Skip to content

feat(supply-chain): retention, operations docs, and query-plan evidence - #113

Merged
balcsida merged 5 commits into
feat/supply-chain/m6-mcpfrom
feat/supply-chain/m7-operations
Sep 22, 2026
Merged

balcsida merged 5 commits into
feat/supply-chain/m6-mcpfrom
feat/supply-chain/m7-operations

Conversation

@balcsida

@balcsida balcsida commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Summary

Milestone 7 (partial; remaining items listed in the plan). Depends on #112.

  • Retention – prunes snapshots per stream beyond GRAPHNEST_SUPPLY_CHAIN_RETAIN_SNAPSHOTS (default 10) while always keeping the current snapshot and any snapshot referenced by a policy result, decision, or conclusion; removes unreferenced documents, bounds failed collection attempts (50/stream) and finished jobs (30 days); runs on the scheduler tick. Config/Compose docs/Helm values.
  • Metrics – enrichment queue depth added to the fixed-vocabulary gauges.
  • Docs – review workflow, policies, MCP tools, retention, and repository-removal behavior in the operations guide, README, CHANGELOG.
  • Pilot comparison checklist (docs/supply-chain-pilot-checklist.md) for comparing against an existing Code Insight assessment of the same repositories/builds — coverage, evidence, unknowns, conflicts, workflow gaps; explicitly not a parity claim and no migration of proprietary audit history.
  • Query-plan evidence (docs/supply-chain-query-plans.md) – opt-in integration benchmark seeding 200 repositories × 250 components (50,000 occurrences), recording EXPLAIN ANALYZE for the portfolio queries with dataset and environment named (no latency promise).

Verification

Integration test for retention (reviewed snapshot survives, latest pointer intact, unreferenced documents removed, history pruning). Full gate set at the stack head: build, fmt lint, staticcheck, govulncheck (unchanged vs main), test, test-race, postgres-test, e2e-test (×2), compose-test, helm-lint helm-test, brand-check, makefile-test abi-test tools-check, scanner-test, parity-reference, Playwright smoke, fuzzers. Not run: make image image-test; anything against a live GHES or registry.

Known gaps / next task

No review UI yet (REST only); no webhook-triggered refresh; Compose passes registry env through rather than templating it; make image not built. Next: review UI layer, then make image image-test.


Part of the Dependencies & Licenses stack (native GitHub stack #114, ten layers, main ← #104 ← #105 ← #106 ← #107 ← #108 ← #109 ← #110 ← #111 ← #112 ← #113). Design: ADR-0017; living plan with the full validation table: docs/execplans/supply-chain.md. All commits are SSH-signed. Nothing here calls a live GitHub Enterprise Server or a live package registry; GitHub and registry behavior is exercised against fixtures and fake servers only.

Stack created with GitHub Stacks CLI

@balcsida
balcsida added this pull request to stack #114 September 22, 2026 21:06
@balcsida balcsida changed the title feat/supply chain/m7 operations feat(supply-chain): retention, operations docs, and query-plan evidence Sep 22, 2026
@balcsida
balcsida force-pushed the feat/supply-chain/m7-operations branch 2 times, most recently from f657703 to 10f71bd Compare September 22, 2026 22:19
@balcsida
balcsida marked this pull request as ready for review September 22, 2026 22:20
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

balcsida and others added 5 commits September 23, 2026 00:30
…ews and MCP

Prune snapshots per stream beyond a configurable count while always
keeping the current snapshot and any snapshot referenced by a policy
result, decision, or conclusion; drop unreferenced documents, bounded
failed attempts, and old finished jobs on the scheduler tick; export
enrichment queue depth. Add GRAPHNEST_SUPPLY_CHAIN_RETAIN_SNAPSHOTS to
config, Compose docs, and the Helm chart, and document the review
workflow, policies, MCP tools, and retention in the operations guide,
README, and CHANGELOG.

Co-Authored-By: Claude <noreply@anthropic.com>
…dataset

Add an opt-in integration benchmark that seeds 200 repositories x 250
components, records EXPLAIN ANALYZE for the overview, unique-coordinate,
portfolio page, coordinate-occurrence, and review-queue queries, and
writes the evidence to docs/supply-chain-query-plans.md with the dataset
and environment named. Add the pilot comparison checklist.

Co-Authored-By: Claude <noreply@anthropic.com>
… task

Co-Authored-By: Claude <noreply@anthropic.com>
…erences

Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Claude <noreply@anthropic.com>
@balcsida
balcsida force-pushed the feat/supply-chain/m7-operations branch from 10f71bd to 30afa59 Compare September 22, 2026 22:30
@balcsida
balcsida force-pushed the feat/supply-chain/m7-operations branch 2 times, most recently from f5dea72 to 30afa59 Compare September 22, 2026 23:51
@balcsida
balcsida merged commit 0def80c into main Sep 22, 2026
16 of 24 checks passed
@balcsida balcsida mentioned this pull request Sep 23, 2026
@balcsida
balcsida deleted the feat/supply-chain/m7-operations branch September 23, 2026 07:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant