Context
README shows vg sbom delta --from … --to … but contributors still ask what “changed” means (components added/removed/version-bumped vs vulnerability delta) and how to gate CI on the text/JSON output locally.
What to do
- Document
vg sbom delta inputs (--from / --to artifacts), output shape, and typical CI usage next to vg baseline / scan gates.
- Clarify that this is an inventory delta, not a compliance attestation.
- Give one copy-pasteable local example using files under
.vibgrate/.
Acceptance
Context
README shows
vg sbom delta --from … --to …but contributors still ask what “changed” means (components added/removed/version-bumped vs vulnerability delta) and how to gate CI on the text/JSON output locally.What to do
vg sbom deltainputs (--from/--toartifacts), output shape, and typical CI usage next tovg baseline/ scan gates..vibgrate/.Acceptance
vgonly; no secrets or cloud-required stepsgit commit -s)