Repository navigation
docs(maturity): done-criterion 2 states the measurement that was actually taken - #462
Conversation
…ally taken Criterion 2 of the SDK maturity program required a self-scan round trip to preserve org for "24/24 packages (today: 0/24)". No fixture, script, or test behind that figure exists anywhere in the repository, so it could never be reproduced or signed off as written. The criterion now states the measurement that was taken, with the commands to repeat it: a self-scan of this repository with the gomod detector, exported to CycloneDX, ingested, exported, and exported once more. 317 components on every hop; hops 2 and 3 identical once serial and timestamp are stripped; 316 of 317 components carry group. The one that does not is go4.org, whose module path has no organization segment -- there was nothing to preserve, and the original denominator counted it as a loss. TestOrgSurvivesACycloneDXRoundTripOnlyWhereItExists pins both halves in internal/sbom, so the criterion is a test rather than a one-off. Closes #455. Co-Authored-By: Claude Fable 5.1 <[email protected]>
|
Warning Review limit reachedNext included review available in 56 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Bomly Diff SummaryCompared Overview
Dependency Changes✅ No dependency changes. Vulnerabilities✅ No vulnerability changes. License Changes✅ No license changes. Project Posture✅ No project posture changes ( Policy Findings✅ No policy differences were identified. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 708d1b2242
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…ery hop Codex review on #462: comparing only hop 2 with hop 3 would not catch a group dropped or rewritten on the first ingest that then stabilized. The procedure now compares the package-URL-to-group mapping between hop 1 and hop 2, and the scan's own org per package against hop 1; both are identical apart from the root module, which the scan JSON does not list. Co-Authored-By: Claude Fable 5.1 <[email protected]>
Closes #455.
Done-criterion 2 in
dev-docs/SDK_MATURITY_PLAN.md§6 read "a self-scan round trip preservesorgfor 24/24 packages (today: 0/24)". Searched the whole repository: no fixture, script, or test defines those 24 packages, so the criterion could not be reproduced and should not have been signed off as written.What the criterion now says: the measurement that was taken on 2026-09-12, with the four commands to repeat it (self-scan with
gomod→ CycloneDX → ingest → export → export). Result: 317 components on every hop; hop 2 and hop 3 identical once serial and timestamp are stripped; 316 of 317 components carrygroup. The one that does not ispkg:golang/[email protected], whose module path has no organization segment, so there was nothing to preserve. The original denominator counted it as a loss.Made into a test:
TestOrgSurvivesACycloneDXRoundTripOnlyWhereItExists(internal/sbom/org_round_trip_test.go) exports a Go module with an org and one without, ingests, and asserts the first keepsgithub.com/spf13with the namegithub.com/spf13/cobra(no doubled or lost namespace) and the second stays org-less asgo4.org, and that the second hop writes the same groups as the first.TestSingleSourceExportIsAFixedPointalready pins the fixed-point half over a source document.make verifypasses.🤖 Generated with Claude Code