diff --git a/CHANGELOG.md b/CHANGELOG.md index c8c31ecc..6ea2928b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,34 @@ the compatibility and migration notes before upgrading. ## [Unreleased] +## [0.6.0] - 2026-09-23 + +This release adds the opt-in Dependencies & Licenses module: a preserved +inventory of each managed repository's GitHub dependency-graph SBOM export, +exact-version license evidence from explicitly configured package registries, +portfolio queries and exports, standards-based SBOM imports, review workflows, +and read-only MCP tools. Everything is disabled by default; with +`GRAPHNEST_SUPPLY_CHAIN` unset the server behaves as in v0.5.0 apart from the +additive migrations below. + +### Upgrade guidance + +- Migrations 033 through 036 add the `supply_chain_*` tables; they run + automatically at startup, cascade from `repositories`, and touch nothing + else. No configuration changes are required. ([#105], [#108], [#110], [#111]) +- The module is opt-in and durable-mode only: set `GRAPHNEST_SUPPLY_CHAIN=true` + (Helm: `server.supplyChain.enabled`) to start collection. It never contacts + a package registry unless a `GRAPHNEST_SUPPLY_CHAIN_REGISTRY__URL` + route is configured, and a GitHub dependency-graph export is always reported + as an unbound observation (`subject_assurance: unknown`) with `NOASSERTION`, + `NONE`, and `UNLICENSED` never mapped to a license. ([#106], [#108]) +- Snapshot retention defaults to ten snapshots per stream + (`GRAPHNEST_SUPPLY_CHAIN_RETAIN_SNAPSHOTS`); the current snapshot and any + snapshot referenced by a review record are always kept. ([#113]) +- The GitHub dependency-graph collector has been exercised against recorded + GHES fixtures only; live GHES and registry behaviour still require + environment-specific validation (`docs/supply-chain-pilot-checklist.md`). + ### Added - Opt-in Dependencies & Licenses inventory (`GRAPHNEST_SUPPLY_CHAIN=true`, @@ -18,6 +46,7 @@ the compatibility and migration notes before upgrading. (`subject_assurance: unknown`) and license fields are preserved verbatim. Migration 033 adds the `supply_chain_*` tables; with the module disabled nothing else changes. See ADR-0017 and `docs/execplans/supply-chain.md`. + ([#104], [#105], [#106], [#107]) - Exact-version license evidence for npm, NuGet, and Maven components from explicitly configured registry routes (`GRAPHNEST_SUPPLY_CHAIN_REGISTRY_*`), parsed with a bounded SPDX 2.3 expression parser against the pinned SPDX @@ -27,14 +56,14 @@ the compatibility and migration notes before upgrading. or unknown and are shown in the component table and a new evidence detail view (`GET /v1/supply-chain/repositories/{id}/component`). No route means no outbound license traffic. Migration 034 adds the evidence, enrichment-job, - and assessment tables. + and assessment tables. ([#108]) - Portfolio read APIs over the caller's authorized repositories: an overview whose every count names its denominator, keyset-paginated unique coordinates with ecosystem, search, license, and assessment filters, bounded facets, a coordinate detail listing authorized occurrences, a CSV export with provenance columns and formula-safe cells, and a snapshot comparison that separates component, declared-license, and edge changes - from document metadata changes. + from document metadata changes. ([#109]) - Standards-based imports of SPDX 2.3 JSON and CycloneDX 1.6 JSON into declared `import::