Files
git.stella-ops.org/docs/features/checked/web/evidence-provenance-visualization-component.md
2026-02-12 10:27:23 +02:00

2.3 KiB

Evidence Provenance Visualization Component

Module

Web

Status

VERIFIED

Description

Interactive evidence provenance chain visualization showing the path: finding -> advisory -> VEX -> policy -> attestation. Part of the evidence-export feature module with routing integration.

Implementation Details

  • Feature directory: src/Web/StellaOps.Web/src/app/shared/components/evidence-checklist/
  • Components:
    • evidence-checklist (src/Web/StellaOps.Web/src/app/shared/components/evidence-checklist/evidence-checklist.component.ts)
  • Source: SPRINT_20251229_016_FE_evidence_export_replay_ui.md

E2E Test Plan

  • Setup:
    • Log in with a user that has appropriate permissions
    • Navigate to the relevant page/section where this feature appears
    • Ensure test data exists (scanned artifacts, SBOM data, or seed data as needed)
  • Core verification:
    • Verify the visualization renders correctly with sample data
    • Verify interactive elements (hover tooltips, click-to-drill-down) work
    • Verify the visualization handles empty/minimal data gracefully
  • Edge cases:
    • Verify graceful handling when backend API is unavailable (error state)
    • Verify responsive layout at different viewport sizes
    • Verify accessibility (keyboard navigation, screen reader labels, ARIA attributes)

Verification

  • Run: docs/qa/feature-checks/runs/web/evidence-provenance-visualization-component/run-001/
  • Tier 0 (source): pass ( ier0-source-check.json)
  • Tier 1 (build/tests): pass ( ier1-build-check.json)
  • Tier 2 (behavior): pass ( ier2-e2e-check.json)
  • Verified on (UTC): 2026-02-10

Recheck (run-003)

  • Date (UTC): 2026-02-11T06:50:05Z
  • Status: FAILED (strict Tier 2 UI replay)
  • Tier 2 evidence: docs/qa/feature-checks/runs/web/evidence-provenance-visualization-component/run-003/tier2-ui-check.json
  • Notes: /evidence/provenance rendered the page header, but selecting artifact art-001 did not render any .chain-node entries in the strict end-user transaction.

Recheck (run-004)

  • Date (UTC): 2026-02-11T10:08:09Z
  • Status: PASSED (strict Tier 2 UI replay)
  • Tier 2 evidence: docs/qa/feature-checks/runs/web/evidence-provenance-visualization-component/run-004/tier2-ui-check.json
  • Notes: Verified on /evidence/provenance after artifact selection with chain-node and detail modal assertions.