Generate a dependency inventory from resolved inputs
The package manifest lists declared ranges, not the exact dependency versions bundled into the archive.
- Focused work estimate
- 1h 30m + prerequisites
- Priority in the scenario
- Medium
- Engineering practice
- SBOM · Dependency management
Estimated field mix
- DevOps60%
- Security40%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional command-line product publishes local package archives. Builds contain timestamps, checksums are copied without provenance, and cleanup can delete the only rollback artifact. Use generated source trees, ephemeral development signing keys, and local object storage; no public registry or production key is supplied.
Setup prerequisites
- Content hashing
- Archive formats
- Release metadata
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
Acceptance criteria
- Inventory records exact package, version, integrity, and relationship
- Generation uses the resolved lock and packaged output
- Unknown or duplicate identities fail the release gate
Implementation constraints
- Do not contact public vulnerability or package services in the exercise.
Verification to include
- Generate a stable inventory for the fixture lockfile.
- Remove an integrity entry and add a duplicate package identity, then block publication.
Deliverables
- Dependency inventory generator and malformed-lock tests
Rollout and recovery
Attach inventory to local artifacts before enforcing completeness.
Value of the work
For the engineer: Practice reproducible artifacts, provenance validation, signing-key isolation and retention safety.
For the team: Review a supply path that can trace, verify, retain, and revoke artifacts without relying on mutable names.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.