1.1 KiB
1.1 KiB
nigig-traffic SBOM / license manifest (TRAFFIC-13)
Status: TEMPLATE — no release artifact exists yet (build blocked on
TRAFFIC-P0-01). Starting with the first coherent-pin release candidate,
this file (or its per-release sibling SBOM-<commit>.md) records:
- workspace commit SHA +
Cargo.lockhash, - Makepad fork remote + full pinned rev + review link for the pin,
cargo metadata-derived dependency list for thenigig-trafficclosure: name, version, source (registry/git), license, content hash,- packaged-asset manifest (
AssetManifestlogical IDs, content hashes, licenses/attributions, byte/triangle/texture totals), - scenario content hashes (ID → content version → catalog hash),
- build provenance (runner image, toolchain channel + installer digest, pinned action SHAs).
Generate the dependency section with:
cargo metadata --locked --format-version 1 --filter-platform x86_64-unknown-linux-gnu \
| python3 -c "import json,sys; ..."
cargo tree --locked -p nigig-traffic --prefix none
Archive the filled manifest with the release. Never ship without it.