Files
git.stella-ops.org/src/SbomService/StellaOps.SbomService/AGENTS.md
master 8355e2ff75
Some checks failed
Docs CI / lint-and-preview (push) Has been cancelled
feat: Add initial implementation of Vulnerability Resolver Jobs
- Created project for StellaOps.Scanner.Analyzers.Native.Tests with necessary dependencies.
- Documented roles and guidelines in AGENTS.md for Scheduler module.
- Implemented IResolverJobService interface and InMemoryResolverJobService for handling resolver jobs.
- Added ResolverBacklogNotifier and ResolverBacklogService for monitoring job metrics.
- Developed API endpoints for managing resolver jobs and retrieving metrics.
- Defined models for resolver job requests and responses.
- Integrated dependency injection for resolver job services.
- Implemented ImpactIndexSnapshot for persisting impact index data.
- Introduced SignalsScoringOptions for configurable scoring weights in reachability scoring.
- Added unit tests for ReachabilityScoringService and RuntimeFactsIngestionService.
- Created dotnet-filter.sh script to handle command-line arguments for dotnet.
- Established nuget-prime project for managing package downloads.
2025-11-18 07:52:15 +02:00

1.7 KiB

StellaOps.SbomService — Agent Charter

Mission

Expose normalized SBOM projections (components, relationships, scopes, entrypoints) that downstream systems such as Cartographer, Policy Engine, and Scheduler consume. Maintain deterministic SBOM versioning, change events, and tenant-aware access patterns.

Responsibilities

  • Normalize ingest from Scanner outputs/CycloneDX/SPDX artifacts into canonical documents.
  • Provide APIs for SBOM metadata, projections, entrypoint catalogs, and version history.
  • Emit change events when SBOMs are added or updated so Cartographer and overlay workers can react.
  • Enforce Authority scopes/tenancy and deliver observability for SBOM projection latency.

Expectations

  • SBOM documents remain immutable once published; new versions append only.
  • Keep projections deterministic and schema-validated; include compliance checklists.
  • Update TASKS.md whenever status changes and coordinate with Cartographer/Scheduler guilds.

Required Reading

  • docs/modules/platform/architecture-overview.md
  • docs/modules/sbomservice/architecture.md
  • docs/implplan/SPRINT_0142_0001_0001_sbomservice.md

Working Agreement

    1. Update task status to DOING/DONE in both correspoding sprint file /docs/implplan/SPRINT_*.md and the local TASKS.md when you start or finish work.
    1. Review this charter and the Required Reading documents before coding; confirm prerequisites are met.
    1. Keep changes deterministic (stable ordering, timestamps, hashes) and align with offline/air-gap expectations.
    1. Coordinate doc updates, tests, and cross-guild communication whenever contracts or workflows change.
    1. Revert to TODO if you pause the task without shipping changes; leave notes in commit/PR descriptions for context.