Skip to content

Feature: Add product releases and artifact-to-product mapping #303

Description

@JustNZ

Release

Release 2 — VEX and remediation operations

Goal

Give VEX, remediation, support-period, and regulatory evidence an exact product scope instead of treating each image scan as an isolated artifact.

Scope

  • Add products, product releases, owners, support start/end dates, and lifecycle state.
  • Map releases to image digests, SBOMs, Helm sources, and Git repository revisions.
  • Preserve immutable historical mappings when tags move.
  • Add product/release views and API endpoints.
  • Allow organization policy and reporting to scope by product or release.

Acceptance criteria

  • One release can reference multiple platform-specific image digests.
  • A digest can be traced to its product release and source revision.
  • Moving tags do not rewrite historical product evidence.
  • Permissions follow existing organization ownership rules.
  • Existing scans remain usable when they have not yet been assigned to a product.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions