generated from coulomb/repo-seed
Implements CUST-WP-0007. Resolves inconsistencies I-1, I-2, I-5, I-6
identified in the GEMS audit (GenericEntityModellingSystem.md).
Pass 1 (e1f2a3b4c5d6): domain_id FK on extension_points and
technical_debt (replaces raw string column); repo_id FK on contributions.
Fixes domain-filtering bugs in EP/TD dashboard pages.
Pass 2 (f2a3b4c5d6e7): repo_id nullable FK on workstreams, aligning
the GEMS primary attachment with ADR-001 (repo > topic). Dashboard
pages updated to prefer repo->domain over topic->domain.
Pass 3 (a3b4c5d6e7f8): SBOMSnapshot container entity (GEMS Complex
between Repository and SBOMEntry). Ingest is now additive — each call
creates a new snapshot; history is retained. List/report endpoints
filter to latest snapshot per repo via _latest_snapshot_ids_subquery().
New endpoints: GET /sbom/snapshots/, GET /sbom/snapshots/{id}/.
Dashboard gains a Snapshot History section.
Also adds GEMS analysis artefacts: wiki/GEMS-StateHub-TypeRegistry.md,
wiki/GEMS-StateHub-SWOT.md, workplans/CUST-WP-0006 (analysis),
workplans/CUST-WP-0007 (migration, now completed).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
57 lines
2.0 KiB
Python
57 lines
2.0 KiB
Python
import enum
|
|
import uuid
|
|
from datetime import datetime
|
|
|
|
from sqlalchemy import Boolean, DateTime, Enum, ForeignKey, String
|
|
from sqlalchemy.dialects.postgresql import UUID
|
|
from sqlalchemy.orm import Mapped, mapped_column, relationship
|
|
|
|
from api.models.base import Base, new_uuid
|
|
|
|
|
|
class Ecosystem(str, enum.Enum):
|
|
python = "python"
|
|
node = "node"
|
|
rust = "rust"
|
|
go = "go"
|
|
java = "java"
|
|
other = "other"
|
|
|
|
|
|
class SBOMEntry(Base):
|
|
"""Snapshot-based SBOM entry — no updated_at; new ingest replaces old rows."""
|
|
__tablename__ = "sbom_entries"
|
|
|
|
id: Mapped[uuid.UUID] = mapped_column(
|
|
UUID(as_uuid=True), primary_key=True, default=new_uuid
|
|
)
|
|
repo_id: Mapped[uuid.UUID] = mapped_column(
|
|
UUID(as_uuid=True), ForeignKey("managed_repos.id", ondelete="RESTRICT"),
|
|
nullable=False, index=True,
|
|
)
|
|
package_name: Mapped[str] = mapped_column(String(300), nullable=False)
|
|
package_version: Mapped[str | None] = mapped_column(String(100), nullable=True)
|
|
ecosystem: Mapped[Ecosystem] = mapped_column(
|
|
Enum(Ecosystem, name="ecosystem"), nullable=False
|
|
)
|
|
license_spdx: Mapped[str | None] = mapped_column(String(100), nullable=True)
|
|
is_direct: Mapped[bool] = mapped_column(Boolean, nullable=False, default=True)
|
|
is_dev: Mapped[bool] = mapped_column(Boolean, nullable=False, default=False)
|
|
snapshot_id: Mapped[uuid.UUID] = mapped_column(
|
|
UUID(as_uuid=True),
|
|
ForeignKey("sbom_snapshots.id", ondelete="RESTRICT"),
|
|
nullable=False,
|
|
index=True,
|
|
)
|
|
snapshot_at: Mapped[datetime] = mapped_column(
|
|
DateTime(timezone=True), nullable=False
|
|
)
|
|
created_at: Mapped[datetime] = mapped_column(
|
|
DateTime(timezone=True), nullable=False
|
|
)
|
|
|
|
repo: Mapped["ManagedRepo"] = relationship("ManagedRepo", lazy="selectin") # noqa: F821
|
|
snapshot: Mapped["SBOMSnapshot"] = relationship( # noqa: F821
|
|
"SBOMSnapshot", lazy="selectin", back_populates="entries"
|
|
)
|