chore: refresh org SBOM inventory - #1678
Conversation
There was a problem hiding this comment.
Note
This report is out of date. Scroll down for Devin Review's latest report on this PR.
Devin Review found 3 potential issues.
⚠️ 3 issues in files not directly in the diff
⚠️ Partial inventory appears complete
With 34 of 63 SBOM fetches returning 404, repo_count reports all 63 while component totals cover only 29. The inventory presents partial organization evidence as complete.
⚠️ Permitted licenses trigger violations
For MPL-2.0 components without another prohibited license, flagged reports at least 137 policy violations. Governance therefore escalates expressly permitted dependencies.
⚠️ Permissive alternatives trigger violations
When an SPDX expression offers a permissive alternative, flagged rejects it because another alternative is copyleft. Seven selectable permissive dependencies become policy violations.
There was a problem hiding this comment.
Devin Review found 1 new potential issue.
⚠️ 1 issue in files not directly in the diff
⚠️ Restricted licenses escape policy review
Seven LicenseRef-NVIDIA-Proprietary components are marked unflagged. Unknown and non-standard licenses also disappear from the commercial-permissive policy review.
…ialization Companion infrastructure repair for contextual-orchestrator#1111, now merged at d0fe10b508b46b225627fd201ef49ba6b3712598. User-authorized chicken-and-egg recovery. Reviewed all three changed files: accept only a full immutable organization VCS commit plus a single lower bound satisfied by the fixed Python 3.14 coverage image; false and complex markers remain rejected. Exact-head Trusted uv Materializer Quality CI 34322532030, SAST 34322531949, Security Scan 34322531920, Python Security 34322531962, and CodeQL 34322531908 are successful; zero review threads. No formal approval is claimed. No rulesets, credentials, statuses, or source isolation boundaries were weakened. Fresh consumer execution is still required to establish restoration.
Explicit user-authorized bypass for contextual-orchestrator incident recovery. Full three-file diff reviewed at 3431353; zero inline review threads. Exact-head Python Security 34310169116, SAST 34310169148, CodeQL 34310169106 and Security Scan 34310169250 are success. Preserve legacy log forms and omit provider response bodies, credentials and free-form messages; validate typed provider status/request IDs and reject multiline/partial tokens. Prerequisite for #2053 and merged contextual-orchestrator#1105 producer compatibility. No independent-approval or complete live-runtime-recovery claim. No scanner, ruleset or status modifications.
…he central collector Explicit user-authorized bypass for contextual-orchestrator infrastructure recovery. Prerequisite #1978 merged at 7b16449; retargeted this unchanged head to main without rewriting history. Full four-file diff reviewed; zero inline review threads. Exact-head CodeQL 34311014133, Security Scan 34311014127 and SAST 34311014150 are success; prior branch-based test claims are not fresh main/consumer evidence. Admit only 32-lowercase-hex server request IDs and contract-specific absence markers; retain legacy records and omit error text. Success summaries restricted to fixed review paths. No expanded auth, raw log publication, scanner suppression or synthetic statuses. Paired producer contextual-orchestrator#1105 is merged at 650bb67dd9cb9b0846a9026dd829c82f43b839e8. No independent approval or live incident-restoration claim.
User-authorized infrastructure-only incident merge, 2026-09-10. Full four-file queue-only delta reviewed. Source head28e10b5a Runtime Quality, Security, SAST, Python Security and CodeQL all succeeded; both authenticated dispatch language verdicts succeeded. OpenCode formal rejection cites peer infrastructure checks only, not a source finding. Original Noema34186939795/job101940505698 proves a CO414f2297 inference HTTP502 after73.4s prevented the model verdict. Existing inline/folded-comment parser findings are repaired in the current source; no unresolved inline threads. Ordinary expected-head merge, no review dismissal, synthetic status, permission/protection weakening, credential change or forced history. Push runs coalesce per branch; scheduled/PR evidence semantics preserved. Intermediate cancelled push reports are not guaranteed, as documented. Fresh merged-head CI and actual queue recovery remain unverified until observed. Evidence: issuecomment5613486794.
Automated central SBOM inventory refresh for live non-fork repositories. Review reciprocal, restricted, and NOASSERTION license evidence in docs/sbom/inventory.md against the product's actual distribution and hosted-service model.
Current blocking state (2026-09-08)
e6b292ce5e104212eaa032579afff1514b865019; livemaincomparison is ahead 70 / behind 0. The effective customer-evidence delta remainsdocs/sbom/inventory.jsonanddocs/sbom/inventory.md.required-workflow-bootstrapis deterministically RED before policy analysis because the Contents API does not inline the 1,148,611-byte JSON and protectedmain's policy caps that evidence path at 1 MiB. This is not an Nginx finding.1cb8cceb8719eb054979d84141cda9a95c0c6873, ahead 5 / behind 0, with bounded Git Blobs fallback plus malicious-content and malformed-evidence tests. Both original and Ready-event same-head Security, SAST, Python Security, and CodeQL PR runs are terminal GREEN. Noema and Strix were materialized but failed on centralorchestrator/freeavailability (HTTP 429 / zero ready routes); OpenCode's derivedCHANGES_REQUESTEDcontains no leaf-source finding. Keep this inventory PR Draft until fix(pingora): read Contents-API-oversized files through the Git Blobs API #1946 reaches protectedmain, this branch non-force integrates that release, and new exact-head checks plus independent review are valid.orchestrator/freeHTTP 429 is a separate review-transport blocker. Keep this PR Draft until fix(pingora): read Contents-API-oversized files through the Git Blobs API #1946 reaches protectedmain, this branch non-force integrates that release, and all new exact-head checks plus independent review are valid.