Files
git.stella-ops.org/docs/sbom/vuln-resolution.md
StellaOps Bot 18d87c64c5 feat: add PolicyPackSelectorComponent with tests and integration
- Implemented PolicyPackSelectorComponent for selecting policy packs.
- Added unit tests for component behavior, including API success and error handling.
- Introduced monaco-workers type declarations for editor workers.
- Created acceptance tests for guardrails with stubs for AT1–AT10.
- Established SCA Failure Catalogue Fixtures for regression testing.
- Developed plugin determinism harness with stubs for PL1–PL10.
- Added scripts for evidence upload and verification processes.
2025-12-05 21:24:34 +02:00

584 B

SBOM Vulnerability Resolution (Md.XI draft)

Status: DRAFT — pending export/advisory integration and GRAP0101 field freeze.

Scope

  • Version semantics, scope, paths, safe version hints for SBOM components in Vuln Explorer.
  • Deterministic examples with hashes in docs/assets/vuln-explorer/SHA256SUMS.

Dependencies

  • Advisory integration (DOCS-VULN-29-008).
  • GRAP0101 identifiers.

Outline

  • Component resolution (purl, NEVRA); scope (prod/dev/test).
  • Path specificity and deduping rules.
  • Safe version hints and policy overlays.

Last updated: 2025-12-05 (UTC)