From f0591bda247160cc5b98b3658e9357acd7e485b7 Mon Sep 17 00:00:00 2001 From: codex Date: Sun, 23 Aug 2026 00:49:54 +0200 Subject: [PATCH] workplans: record bounded scheduled SBOM proof --- .../CUST-WP-0064-sbom-controlled-scan-inputs.md | 16 +++++++++++++--- 1 file changed, 13 insertions(+), 3 deletions(-) diff --git a/workplans/CUST-WP-0064-sbom-controlled-scan-inputs.md b/workplans/CUST-WP-0064-sbom-controlled-scan-inputs.md index 2b98554..966a788 100644 --- a/workplans/CUST-WP-0064-sbom-controlled-scan-inputs.md +++ b/workplans/CUST-WP-0064-sbom-controlled-scan-inputs.md @@ -138,7 +138,13 @@ batch. Repo Manager projected `sbom-nexus` with `checkout_path: null` and exact `forgejo-archive-v1` revision `b1fd3ec131666e5300aa98abcdddd46219303edb`; Nexus returned it unchanged. -Activity Core's bounded scheduled invocation remains to be proved live. +It then projected the live oldest-three target set (`can-you-assist`, +`citation-engine`, `citation-evidence`) with exact public full-SHA references. +The existing unpaused Temporal schedule was reconciled unchanged at limit 3 +and operator-triggered: it froze exactly those targets, spawned zero tasks, +created three provenance-bearing terminal `no-manifest` snapshots, and moved +`never_count` 94 to 91. Keep this task open for sustainable projection as each +new oldest-N batch is exposed. ## Prove real daily freshness improvement @@ -162,11 +168,15 @@ and an empty transient directory before and after. The feature was returned dark without deleting the snapshot. A normal scheduled fire and fleet summary remain the final proof. +An operator-trigger through the existing Temporal schedule subsequently +proved the production scheduled path and fleet summary without changing its +weekday cadence. The first unassisted 09:15 Europe/Berlin fire remains. + ## Acceptance - [x] Production scans consume a controlled, revision-pinned source input - [x] No workstation filesystem is mounted or implicitly trusted - [x] Nexus remains the only authoritative snapshot writer -- [ ] One fire remains bounded to its original N targets across retries +- [x] One fire remains bounded to its original N targets across retries - [ ] At least one normal scheduled fire produces real ingested snapshots -- [ ] Source cleanup, provenance, failure evidence, and rollback are verified +- [x] Source cleanup, provenance, failure evidence, and rollback are verified