Show pageOld revisionsBacklinksAdd to bookExport to PDFODT exportBack to top This page is read only. You can view the source, but not change it. Ask your administrator if you think this is wrong. ====== Dependency Record ====== [[dido:99_annexes:annex-b-terms-and-definitions:start|Go up to Terms and Definitions]] ===== Discussion ===== A Dependency Record is a controlled information record that identifies and describes a [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency|Dependency]] and its relevant technical, legal, provenance, integrity, lifecycle, and usage characteristics. The record may identify the Dependency name, type, version, source, supplier, license, integrity value, storage location, capture time, applicable platform, consuming process, associated artifact, and [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]]. A Dependency Record allows a build, deployment, transfer, verification, or governance process to reason about a Dependency without inspecting the complete dependency content. One or more Dependency Records may form a [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency_manifest|Dependency Manifest]]. ===== Definition ===== //controlled information record that identifies and describes a [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency|dependency]] and its relevant technical, legal, provenance, integrity, lifecycle, and usage characteristics// ===== Source ===== Generalized from dependency management, configuration-item records, package metadata, software supply-chain records, and artifact inventories and specialized for the Crucible architecture and operational model. ===== Note ===== A Dependency Record is not the Dependency itself. The record provides information required to identify, locate, verify, assess, transfer, or govern the Dependency. A single Dependency may have several Dependency Records when different versions, sources, platforms, or lifecycle contexts apply. ===== Example ===== A Dependency Record identifies a specific operating-system package by name, version, source repository, cryptographic digest, license, capture time, and the [[dido:99_annexes:annex-b-terms-and-definitions:i:image_build|Image Build]] that consumed it. ---- <WRAP centeralign> © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. </WRAP> dido/99_annexes/annex-b-terms-and-definitions/d/dependency_record.txt Last modified: 2026/07/18 12:33by 127.0.0.1