ADORSYS-GIS / ADORSYS-GIS/lightbridge-governance
[Story]: AIBOM schema mapping (SPDX 3.0 AI Profile and CycloneDX ML-BOM)
- Dominant language
- Rust
- Stars
- 1
- Forks
- 2
- Avg merge
- 13h 13m
- Merged PRs (30d)
- 110
Description
## Summary
Define the AIBOM schema mapping: SPDX 3.0 AI Profile fields for external/customer-facing export, and CycloneDX ML-BOM fields for internal use, both sourced from lightbridge's actual model and dependency data.
## Intent / Source of truth
Schema definition is the prerequisite for the export pipeline; both formats are named as the 2026 procurement standard (SPDX externally, CycloneDX internally). Part of [Epic] AIBOM and model-provenance export.
## Scope
- [ ] Field-by-field mapping from ai-helm-values models.yaml/inference.yaml to SPDX 3.0 AI Profile
- [ ] CycloneDX ML-BOM mapping for internal dependency/dataset tracking
- [ ] Handling for fields ai-helm-values doesn't currently capture (identify gaps to fill upstream)
## Out of scope
- The export pipeline implementation itself (separate story)
## Verification
Schema mapping document reviewed; any identified data gaps filed as follow-up issues against the relevant source (ai-helm-values or this repo).
## Risk assessment
If a required AIBOM field has no current source in ai-helm-values, that's a real gap to flag rather than paper over with placeholder data — an inaccurate provenance field is a compliance liability.
## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.
Contributor guide
Assessment
This issue has not been assessed yet.