Skip to content

docs(maturity): done-criterion 2 states the measurement that was actually taken - #462

Merged
bomly-guy merged 2 commits into
mainfrom
docs/maturity-criterion-2
Sep 13, 2026
Merged

bomly-guy merged 2 commits into
mainfrom
docs/maturity-criterion-2

Conversation

@bomly-guy

Copy link
Copy Markdown
Collaborator

Closes #455.

Done-criterion 2 in dev-docs/SDK_MATURITY_PLAN.md §6 read "a self-scan round trip preserves org for 24/24 packages (today: 0/24)". Searched the whole repository: no fixture, script, or test defines those 24 packages, so the criterion could not be reproduced and should not have been signed off as written.

What the criterion now says: the measurement that was taken on 2026-09-12, with the four commands to repeat it (self-scan with gomod → CycloneDX → ingest → export → export). Result: 317 components on every hop; hop 2 and hop 3 identical once serial and timestamp are stripped; 316 of 317 components carry group. The one that does not is pkg:golang/[email protected], whose module path has no organization segment, so there was nothing to preserve. The original denominator counted it as a loss.

Made into a test: TestOrgSurvivesACycloneDXRoundTripOnlyWhereItExists (internal/sbom/org_round_trip_test.go) exports a Go module with an org and one without, ingests, and asserts the first keeps github.com/spf13 with the name github.com/spf13/cobra (no doubled or lost namespace) and the second stays org-less as go4.org, and that the second hop writes the same groups as the first. TestSingleSourceExportIsAFixedPoint already pins the fixed-point half over a source document.

make verify passes.

🤖 Generated with Claude Code

…ally taken

Criterion 2 of the SDK maturity program required a self-scan round trip to
preserve org for "24/24 packages (today: 0/24)". No fixture, script, or test
behind that figure exists anywhere in the repository, so it could never be
reproduced or signed off as written.

The criterion now states the measurement that was taken, with the commands
to repeat it: a self-scan of this repository with the gomod detector,
exported to CycloneDX, ingested, exported, and exported once more. 317
components on every hop; hops 2 and 3 identical once serial and timestamp
are stripped; 316 of 317 components carry group. The one that does not is
go4.org, whose module path has no organization segment -- there was nothing
to preserve, and the original denominator counted it as a loss.

TestOrgSurvivesACycloneDXRoundTripOnlyWhereItExists pins both halves in
internal/sbom, so the criterion is a test rather than a one-off.

Closes #455.

Co-Authored-By: Claude Fable 5.1 <[email protected]>
@coderabbitai

coderabbitai Bot commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 56 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: da50c42a-cfbd-4d45-9607-d4816ad73ad2

📥 Commits

Reviewing files that changed from the base of the PR and between 6d3bcb2 and c60641e.

📒 Files selected for processing (2)
  • dev-docs/SDK_MATURITY_PLAN.md
  • internal/sbom/org_round_trip_test.go

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

Bomly Diff Summary

Compared 6d3bcb2f74136a114ed78b8c203bf28bbfd97aba to c60641ebf02249a4cce863bd58de8e2ca856bd7f.

Overview

Status Manifests Dependencies Findings Duration
✅ Pass +0 / ~0 / -0 0 added / 0 version changed / 0 detail changes / 0 removed 0 introduced / 0 persisted / 0 resolved 1m 9s

Dependency Changes

✅ No dependency changes.

Vulnerabilities

✅ No vulnerability changes.

License Changes

✅ No license changes.

Project Posture

✅ No project posture changes (--matchers +scorecard was not selected).

Policy Findings

✅ No policy differences were identified.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 708d1b2242

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/sbom/org_round_trip_test.go
Comment thread dev-docs/SDK_MATURITY_PLAN.md
…ery hop

Codex review on #462: comparing only hop 2 with hop 3 would not catch a
group dropped or rewritten on the first ingest that then stabilized. The
procedure now compares the package-URL-to-group mapping between hop 1 and
hop 2, and the scan's own org per package against hop 1; both are
identical apart from the root module, which the scan JSON does not list.

Co-Authored-By: Claude Fable 5.1 <[email protected]>
@bomly-guy
bomly-guy merged commit 94bc119 into main Sep 13, 2026
16 checks passed
@bomly-guy
bomly-guy deleted the docs/maturity-criterion-2 branch September 13, 2026 07:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Done-criterion 2 was signed off on a different measurement than the one it states

1 participant