Skip to content

fix: use framework version in CycloneDX SBOM metadata - #117

Merged
CruxExperts merged 13 commits into
mainfrom
fix/cyclonedx-framework-version
Sep 26, 2026
Merged

CruxExperts merged 13 commits into
mainfrom
fix/cyclonedx-framework-version

Conversation

@CruxExperts

Copy link
Copy Markdown
Owner

Summary

  • Use LocalSetup's framework version for CycloneDX application components. Release SBOMs bind to the validated VERSION in the completed archive; source and installed SBOM generation use repository VERSION when present and fall back to installed distribution metadata when it is absent.
  • Reject missing, duplicate, nonregular, oversized, or malformed archive VERSION entries and stale release SBOM component versions.
  • Keep artifact metadata's separate pack-format value at 3.
  • Add the v4.44.3 release record and refreshed documentation for the sequential QC and SBOM patch slices from the published v4.44.1 baseline, under the existing 4.x major-line lock.

Validation

  • Focused package and provenance tests: 30 passed.
  • release-docs check --version 4.44.3: passed.
  • docs-align check --ci: passed with zero findings.
  • Generated documentation was repeatable and all receipts report source_dirty: false.
  • Clean publish-preflight --base origin/main --head HEAD: passed; target 4.44.3, no major-line violations.
  • git diff --check: passed. Full PR validation will run before merge.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-26T09:57:38.961140Z b4273c1 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions github-actions Bot added area/docs Affected repository area area/installer Installer, bootstrap, conversion, or rollback area/release Affected repository area area/skills Skills, workflows, or packs status/needs-triage Triage status type/pr Issue or PR type labels Sep 26, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5a246e405e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread ls/docs/releases/4.44.3.json Outdated
{
"schema_version": 1,
"version": "4.44.3",
"source_commit": "08c643e92dede0e33190cf85dbbe38550179077e",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Preserve the release source ancestry

In the reviewed f5a048e history, 08c643e92dede0e33190cf85dbbe38550179077e is not an ancestor (git merge-base --is-ancestor 08c643e f5a048e exits 1); the generated receipts similarly name sibling commit 3e25918. Consequently release_docs.check() emits source_not_ancestor, while regeneration from this commit rewrites the provenance, blocking the release and generated-doc gates. Preserve the multi-commit ancestry, or move the release record and regenerated receipts to a follow-up commit based on the accepted implementation.

AGENTS.md reference: AGENTS.md:L146-L154

Useful? React with 👍 / 👎.

Comment thread ls/core/package.py
"type": "application",
"name": metadata["pack_id"],
"version": str(metadata["version"]),
"version": _framework_version_from_artifact(artifact_path),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Add VERSION to the existing SBOM fixture

When the full suite reaches test_public_sbom_checks_full_vendor_metadata_and_manifest_binding, that test constructs an archive containing only the vendored files and uv.lock, then calls write_cyclonedx_sbom; this new unconditional lookup therefore raises ValueError("framework VERSION not found in artifact") before the existing assertions. Add a valid VERSION member to that fixture so the required release-validation suite remains green.

AGENTS.md reference: AGENTS.md:L114-L118

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b4273c1a24

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

{
"schema_version": 1,
"version": "4.44.3",
"source_commit": "f44ecd55dcdc9e5516876b35001a99cb1e9d14b0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Rebind the release record to an ancestor

Fresh evidence in 6d59e2b is that this updated source_commit now points to f44ecd55dcdc9e5516876b35001a99cb1e9d14b0, but git merge-base --is-ancestor f44ecd5 6d59e2b exits 1; the regenerated receipts similarly point to non-ancestor 213176b. Consequently release_docs.check() reports source_not_ancestor, blocking the required release-documentation gate. Preserve the multi-commit ancestry or regenerate and rebind the record and receipts from a follow-up commit based on the accepted implementation.

AGENTS.md reference: AGENTS.md:L146-L154

Useful? React with 👍 / 👎.

@CruxExperts
CruxExperts merged commit b4273c1 into main Sep 26, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/docs Affected repository area area/installer Installer, bootstrap, conversion, or rollback area/release Affected repository area area/skills Skills, workflows, or packs status/needs-triage Triage status type/pr Issue or PR type

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant