Skip to content

docs: add a downloads & provenance guide - #95

Merged
brawer merged 1 commit into
mainfrom
bom-docs
Sep 3, 2026
Merged

docs: add a downloads & provenance guide#95
brawer merged 1 commit into
mainfrom
bom-docs

Conversation

@brawer

@brawer brawer commented Sep 3, 2026

Copy link
Copy Markdown
Owner

Phase 3 (final) of #87 — the docs.

New docs/downloads.md:

  • the three published files and their URLs (stable GeoTIFF, dated BOM, dated stats), with the keep-3 retention caveat;
  • checking for updates with HTTP conditional requests (ETag / If-None-Match);
  • one way to get the provenance record: the Link header on the GeoTIFF response → the CycloneDX BOM;
  • what the BOM records (component, tools purl, tile-logs dependency + LWG licence evidence, formulation);
  • the integrity-verification recipe;
  • recording OSMViews in a downstream data BOM — copy purl+hashes, attach a hashed bom external reference to an archived copy of ours.

Also linked from the root README (new "Downloading the data" section) and the two component READMEs, which additionally lose their stale "Release instructions" sections (obsolete prod/deploy_release.py; RELEASING.md is authoritative) and get a one-line refresh; the builder README now links the defensive publication.

docs: commit — silent, ships with the next release alongside the feat: PRs (#90, #92, #94) that introduced the dated URLs it describes.

🤖 Generated with Claude Code

@brawer
brawer force-pushed the bom-docs branch 10 times, most recently from 31f50e5 to 52b3481 Compare September 3, 2026 09:21
@brawer brawer changed the title docs: add a provenance & SBOM guide docs: add a downloads & provenance guide Sep 3, 2026
@brawer
brawer force-pushed the bom-docs branch 9 times, most recently from a93b598 to 67c4bcd Compare September 3, 2026 11:09
New docs/downloads.md: the published files and their URLs (stable
GeoTIFF, dated BOM, dated statistics) with the keep-3 retention caveat;
checking for updates with conditional requests; how to get the provenance
record (the Link header on the download → the CycloneDX BOM); what the BOM
contains; the integrity-verification recipe; and how a downstream data BOM
records which OSMViews build it consumed.

Linked from the root README (new "Downloading the data" section) and the
two component READMEs. Those also lose their stale "Release instructions"
sections (superseded by RELEASING.md) and gain a one-line refresh; the
builder README now points at the defensive publication.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0124hdGM7xKmGF3HPDy7PL6j
@brawer
brawer merged commit f56a80e into main Sep 3, 2026
8 checks passed
@brawer
brawer deleted the bom-docs branch September 3, 2026 11:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant