From 27080475c1e7382593a8a7f6f847330403d943b9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?D=C3=A1vid=20Balatoni?= Date: Tue, 22 Sep 2026 22:30:44 +0200 Subject: [PATCH 1/5] feat(supply-chain): add review-preserving retention and document reviews and MCP Prune snapshots per stream beyond a configurable count while always keeping the current snapshot and any snapshot referenced by a policy result, decision, or conclusion; drop unreferenced documents, bounded failed attempts, and old finished jobs on the scheduler tick; export enrichment queue depth. Add GRAPHNEST_SUPPLY_CHAIN_RETAIN_SNAPSHOTS to config, Compose docs, and the Helm chart, and document the review workflow, policies, MCP tools, and retention in the operations guide, README, and CHANGELOG. Co-Authored-By: Claude --- CHANGELOG.md | 14 ++++ README.md | 2 + cmd/graphnest-server/main.go | 12 ++++ deploy/helm/graphnest/ci/optional-values.yaml | 1 + .../helm/graphnest/templates/configmaps.yaml | 1 + deploy/helm/graphnest/tests/render.sh | 1 + deploy/helm/graphnest/values.schema.json | 3 +- deploy/helm/graphnest/values.yaml | 2 + docs/operations.md | 54 +++++++++++++++- internal/config/config.go | 16 ++++- internal/config/supply_chain_test.go | 5 +- internal/postgres/supply_chain.go | 53 +++++++++++++++ internal/postgres/supply_chain_test.go | 64 +++++++++++++++++++ 13 files changed, 221 insertions(+), 7 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index f3cb196c..c8c31ecc 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -45,6 +45,20 @@ the compatibility and migration notes before upgrading. (`GET /v1/supply-chain/exports/{id}/derived.spdx.json`) names GraphNest as creator, links the preserved original, and carries assessments as comments only. Migration 035 adds imports and upload grants. +- Review workflows: a queue of occurrences needing review, human license + conclusions recorded as immutable evidence, scoped approve/reject/exception + decisions with optimistic concurrency on the evidence fingerprint + (`409 stale_basis`), versioned policies evaluated over the SPDX expression + tree with a clearly labelled example fixture and no auto-approval of + unknowns, repository-scoped review grants, and an append-only audit trail + under `/v1/supply-chain/review/*` and `/v1/supply-chain/policies`. + Migration 036 adds the review tables. +- Read-only MCP tools `search_dependency_inventory`, + `find_component_repositories`, and `inspect_component_license` over the + same authorized services as REST. +- Retention for inventory snapshots (`GRAPHNEST_SUPPLY_CHAIN_RETAIN_SNAPSHOTS`) + that always preserves the current snapshot and any snapshot referenced by + a review record, plus bounded collection and job history. ## [0.5.0] - 2026-09-18 diff --git a/README.md b/README.md index 8d569ebc..8f1a18cf 100644 --- a/README.md +++ b/README.md @@ -213,6 +213,8 @@ What the inventory is and is not: - A failed refresh (403, 404, rate limit, malformed or oversized document, outage) records a collection attempt and leaves the last successful snapshot in place; the status reports `collection: failed` alongside the retained inventory. - Inventory eligibility is repository authorization alone. It works for repositories with no Zoekt index, no SCIP upload, and no graph enrichment, and inventory work never blocks lexical indexing. +License review is a separate, auditable layer: reviewers with a repository-scoped grant record human conclusions and approve/reject/exception decisions against the exact evidence they saw (a changed evidence fingerprint is refused), versioned policies are evaluated over the SPDX expression tree (the shipped policy is a labelled example, and unknown licensing never auto-approves), and three read-only MCP tools expose the inventory to agents through the same authorization as REST. + SBOMs produced elsewhere (Syft, ORT, or any tool writing SPDX 2.3 JSON or CycloneDX 1.6 JSON) can be imported into separate `import::