ADORSYS-GIS / ADORSYS-GIS/lightbridge-governance

[Story]: Customer-facing self-serve AIBOM download and API

オープン
#117 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
user-story
主要言語
Rust
スター
1
フォーク
2
平均マージ
13時間 13分
マージ済み PR(30日)
110

説明

## Summary
Build a customer-facing self-serve AIBOM download/API so an enterprise customer's security team can pull the current AIBOM on demand for their own compliance review.

## Intent / Source of truth
The AIBOM is only useful commercially if customers can actually get it without a manual request-and-wait cycle. Part of [Epic] AIBOM and model-provenance export.

## Scope
- [ ] Authenticated download endpoint (per-org scoped, showing only models/services relevant to that customer's deployment)
- [ ] API access for programmatic retrieval (customer's own compliance tooling)
- [ ] Format selection (SPDX 3.0 AI Profile vs CycloneDX)

## Out of scope
- Public/unauthenticated AIBOM access

## Verification
A test customer account can download a correctly-scoped AIBOM in both supported formats via UI and API.

## Risk assessment
Scoping must ensure a customer only sees the AIBOM relevant to their own tenancy/deployment, not the full internal catalog across all customers.

## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。