nigig-org/crates/apps/nigig-traffic/docs/SBOM.md

25 lines
1.1 KiB
Markdown

# nigig-traffic SBOM / license manifest (TRAFFIC-13)
Status: TEMPLATE — no release artifact exists yet (build blocked on
TRAFFIC-P0-01). Starting with the first coherent-pin release candidate,
this file (or its per-release sibling `SBOM-<commit>.md`) records:
- workspace commit SHA + `Cargo.lock` hash,
- Makepad fork remote + full pinned rev + review link for the pin,
- `cargo metadata`-derived dependency list for the `nigig-traffic`
closure: name, version, source (registry/git), license, content hash,
- packaged-asset manifest (`AssetManifest` logical IDs, content hashes,
licenses/attributions, byte/triangle/texture totals),
- scenario content hashes (ID → content version → catalog hash),
- build provenance (runner image, toolchain channel + installer digest,
pinned action SHAs).
Generate the dependency section with:
```sh
cargo metadata --locked --format-version 1 --filter-platform x86_64-unknown-linux-gnu \
| python3 -c "import json,sys; ..."
cargo tree --locked -p nigig-traffic --prefix none
```
Archive the filled manifest with the release. Never ship without it.