feat: add PolicyPackSelectorComponent with tests and integration
- Implemented PolicyPackSelectorComponent for selecting policy packs. - Added unit tests for component behavior, including API success and error handling. - Introduced monaco-workers type declarations for editor workers. - Created acceptance tests for guardrails with stubs for AT1–AT10. - Established SCA Failure Catalogue Fixtures for regression testing. - Developed plugin determinism harness with stubs for PL1–PL10. - Added scripts for evidence upload and verification processes.
This commit is contained in:
18
docs/sbom/vuln-resolution.md
Normal file
18
docs/sbom/vuln-resolution.md
Normal file
@@ -0,0 +1,18 @@
|
||||
# SBOM Vulnerability Resolution (Md.XI draft)
|
||||
|
||||
> Status: DRAFT — pending export/advisory integration and GRAP0101 field freeze.
|
||||
|
||||
## Scope
|
||||
- Version semantics, scope, paths, safe version hints for SBOM components in Vuln Explorer.
|
||||
- Deterministic examples with hashes in `docs/assets/vuln-explorer/SHA256SUMS`.
|
||||
|
||||
## Dependencies
|
||||
- Advisory integration (DOCS-VULN-29-008).
|
||||
- GRAP0101 identifiers.
|
||||
|
||||
## Outline
|
||||
- Component resolution (purl, NEVRA); scope (prod/dev/test).
|
||||
- Path specificity and deduping rules.
|
||||
- Safe version hints and policy overlays.
|
||||
|
||||
_Last updated: 2025-12-05 (UTC)_
|
||||
Reference in New Issue
Block a user