Skip to content

Docs: document vg sbom delta semantics and CI usage #254

Description

@vibgrate-team

Context

README shows vg sbom delta --from … --to … but contributors still ask what “changed” means (components added/removed/version-bumped vs vulnerability delta) and how to gate CI on the text/JSON output locally.

What to do

  • Document vg sbom delta inputs (--from / --to artifacts), output shape, and typical CI usage next to vg baseline / scan gates.
  • Clarify that this is an inventory delta, not a compliance attestation.
  • Give one copy-pasteable local example using files under .vibgrate/.

Acceptance

  • Public docs cover flags, exit behavior (if any), and example
  • Uses vg only; no secrets or cloud-required steps
  • Cross-links SBOM export docs
  • DCO sign-off (git commit -s)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationgood first issueGood for newcomers

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions