25 lines
1.1 KiB
Markdown
25 lines
1.1 KiB
Markdown
# nigig-traffic SBOM / license manifest (TRAFFIC-13)
|
|
|
|
Status: TEMPLATE — no release artifact exists yet (build blocked on
|
|
TRAFFIC-P0-01). Starting with the first coherent-pin release candidate,
|
|
this file (or its per-release sibling `SBOM-<commit>.md`) records:
|
|
|
|
- workspace commit SHA + `Cargo.lock` hash,
|
|
- Makepad fork remote + full pinned rev + review link for the pin,
|
|
- `cargo metadata`-derived dependency list for the `nigig-traffic`
|
|
closure: name, version, source (registry/git), license, content hash,
|
|
- packaged-asset manifest (`AssetManifest` logical IDs, content hashes,
|
|
licenses/attributions, byte/triangle/texture totals),
|
|
- scenario content hashes (ID → content version → catalog hash),
|
|
- build provenance (runner image, toolchain channel + installer digest,
|
|
pinned action SHAs).
|
|
|
|
Generate the dependency section with:
|
|
|
|
```sh
|
|
cargo metadata --locked --format-version 1 --filter-platform x86_64-unknown-linux-gnu \
|
|
| python3 -c "import json,sys; ..."
|
|
cargo tree --locked -p nigig-traffic --prefix none
|
|
```
|
|
|
|
Archive the filled manifest with the release. Never ship without it.
|