fix: use framework version in CycloneDX SBOM metadata - #117
Conversation
Release-Slice: release-sbom-framework-version
Release-Type: none
Release-Type: none
Release-Type: none
Release-Type: none
Release-Type: none
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5a246e405e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| { | ||
| "schema_version": 1, | ||
| "version": "4.44.3", | ||
| "source_commit": "08c643e92dede0e33190cf85dbbe38550179077e", |
There was a problem hiding this comment.
Preserve the release source ancestry
In the reviewed f5a048e history, 08c643e92dede0e33190cf85dbbe38550179077e is not an ancestor (git merge-base --is-ancestor 08c643e f5a048e exits 1); the generated receipts similarly name sibling commit 3e25918. Consequently release_docs.check() emits source_not_ancestor, while regeneration from this commit rewrites the provenance, blocking the release and generated-doc gates. Preserve the multi-commit ancestry, or move the release record and regenerated receipts to a follow-up commit based on the accepted implementation.
AGENTS.md reference: AGENTS.md:L146-L154
Useful? React with 👍 / 👎.
| "type": "application", | ||
| "name": metadata["pack_id"], | ||
| "version": str(metadata["version"]), | ||
| "version": _framework_version_from_artifact(artifact_path), |
There was a problem hiding this comment.
Add VERSION to the existing SBOM fixture
When the full suite reaches test_public_sbom_checks_full_vendor_metadata_and_manifest_binding, that test constructs an archive containing only the vendored files and uv.lock, then calls write_cyclonedx_sbom; this new unconditional lookup therefore raises ValueError("framework VERSION not found in artifact") before the existing assertions. Add a valid VERSION member to that fixture so the required release-validation suite remains green.
AGENTS.md reference: AGENTS.md:L114-L118
Useful? React with 👍 / 👎.
Release-Type: none
Release-Type: none
Release-Type: none
Release-Type: none
Release-Type: none
Release-Type: none
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b4273c1a24
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| { | ||
| "schema_version": 1, | ||
| "version": "4.44.3", | ||
| "source_commit": "f44ecd55dcdc9e5516876b35001a99cb1e9d14b0", |
There was a problem hiding this comment.
Rebind the release record to an ancestor
Fresh evidence in 6d59e2b is that this updated source_commit now points to f44ecd55dcdc9e5516876b35001a99cb1e9d14b0, but git merge-base --is-ancestor f44ecd5 6d59e2b exits 1; the regenerated receipts similarly point to non-ancestor 213176b. Consequently release_docs.check() reports source_not_ancestor, blocking the required release-documentation gate. Preserve the multi-commit ancestry or regenerate and rebind the record and receipts from a follow-up commit based on the accepted implementation.
AGENTS.md reference: AGENTS.md:L146-L154
Useful? React with 👍 / 👎.
Summary
VERSIONin the completed archive; source and installed SBOM generation use repositoryVERSIONwhen present and fall back to installed distribution metadata when it is absent.VERSIONentries and stale release SBOM component versions.3.Validation
release-docs check --version 4.44.3: passed.docs-align check --ci: passed with zero findings.source_dirty: false.publish-preflight --base origin/main --head HEAD: passed; target 4.44.3, no major-line violations.git diff --check: passed. Full PR validation will run before merge.