-
-
Notifications
You must be signed in to change notification settings - Fork 0
Adopt bomly-sdk v0.14 and emit the scan record #483
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
bomly-guy
wants to merge
4
commits into
main
Choose a base branch
from
claude/adopt-sdk-v014-scan-record
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
4 commits
Select commit
Hold shift + click to select a range
8eb2bdc
build(deps)!: adopt bomly-sdk v0.14
bomly-guy 2f0c4c5
feat(git): record the commit a scan ran against
bomly-guy 190ca1d
feat(sbom): keep what an ingested document says about its packages
bomly-guy 5d22253
feat(output)!: emit the scan record
bomly-guy File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
58 changes: 58 additions & 0 deletions
58
dev-docs/adr/0046-the-scan-output-is-the-sdk-scan-record.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,58 @@ | ||
| # ADR-0046: The scan output is the SDK's scan record | ||
|
|
||
| - **Date:** 2026-09-24 | ||
| - **Status:** Accepted | ||
|
|
||
| ## Context | ||
|
|
||
| `bomly scan --format json` emitted a document defined in `internal/output`: | ||
| three collections -- manifests, packages, findings -- joined by package URL | ||
| (ADR-0006, ADR-0011), each a CLI-local projection of an SDK type with its own | ||
| JSON tags, builders and tests. The document carried nothing about the run | ||
| that produced it: no subject, no timestamp, no tool version, no verdict; the | ||
| verdict lived only in the process exit code. | ||
|
|
||
| A second consumer of that document now exists in the SDK's own `scan` | ||
| package, which defines it as `scan.Record` under the schema `bomly.scan.v1` | ||
| with the envelope the CLI never wrote. Under ADR-0040 a shape two consumers | ||
| share belongs in the SDK, and a projection maintained beside it would have | ||
| to be kept equal to it by hand -- the drift ADR-0045 ended for the SBOM | ||
| codec. | ||
|
|
||
| ## Decision | ||
|
|
||
| `bomly scan` emits `scan.Record`. The CLI builds it from the pipeline's | ||
| consolidated manifests, registry and findings, fills `subject` from the | ||
| execution target (repository, ref, and the commit the ref resolved to -- | ||
| never a local path), `run` from the invocation, and `verdict` from the same | ||
| count the exit code uses, and writes it through `scan.Encode`, so what is | ||
| written is the canonical, digested form. | ||
|
|
||
| The projection types are gone. A manifest and its dependencies are | ||
| `scan.Manifest` and `scan.Dependency`; a package is `model.Package` as the | ||
| registry holds it; a finding is `model.Finding`, referencing its package by | ||
| `package_ref`; a license is `model.PackageLicense` and a location | ||
| `model.PackageLocation`. The `diff` and `explain` documents keep their own | ||
| `schema_version` and adopt the same finding and package shapes. The one | ||
| projection the old types did that a type cannot -- backfilling a finding's | ||
| severity from its advisory -- is a function, `output.FindingsWithSeverity`, | ||
| applied wherever findings enter a document. A package's presentation | ||
| identity (`@scope/name` from `org` and `name`) is derived by the renderers, | ||
| not written into the document. | ||
|
|
||
| ## Consequences | ||
|
|
||
| - `findings[].package` (an identity block) becomes `findings[].package_ref` | ||
| (the package URL); `packages[].name` and `org` are coordinates, not a | ||
| display name; empty collections are omitted rather than written empty. The | ||
| goldens and generated schemas were regenerated once. | ||
| - `subject`, `run`, `verdict`, `policy`, `waivers` and per-section `digests` | ||
| are new optional keys; `findings[].decision` records which resolver settled | ||
| a policy status. Local `--path` scans inside a repository record the | ||
| working tree's HEAD. | ||
| - `internal/output` no longer defines the scan document's shape; its guards | ||
| live in the SDK (`scan/record_test.go`). The CLI keeps the builders that | ||
| need pipeline context -- manifest paths relative to the subproject, the | ||
| `Matched` flag from the registry -- and the renderers. | ||
| - The scan JSON is stable across runs of the same content: `scan.Encode` | ||
| orders every collection, so a digest over it identifies what was found. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
Remove the conflicting end-of-life guidance.
This passage says end-of-life records survive a round trip. Lines 501-505 still say import discards them and instruct readers to run
--enrich. Update or remove the older bullet so readers get one accurate conversion rule.🤖 Prompt for AI Agents