docs consolidation
This commit is contained in:
@@ -1,15 +0,0 @@
|
||||
# Build/Infra Prep — PREP-BUILD-INFRA-SBOM-SERVICE-GUILD-BLOCKED-M
|
||||
|
||||
Status: Draft (2025-11-20)
|
||||
Owners: SBOM Service Guild
|
||||
Scope: Document restore/build blocking issues awaiting vetted feed/cache.
|
||||
|
||||
## Blocker summary
|
||||
- Multiple restore attempts hang/fail; need vetted NuGet feed/cache for SBOM Service solution.
|
||||
|
||||
## Needed actions
|
||||
- Provide approved offline feed snapshot for SBOM Service dependencies.
|
||||
- CI runner with feed configured to validate restore.
|
||||
|
||||
## Handoff
|
||||
Use as PREP artefact; update once feed snapshot is supplied and restore passes.
|
||||
@@ -1,20 +0,0 @@
|
||||
# SBOM Service Prep — PREP-SBOM-SERVICE-21-001
|
||||
|
||||
Status: Draft (2025-11-20)
|
||||
Owners: SBOM Service Guild · Cartographer Guild
|
||||
Scope: Waiting on LNM v1 fixtures to freeze normalized SBOM projection read API.
|
||||
|
||||
## Needed inputs
|
||||
- LNM v1 fixtures (due 2025-11-18 UTC) for schema alignment.
|
||||
|
||||
## Proposed API surface (draft)
|
||||
- `GET /sboms/{id}/projection` with query `page`, `page_size`, `tenant_id`.
|
||||
- Response includes `components[]`, `licenses[]`, `hashes[]`, `provenance`.
|
||||
- Deterministic ordering, tenant enforcement.
|
||||
|
||||
## Open decisions
|
||||
- Pagination defaults and max page size.
|
||||
- Which hash algorithms to expose.
|
||||
|
||||
## Handoff
|
||||
Use as PREP artefact; finalize once fixtures arrive.
|
||||
@@ -1,31 +0,0 @@
|
||||
# SBOM Service Prep — PREP-SBOM-SERVICE-GUILD-CARTOGRAPHER-GUILD-OB
|
||||
|
||||
Status: Published (2025-11-22)
|
||||
|
||||
Owners: SBOM Service Guild · Cartographer Guild · Observability Guild · Zastava Observer/Webhook Guilds · Security Guild
|
||||
|
||||
Scope: Capture a single readiness note for Runtime & Signals wave (0140) so SBOM-SERVICE-21-001..004 and SBOM-AIAI-31-001/002 can start once fixtures and AirGap approvals land.
|
||||
|
||||
## Current inputs (as of 2025-11-22)
|
||||
- Link-Not-Merge v1 projection schema frozen on 2025-11-17 (per Sprint 0140 decisions); JSON fixtures have not been published.
|
||||
- Mock surface bundle v1 exists; real scanner cache ETA is still outstanding, so Graph/Zastava cannot validate parity yet.
|
||||
- CAS/provenance decisions are tracked under `docs/signals/cas-promotion-24-002.md` and `docs/signals/provenance-24-003.md`; SBOM events must align with these provenance fields.
|
||||
|
||||
## Outstanding blockers to flip SBOM wave to DOING
|
||||
- Publish LNM v1 JSON fixtures with hash list to `docs/modules/sbomservice/fixtures/lnm-v1/` plus `SHA256SUMS`. Owners: Concelier Core · Cartographer Guild.
|
||||
- Run AirGap parity review for `/sbom/paths`, `/sbom/versions`, and `/sbom/events`; template and minutes location published at `docs/modules/sbomservice/runbooks/airgap-parity-review.md`. Owner: Observability Guild with SBOM Service Guild.
|
||||
- Confirm scanner cache drop timeline and hash for the real surface cache; mirror in sprint 0140 tracker once published. Owner: Scanner Guild.
|
||||
|
||||
## Ready-to-start checklist for SBOM-SERVICE-21-001..004
|
||||
- Verify fixtures landed at the path above and match the frozen field list; add deterministic fixture IDs to tests.
|
||||
- Emit projection change events with schema version and fixture set hash; expose counters and optional OTEL traces behind config.
|
||||
- Provide observability baselines (dashboards/alerts) for path/timeline endpoints with latency and error-rate SLOs.
|
||||
- Document tenant scoping and add-only evolution in API reference before exposing to Console and Advisory AI consumers.
|
||||
|
||||
## Evidence
|
||||
- This prep note: `docs/modules/sbomservice/prep/2025-11-22-prep-sbom-service-guild-cartographer-ob.md`.
|
||||
- Blocker detail mirrored in `docs/implplan/SPRINT_0140_0001_0001_runtime_signals.md` Delivery Tracker and Decisions & Risks.
|
||||
|
||||
## Exit criteria
|
||||
- LNM v1 fixtures and AirGap review minutes committed and linked in sprints 0140 and 0142.
|
||||
- Sprint 0140 SBOM wave can move from BLOCKED to DOING with cache ETA recorded.
|
||||
Reference in New Issue
Block a user