At a glance
| Input | Action | Output | Limit |
|---|---|---|---|
| Source revision and policy version | Validate stable manifest context | Revision-bound import identity | Values must meet bounded contract rules |
| Observed terms and findings | Validate manifest records | Report-only evidence | Maximum 1,000 terms |
| JSON file | Load and import it | Import summary and findings | Maximum 256 KB |
| Repeated identical manifest | Reuse prior identity | Idempotent result | Changed evidence needs a new manifest |
How it works
- Generate the supported JSON manifest for one source revision.
- Open Offline Manifest Sync.
- Choose the local manifest file.
- Review the JSON before import.
- Select Import manifest.
- Review the import summary and findings.
Example
A restricted build environment creates a manifest for one commit and policy version. An administrator imports it without granting ongoing repository access. Findings remain tied to that supplied revision and do not change the source repository.
What this does not mean
The manifest is supplied evidence. Compliance Glossary does not inspect the source repository during offline import or prove that the generator covered every file. Protect the generation process.
Related questions
Next step
Generate each manifest inside the controlled source pipeline.
View on Atlassian Marketplace