feat(state-hub): v0.3 schema — contributions + sbom_entries migrations, models, schemas, routers
Migrations (chain: b1c2d3e4f5a6 → c2d3e4f5a6b7 → d3e4f5a6b7c8):
- c2d3e4f5a6b7: contributions table (contributiontype BR/FR/EP/UPR enum,
contributionstatus 7-state lifecycle, FKs to topics/workstreams)
- d3e4f5a6b7c8: sbom_entries table (ecosystem enum, snapshot-based replacement),
+ sbom_source + last_sbom_at columns on managed_repos
New models: Contribution (ContributionType, ContributionStatus), SBOMEntry (Ecosystem)
Modified: ManagedRepo (sbom_source, last_sbom_at columns)
New routers:
- /contributions/ — CRUD + lifecycle-guarded PATCH /status + soft-delete (withdrawn)
- /sbom/ — ingest (replace snapshot), list, per-repo view, licence report
Modified:
- /state/summary now includes contribution_counts and licence_risk_count
- main.py: registers contributions + sbom routers; bumps version to 0.6.0
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-02-28 17:28:27 +01:00
|
|
|
import enum
|
|
|
|
|
import uuid
|
|
|
|
|
from datetime import datetime
|
|
|
|
|
|
|
|
|
|
from sqlalchemy import Boolean, DateTime, Enum, ForeignKey, String
|
|
|
|
|
from sqlalchemy.dialects.postgresql import UUID
|
|
|
|
|
from sqlalchemy.orm import Mapped, mapped_column, relationship
|
|
|
|
|
|
|
|
|
|
from api.models.base import Base, new_uuid
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
class Ecosystem(str, enum.Enum):
|
|
|
|
|
python = "python"
|
|
|
|
|
node = "node"
|
|
|
|
|
rust = "rust"
|
|
|
|
|
go = "go"
|
|
|
|
|
java = "java"
|
2026-03-12 04:40:26 +01:00
|
|
|
terraform = "terraform"
|
|
|
|
|
ansible = "ansible"
|
|
|
|
|
tool = "tool"
|
feat(state-hub): v0.3 schema — contributions + sbom_entries migrations, models, schemas, routers
Migrations (chain: b1c2d3e4f5a6 → c2d3e4f5a6b7 → d3e4f5a6b7c8):
- c2d3e4f5a6b7: contributions table (contributiontype BR/FR/EP/UPR enum,
contributionstatus 7-state lifecycle, FKs to topics/workstreams)
- d3e4f5a6b7c8: sbom_entries table (ecosystem enum, snapshot-based replacement),
+ sbom_source + last_sbom_at columns on managed_repos
New models: Contribution (ContributionType, ContributionStatus), SBOMEntry (Ecosystem)
Modified: ManagedRepo (sbom_source, last_sbom_at columns)
New routers:
- /contributions/ — CRUD + lifecycle-guarded PATCH /status + soft-delete (withdrawn)
- /sbom/ — ingest (replace snapshot), list, per-repo view, licence report
Modified:
- /state/summary now includes contribution_counts and licence_risk_count
- main.py: registers contributions + sbom routers; bumps version to 0.6.0
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-02-28 17:28:27 +01:00
|
|
|
other = "other"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
class SBOMEntry(Base):
|
|
|
|
|
"""Snapshot-based SBOM entry — no updated_at; new ingest replaces old rows."""
|
|
|
|
|
__tablename__ = "sbom_entries"
|
|
|
|
|
|
|
|
|
|
id: Mapped[uuid.UUID] = mapped_column(
|
|
|
|
|
UUID(as_uuid=True), primary_key=True, default=new_uuid
|
|
|
|
|
)
|
|
|
|
|
repo_id: Mapped[uuid.UUID] = mapped_column(
|
|
|
|
|
UUID(as_uuid=True), ForeignKey("managed_repos.id", ondelete="RESTRICT"),
|
|
|
|
|
nullable=False, index=True,
|
|
|
|
|
)
|
|
|
|
|
package_name: Mapped[str] = mapped_column(String(300), nullable=False)
|
|
|
|
|
package_version: Mapped[str | None] = mapped_column(String(100), nullable=True)
|
|
|
|
|
ecosystem: Mapped[Ecosystem] = mapped_column(
|
|
|
|
|
Enum(Ecosystem, name="ecosystem"), nullable=False
|
|
|
|
|
)
|
|
|
|
|
license_spdx: Mapped[str | None] = mapped_column(String(100), nullable=True)
|
|
|
|
|
is_direct: Mapped[bool] = mapped_column(Boolean, nullable=False, default=True)
|
|
|
|
|
is_dev: Mapped[bool] = mapped_column(Boolean, nullable=False, default=False)
|
2026-03-02 23:39:17 +01:00
|
|
|
snapshot_id: Mapped[uuid.UUID] = mapped_column(
|
|
|
|
|
UUID(as_uuid=True),
|
|
|
|
|
ForeignKey("sbom_snapshots.id", ondelete="RESTRICT"),
|
|
|
|
|
nullable=False,
|
|
|
|
|
index=True,
|
|
|
|
|
)
|
feat(state-hub): v0.3 schema — contributions + sbom_entries migrations, models, schemas, routers
Migrations (chain: b1c2d3e4f5a6 → c2d3e4f5a6b7 → d3e4f5a6b7c8):
- c2d3e4f5a6b7: contributions table (contributiontype BR/FR/EP/UPR enum,
contributionstatus 7-state lifecycle, FKs to topics/workstreams)
- d3e4f5a6b7c8: sbom_entries table (ecosystem enum, snapshot-based replacement),
+ sbom_source + last_sbom_at columns on managed_repos
New models: Contribution (ContributionType, ContributionStatus), SBOMEntry (Ecosystem)
Modified: ManagedRepo (sbom_source, last_sbom_at columns)
New routers:
- /contributions/ — CRUD + lifecycle-guarded PATCH /status + soft-delete (withdrawn)
- /sbom/ — ingest (replace snapshot), list, per-repo view, licence report
Modified:
- /state/summary now includes contribution_counts and licence_risk_count
- main.py: registers contributions + sbom routers; bumps version to 0.6.0
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-02-28 17:28:27 +01:00
|
|
|
snapshot_at: Mapped[datetime] = mapped_column(
|
|
|
|
|
DateTime(timezone=True), nullable=False
|
|
|
|
|
)
|
|
|
|
|
created_at: Mapped[datetime] = mapped_column(
|
|
|
|
|
DateTime(timezone=True), nullable=False
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
repo: Mapped["ManagedRepo"] = relationship("ManagedRepo", lazy="selectin") # noqa: F821
|
2026-03-02 23:39:17 +01:00
|
|
|
snapshot: Mapped["SBOMSnapshot"] = relationship( # noqa: F821
|
|
|
|
|
"SBOMSnapshot", lazy="selectin", back_populates="entries"
|
|
|
|
|
)
|