workplans: record bounded scheduled SBOM proof
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
codex 2026-08-23 00:49:54 +02:00
parent 8a481414ec
commit f0591bda24

View file

@ -138,7 +138,13 @@ batch.
Repo Manager projected `sbom-nexus` with `checkout_path: null` and exact
`forgejo-archive-v1` revision
`b1fd3ec131666e5300aa98abcdddd46219303edb`; Nexus returned it unchanged.
Activity Core's bounded scheduled invocation remains to be proved live.
It then projected the live oldest-three target set (`can-you-assist`,
`citation-engine`, `citation-evidence`) with exact public full-SHA references.
The existing unpaused Temporal schedule was reconciled unchanged at limit 3
and operator-triggered: it froze exactly those targets, spawned zero tasks,
created three provenance-bearing terminal `no-manifest` snapshots, and moved
`never_count` 94 to 91. Keep this task open for sustainable projection as each
new oldest-N batch is exposed.
## Prove real daily freshness improvement
@ -162,11 +168,15 @@ and an empty transient directory before and after. The feature was returned
dark without deleting the snapshot. A normal scheduled fire and fleet summary
remain the final proof.
An operator-trigger through the existing Temporal schedule subsequently
proved the production scheduled path and fleet summary without changing its
weekday cadence. The first unassisted 09:15 Europe/Berlin fire remains.
## Acceptance
- [x] Production scans consume a controlled, revision-pinned source input
- [x] No workstation filesystem is mounted or implicitly trusted
- [x] Nexus remains the only authoritative snapshot writer
- [ ] One fire remains bounded to its original N targets across retries
- [x] One fire remains bounded to its original N targets across retries
- [ ] At least one normal scheduled fire produces real ingested snapshots
- [ ] Source cleanup, provenance, failure evidence, and rollback are verified
- [x] Source cleanup, provenance, failure evidence, and rollback are verified