703 B
703 B
1. Red deterministic contract
- 1.1 Add a focused test requiring SPDX 2.3 fields, source/Protocol/module relationships, two architectures, and exact artifact hashes
- 1.2 Prove current packaging cannot produce the required standard SBOM
2. Standard-library generator
- 2.1 Implement bounded deterministic SPDX JSON generation from explicit build and Go module metadata
- 2.2 Record truthful license fields, notices/provenance, unscanned status, and no signing claim
3. Verification
- 3.1 Prove byte-stable regeneration and rejection of dirty, missing, mismatched, or ambiguous inputs
- 3.2 Reconcile the deployment-artifact canonical spec and run strict validation