67 lines
3.6 KiB
Markdown
67 lines
3.6 KiB
Markdown
# Custodian intake records
|
|
|
|
## CUST-IN-0011 — Provision a monitored external security-report Contact URI
|
|
|
|
```yaml
|
|
id: CUST-IN-0011
|
|
kind: intake
|
|
title: "Provision a monitored external security-report Contact URI"
|
|
status: routed
|
|
lane: red
|
|
priority: high
|
|
owner: policy-nexus
|
|
tags: [compliance-relevant]
|
|
origin: residual
|
|
origin_ref: CUST-WP-0063
|
|
selected_contact_uri: "https://security.coulomb.social/"
|
|
updated: "2026-08-22"
|
|
notes: "The operator selected https://security.coulomb.social/ as the RFC 9116 Contact URI. Policy Nexus owns provisioning and receipt testing before policy.coulomb.social/.well-known/security.txt may publish it. Reports route privately to risk-nexus; the route creates no bounty, response-time, or safe-harbour promise. Close only after the HTTPS endpoint is reachable and a private test report reaches Risk Nexus."
|
|
state_hub_intake_id: "01a02b31-f4b0-75e4-a15c-a78e1c276689"
|
|
```
|
|
|
|
## CUST-IN-0012 — Repair the malformed legacy inbox message identity
|
|
|
|
```yaml
|
|
id: CUST-IN-0012
|
|
kind: intake
|
|
title: "Repair the malformed legacy inbox message identity"
|
|
status: open
|
|
lane: green
|
|
priority: low
|
|
owner: hub-core
|
|
origin: residual
|
|
origin_ref: CUST-WP-0063
|
|
notes: "State Hub returns unread risk-nexus message id 0b8dd0bf-41d-47da-96ac-40e443c32e47, whose second UUID group has only three characters. PATCH /messages/{id}/read rejects it during UUID path parsing, so the already-handled superseded request cannot be marked read through the supported API. Repair must preserve the message body and chronology, assign or map a valid stable identity, and then apply the read transition without direct ad hoc database mutation from this repo."
|
|
state_hub_intake_id: "01a02b32-009b-71bd-a7bf-2ce888164d6a"
|
|
```
|
|
|
|
## CUST-IN-0013 — Enforce durable SBOM catch-up operation idempotency
|
|
|
|
```yaml
|
|
id: CUST-IN-0013
|
|
kind: intake
|
|
title: "Enforce durable SBOM catch-up operation idempotency"
|
|
status: open
|
|
lane: blue
|
|
priority: high
|
|
owner: sbom-nexus
|
|
origin: residual
|
|
origin_ref: CUST-WP-0062
|
|
notes: "Activity Core completed ACTIVITY-WP-0033 and now sends a stable Idempotency-Key plus X-Activity-Core-Operation-ID for each workflow-run/repository pair. SBOM Nexus durably enforces that identity on both POST /sbom/{slug}/ingest and POST /sbom/{slug}/skip and replays the original terminal response. Live attended evidence on 2026-08-23 returned the same snapshot 04f5c0ba-d073-4577-ba2d-0854346ac7be for two requests with the same operation key and exact source reference. Scheduled Activity Core proof remains under CUST-WP-0064. Source handoff: State Hub message bc5caa49-25eb-4942-9deb-411b6080d0bb."
|
|
state_hub_intake_id: "01a02b44-89a9-7e94-820b-3d86340117ff"
|
|
```
|
|
|
|
## CUST-IN-0014 — Stop SBOM Nexus restarts on database lease rotation
|
|
|
|
```yaml
|
|
id: CUST-IN-0014
|
|
kind: intake
|
|
title: "Stop SBOM Nexus restarts on database lease rotation"
|
|
status: open
|
|
lane: blue
|
|
priority: high
|
|
owner: sbom-nexus
|
|
origin: residual
|
|
origin_ref: CUST-WP-0062
|
|
notes: "Live review after cutover found the Ready SBOM Nexus pod at restartCount 9 in under five hours. The last container ran exactly 30 minutes, then readiness/liveness returned HTTP 500 because PostgreSQL rejected the expired v-token-sbom-nex-* credential; Kubernetes restarted the process and it recovered. The corrected runtime deployed on 2026-08-23 rereads the mounted URL for every new connection, recycles the pool every five minutes, keeps credentials out of the engine URL, and separates process liveness from database readiness. Initial migration 0002, health, repository reads, and attended canary pass with zero pod restarts. Keep open through one complete lease window and confirm no credential values in logs."
|
|
```
|