ADORSYS-GIS / ADORSYS-GIS/lightbridge-governance

[Story]: AIBOM schema mapping (SPDX 3.0 AI Profile and CycloneDX ML-BOM)

Open
#115 0 comments 0 reactions 0 assignees View on GitHub
user-story
Dominant language
Rust
Stars
1
Forks
2
Avg merge
13h 13m
Merged PRs (30d)
110

Description

## Summary
Define the AIBOM schema mapping: SPDX 3.0 AI Profile fields for external/customer-facing export, and CycloneDX ML-BOM fields for internal use, both sourced from lightbridge's actual model and dependency data.

## Intent / Source of truth
Schema definition is the prerequisite for the export pipeline; both formats are named as the 2026 procurement standard (SPDX externally, CycloneDX internally). Part of [Epic] AIBOM and model-provenance export.

## Scope
- [ ] Field-by-field mapping from ai-helm-values models.yaml/inference.yaml to SPDX 3.0 AI Profile
- [ ] CycloneDX ML-BOM mapping for internal dependency/dataset tracking
- [ ] Handling for fields ai-helm-values doesn't currently capture (identify gaps to fill upstream)

## Out of scope
- The export pipeline implementation itself (separate story)

## Verification
Schema mapping document reviewed; any identified data gaps filed as follow-up issues against the relevant source (ai-helm-values or this repo).

## Risk assessment
If a required AIBOM field has no current source in ai-helm-values, that's a real gap to flag rather than paper over with placeholder data — an inaccurate provenance field is a compliance liability.

## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.