Differences
This shows you the differences between two versions of the page.
| dido:99_annexes:annex-b-terms-and-definitions:d:dependency_manifest [2026/07/13 12:33] – created nick_dido | dido:99_annexes:annex-b-terms-and-definitions:d:dependency_manifest [2026/07/18 12:33] (current) – external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 5: | Line 5: | ||
| ===== Discussion ===== | ===== Discussion ===== | ||
| - | A Dependency Manifest is a machine-processable record that identifies the [[dido: | + | A Dependency Manifest is a machine-processable record that identifies the [[dido: |
| - | The manifest may record dependency names, versions, types, source locations, integrity values, licenses, provenance, relationships, | + | The manifest may record dependency names, versions, types, source locations, integrity values, licenses, provenance, relationships, |
| A Dependency Manifest supports verification, | A Dependency Manifest supports verification, | ||
| Line 15: | Line 15: | ||
| ===== Definition ===== | ===== Definition ===== | ||
| - | // | + | // |
| ===== Source ===== | ===== Source ===== | ||
| - | Generalized from software bills of materials, package manifests, dependency lock files, supply-chain records, and artefact | + | Generalized from software bills of materials, package manifests, dependency lock files, supply-chain records, and artifact |
| ===== Note ===== | ===== Note ===== | ||
| Line 29: | Line 29: | ||
| ===== Example ===== | ===== Example ===== | ||
| - | A Crucible Dependency Manifest records the installation medium, operating-system packages, provider packages, container images, infrastructure repository revisions, compliance | + | A Crucible Dependency Manifest records the installation medium, operating-system packages, provider packages, container images, infrastructure repository revisions, compliance |
| ---- | ---- | ||