[Phase 16] Write the SBOM / supply-chain standard (prerequisite of S12)
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 18/100
- Tipo di issue
- Documentazione
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- markdown, python
- Ambito
- documentation, security
Direzione di ricerca
Read the Phase 16 roadmap at docs/roadmap/phase-16-trust-surface-hardening.md lines 904-908, the layout rules in documentation.md, and the severity handling in check_pip_audit.py. The standard goes under docs/standards/ and is linked from docs/standards/README.md. Done means every decision (CycloneDX version, completeness rules, retention, severity tiers) is a checkable rule and S12 can be reviewed against it.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Roadmap · Phase 16 · prerequisite of step S12 · size M · planned in
docs/roadmap/phase-16-trust-surface-hardening.md:904-908
Summary
SBOMs appear only as descriptive prose and one command; nothing states what a correct SBOM is or what the supply-chain gates mean. Phase 16 S12 has nothing to be reviewed against until this exists.
What the standard must settle
- The CycloneDX version.
- Component completeness: root exclusion,
bom-refuniqueness, license coverage, dependency graph. - The retention channel and window.
- The meaning of each
check_pip_audit.pyseverity tier.
Acceptance criteria
- The standard lives under
docs/standards/in the layoutdocumentation.mdprescribes and is listed indocs/standards/README.md. - It answers every point above with a rule a reviewer can check, not a description.
- Phase 16 step S12 can be reviewed against it.
Planned in docs/roadmap/phase-16-trust-surface-hardening.md (read at f94595f). Unit IDs (F-W20260729-…) come from the 2026-07-29/30 full-project review; the issue numbers next to them are the October 2026 review's records of the same defects.
- Lingua principale
- Python
- Stelle
- 9
- Fork
- 1
- Merge medio
- 4h 3m
- PR unite (30g)
- 3
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di HodeTech/ForgeLM
-
area: dev-tooling bug severity: low source: roadmap wave: 4
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
area: site bug good first issue severity: low source: review-2026-09 wave: 4
Difficoltà 2/5 1-3 ore Idoneità per principianti 66/100
-
documentation good first issue severity: medium source: review-2026-09 wave: 3
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
documentation good first issue severity: low source: review-2026-09 wave: 4
Difficoltà 1/5 1-3 ore Idoneità per principianti 80/100
-
documentation severity: medium source: review-2026-09 wave: 3
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
Tutte le issue di HodeTech/ForgeLM
Issue simili
-
Claiming namespace `jft63`Apertanamespace operations
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 72/100
EclipseFdn/open-vsx.org#14043 ·
I maintainer di solito rispondono entro 1 giorno
-
netbox status: needs triage type: bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
netbox-community/netbox#23376 ·
I maintainer di solito rispondono entro 1 giorno
-
feedback simulation workshop
Difficoltà 2/5 1-3 ore Idoneità per principianti 73/100
githubnext/gh-aw-workshop#4455 ·
I maintainer di solito rispondono entro 1 giorno
-
Triage 🩺
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 1 giorno
-
[BUG] Container scenario crashes without expected_recovery_time, kube DNS example uses retry_waitApertaneeds-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 77/100
krkn-chaos/krkn#1627 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno