# nigig-traffic SBOM / license manifest (TRAFFIC-13) Status: TEMPLATE — no release artifact exists yet (build blocked on TRAFFIC-P0-01). Starting with the first coherent-pin release candidate, this file (or its per-release sibling `SBOM-.md`) records: - workspace commit SHA + `Cargo.lock` hash, - Makepad fork remote + full pinned rev + review link for the pin, - `cargo metadata`-derived dependency list for the `nigig-traffic` closure: name, version, source (registry/git), license, content hash, - packaged-asset manifest (`AssetManifest` logical IDs, content hashes, licenses/attributions, byte/triangle/texture totals), - scenario content hashes (ID → content version → catalog hash), - build provenance (runner image, toolchain channel + installer digest, pinned action SHAs). Generate the dependency section with: ```sh cargo metadata --locked --format-version 1 --filter-platform x86_64-unknown-linux-gnu \ | python3 -c "import json,sys; ..." cargo tree --locked -p nigig-traffic --prefix none ``` Archive the filled manifest with the release. Never ship without it.