUS_DATABASE_URL variable remains available for disposable
development environments; mounted secret files are preferred for production.
Initial API surface
GET /state/healthPUT /repositories/{repo_slug}GET /sbom/catch-up?limit=3POST /sbom/{repo_slug}/ingest- State Hub-compatible
/sbom/snapshot, entry, repository, and licence routes
See docs/state-hub-sbom-extraction-review.md for the extraction inventory and cutover dispositions.