nigig-org/crates/apps/nigig-traffic/docs/SBOM.md

1.1 KiB

nigig-traffic SBOM / license manifest (TRAFFIC-13)

Status: TEMPLATE — no release artifact exists yet (build blocked on TRAFFIC-P0-01). Starting with the first coherent-pin release candidate, this file (or its per-release sibling SBOM-<commit>.md) records:

  • workspace commit SHA + Cargo.lock hash,
  • Makepad fork remote + full pinned rev + review link for the pin,
  • cargo metadata-derived dependency list for the nigig-traffic closure: name, version, source (registry/git), license, content hash,
  • packaged-asset manifest (AssetManifest logical IDs, content hashes, licenses/attributions, byte/triangle/texture totals),
  • scenario content hashes (ID → content version → catalog hash),
  • build provenance (runner image, toolchain channel + installer digest, pinned action SHAs).

Generate the dependency section with:

cargo metadata --locked --format-version 1 --filter-platform x86_64-unknown-linux-gnu \
  | python3 -c "import json,sys; ..."
cargo tree --locked -p nigig-traffic --prefix none

Archive the filled manifest with the release. Never ship without it.