Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02b22-9638-76d2-bbff-b7ea1770b118
3.1 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | quality_dor | quality_dor_at | quality_dor_by | quality_dor_note | parent_workplan | related | state_hub_workstream_id | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SBOM-WP-0003 | workplan | Controlled Forgejo source ingestion and durable operation replay | infotech | sbom-nexus | active | codex | infotech | 2026-08-22 | 2026-08-22 | DoR-Ok | 2026-08-22 | codex | CUST-WP-0064 selected a full-SHA public Forgejo archive contract with bounded extraction, explicit provenance, owner handoffs, idempotency, failure semantics, acceptance evidence, and rollback. | CUST-WP-0064 |
|
dc07cc14-9a5d-568d-8e19-036661e52120 |
Controlled Forgejo source ingestion and durable operation replay
Implement durable operation receipts
id: SBOM-WP-0003-T01
status: done
priority: high
state_hub_task_id: "ad2b95fd-a7b1-5331-a8c3-1545fdb6db10"
Enforce supplied Idempotency-Key / X-Activity-Core-Operation-ID values on
repository ingest and skip. Persist a request fingerprint and snapshot link in
the same transaction, replay the original terminal outcome, and reject key
reuse for a different operation.
Completed with migration 0002, transactional operation receipts, early
replay before source work, request-conflict HTTP 409 behavior, and ingest/skip
tests proving one snapshot across duplicate requests.
Add controlled full-SHA source ingestion
id: SBOM-WP-0003-T02
status: done
priority: high
state_hub_task_id: "3a8734f2-c00e-584f-b5ff-f22370a5ce02"
Consume the forgejo-archive-v1 source reference selected in
the-custodian/docs/sbom-controlled-scan-input-contract-v1.md. Validate the
identity, stream and safely extract within fixed limits, pass the explicit
revision into the scanner, persist archive provenance, and always clean up.
Completed with strict Coulomb identity/full-SHA validation, same-host fetches, streaming compressed limits, safe regular-file-only extraction, one scan slot, subprocess scan timeout, explicit revision override, archive provenance, and temporary-directory cleanup. A real Forgejo archive scan produced 33 entries from one manifest with zero errors.
Extend repository projection and outcomes
id: SBOM-WP-0003-T03
status: done
priority: high
state_hub_task_id: "5be7b81e-0469-5d74-a28c-8802187a122a"
Store and return source references in repository/catch-up projections. Add
terminal source-unavailable and source-rejected outcomes without changing
oldest-N ranking or success-time semantics.
Completed in the repository projection, API model, storage schema, catch-up response, and additive skip handling. Legacy checkout scanning remains available for local/operator compatibility while the production flag is dark.
Prove package integration and production behavior
id: SBOM-WP-0003-T04
status: wait
priority: high
state_hub_task_id: "9c8a2b6c-2b99-5dd8-9c1c-b5ba4ad2367b"
Coordinate the schema migration, ephemeral volume, Forgejo-only egress, and
feature flag with rapp-sbom-nexus; then pass unit/integration tests and the
attended plus scheduled production proof owned by CUST-WP-0064.