Skip to content

Latest commit

 

History

History
64 lines (58 loc) · 7.16 KB

File metadata and controls

64 lines (58 loc) · 7.16 KB

Architecture Decision Records

This directory holds Bomly's architecture decision records (ADRs): one file per decision, numbered chronologically by the date the decision was first recorded. Decisions migrated from the old inline decision log in ../ARCHITECTURE.md keep their original free-form prose; new decisions follow the template.

To record a new decision:

  1. Copy TEMPLATE.md to NNNN-<kebab-case-title>.md, using the next unused number.
  2. Fill in the date, status, and sections.
  3. Add a row to the index below.

To revise a decision, add a new ADR that supersedes it and set the old ADR's status to Superseded by [ADR-NNNN](NNNN-slug.md); do not rewrite history (typo and clarity fixes are fine).

Index

ID Date Title Status
ADR-0001 2026-05-14 Reachability annotates vulnerabilities, not findings Accepted
ADR-0002 2026-05-28 Scorecard matcher reads precomputed runs, not the library Accepted
ADR-0003 2026-05-30 YAML configuration is nested at the file boundary Accepted
ADR-0004 2026-05-31 Dependency graph benchmarking is hidden and local-only Accepted
ADR-0005 2026-06-01 Reachability analyzers derive local hierarchy closures Accepted
ADR-0006 2026-06-04 Three-collection domain model — dependencies, packages, findings Accepted
ADR-0007 2026-06-25 Package locations are detector-relative today Accepted
ADR-0008 2026-07-07 Python graph resolution is lockfile-first, validated, and provenance-backed Accepted
ADR-0009 2026-07-07 Detector fallbacks are loud, annotated degradations Accepted
ADR-0010 2026-07-07 Detector logs are request-scoped by subproject Accepted
ADR-0011 2026-07-08 JSON findings are references; MCP responses are compact projections Accepted
ADR-0012 2026-07-13 Recursive discovery prunes native multi-module roots per package manager Accepted
ADR-0013 2026-07-14 Subprojects and modules are distinct concepts, derived in views Accepted
ADR-0014 2026-07-14 Per-module manifest emission lives in detectors, not consolidation Accepted
ADR-0015 2026-07-17 Registry matching eligibility is an occurrence-level engine boundary Accepted
ADR-0016 2026-07-17 Unresolved dependency parents use an explicit unknown relationship Accepted
ADR-0017 2026-07-17 Bun text lockfiles are native; binary lockfiles degrade explicitly Accepted
ADR-0018 2026-07-23 Enrichment consolidates alias-equivalent vulnerabilities Accepted
ADR-0019 2026-07-23 Finding policy-status resolution belongs inside audit Accepted
ADR-0020 2026-07-25 Repository configuration requires explicit trust Accepted
ADR-0021 2026-07-25 External lookups use Coordinates.EcosystemName(), never the bare Name Accepted
ADR-0022 2026-07-25 Vulnerability remediation is derived enrichment Accepted
ADR-0023 2026-07-25 Grype OS-package distro comes from the PURL, not pipeline plumbing Accepted
ADR-0024 2026-07-26 One typed detector-warning channel, no CI-readiness stage Accepted
ADR-0025 2026-07-26 The discovery probe attributes a skip reason per candidate Accepted
ADR-0026 2026-07-27 Untrusted documents have input limits Accepted
ADR-0027 2026-07-28 Dependency detail changes are canonical diff results Accepted
ADR-0028 2026-08-08 Startup banner frames are procedural; animation is opt-in; gating is env-var-only Accepted
ADR-0029 2026-08-12 Shared helper code lives in bomly-sdk subpackages, not CLI-internal packages Accepted
ADR-0030 2026-08-13 External-integration components live in their own repositories, consumed as ordinary Go modules Accepted
ADR-0031 2026-08-13 Syft-JSON SBOM ingest is removed; treated as any unsupported format Accepted
ADR-0032 2026-08-14 SBOM exports carry a synthesized primary component and shared document identity Accepted
ADR-0033 2026-08-24 Package origin is detector-asserted; SBOM export only projects it Accepted
ADR-0034 2026-08-24 Decisions are recorded as individual ADRs Accepted
ADR-0035 2026-08-25 License emission is validated, not assumed Accepted
ADR-0036 2026-08-26 Dependency identity is content-addressable and SDK-derived Superseded by ADR-0041
ADR-0037 2026-08-26 SBOM assertions are typed SDK model fields, not metadata keys Accepted
ADR-0038 2026-08-26 PURL and SPDX behavior have one home in the SDK Accepted
ADR-0039 2026-08-26 Both modules build on Go 1.27; untrusted JSON parses strictly Accepted
ADR-0040 2026-08-26 The SDK is the default home for behavior Accepted
ADR-0041 2026-08-29 Identity is the canonical PURL on typed graph nodes Accepted