Skip to content

Review TT-PROVENANCE#128

Closed
aschemmel-tech wants to merge 1 commit intomainfrom
aschemmel-tech-patch-4
Closed

Review TT-PROVENANCE#128
aschemmel-tech wants to merge 1 commit intomainfrom
aschemmel-tech-patch-4

Conversation

@aschemmel-tech
Copy link

no impact on nlohman/json

modified assertions and evidences and added SME scores

@github-actions github-actions bot added the M label Nov 10, 2025
Signed-off-by: aschemmel-tech <aschemmel_job@arcor.de>
@coveralls
Copy link

coveralls commented Nov 10, 2025

Coverage Status

coverage: 99.186%. remained the same
when pulling e86afb8 on aschemmel-tech-patch-4
into fe309c2 on main.

@github-actions github-actions bot removed the M label Nov 11, 2025
- Record of component assessment
- List of tools used in construction and verification
- Record of tool impact assessments
- Record of tool qualification reviews
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Revisit (read up on what is expected from CodeThink)

- successful build of nlohmann/json from source
- update logs for mirrored projects
- mirrors reject history rewrites
- mirroring is configured via infrastructure under direct control No newline at end of file
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Revisit (read up on what is expected from CodeThink)

The integrator shall ensure that the build environment used for nlohmann/json is supplied with consistent dependencies in every integrating system. No newline at end of file
The integrator shall ensure that the build environment used for nlohmann/json is supplied with consistent dependencies in every integrating system.

aschemmel-tech: AOUs are supposed to be linked to TA-CONSTRAINTS. I would not know what to do as a integrator based on this. No newline at end of file
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clarify/reformulate statement.

The integrator shall ensure that integrator-controlled mirrors of the dependencies are persistently and accessibly stored as long as the library nlohmann/json is used. No newline at end of file
The integrator shall ensure that integrator-controlled mirrors of the dependencies are persistently and accessibly stored as long as the library nlohmann/json is used.

aschemmel-tech: AOUs are supposed to be linked to TA-CONSTRAINTS. No newline at end of file
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in #115

The integrator shall evaluate the provided evidence and supplement it where necessary, whenever the trustability documentation of nlohmann/json is reviewed. No newline at end of file
The integrator shall evaluate the provided evidence and supplement it where necessary, whenever the trustability documentation of nlohmann/json is reviewed.

aschemmel-tech: AOUs are supposed to be linked to TA-CONSTRAINTS No newline at end of file
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in #115


aschemmel-tech: Evidences asked for are:

- List of components used in construction of nlohman/json - this is not given by JLS-04: recommend to create this list of dependencies within another "statement"
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Revisit

- successful build of nlohmann/json from source - needs "statement" and evidence that no external source and caching is used (need to find out about caching, we qualified bazel caching)
- update logs for mirrored projects - ???
- mirrors reject history rewrites - ???
- mirroring is configured via infrastructure under direct - control covered already???
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

revisit

@aschemmel-tech
Copy link
Author

Topics taken into account in eclipse-score#9

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants