Skip to content

Commit 237769b

Browse files
committed
Explaining the Policy handling and the default one
1 parent 2c202f7 commit 237769b

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

docs/adrs/00014-enterprise-contract-integration.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,8 @@ Users need the ability to:
2828
We will integrate Conforma into Trustify as a user triggered validation service by interacting with Conforma CLI.
2929
Validation is manually triggered — not automatic on SBOM upload.
3030
Validation on upload is deferred to a follow-up version.
31+
Trustify stores information to identify (id, name, URL) of Policies.
32+
A defaut Policy is defined at the application level which will be the Policy used for validation if a SBOM doesn't have a Policy attached to it.
3133

3234
Conforma CLI is deployed separately from Trustify as either a standalone container or equivalent.
3335
An EC Wrapper (HTTP service) acts as a proxy between Trustify's EC service and Conforma CLI.

0 commit comments

Comments
 (0)