Glossary
Terms in monospace are the exact values Logmarq uses in the app, the CLI, or a project's
configuration.
A
Affected — The search that answers which environments you may see report a given version, artifact digest, or vulnerability, with a separate list of the ones Logmarq cannot tell about. Customers
API token — A credential for scripts and pipelines that acts as its user with that user's role, shown once and revocable. A token can be issued read-only.
Artifact — Something a release ships: a container image, Helm chart, package, release asset, or static bundle, declared on the project and pinned to a digest when recorded. Release records
Attention — What a release line needs now: the findings on its newest release that nobody has decided, with why. Release lines
B
Backport need — A linked record that a fix on the main line has to reach a release line. It is closed by naming the line's release that carries the fix. Logmarq never performs the backport. Release lines
Bill of materials — The list of every component and version inside an artifact, stored against its digest. Also called an SBOM. Bills of materials
Branch head — What stands in for a version's commit while it has neither a tag nor a named commit. A record pinned this way says so. Release records
C
Cannot tell — The part of an affected answer listing environments Logmarq has no basis for: nothing recorded, a stale report, or a running release with no bill of materials or scan. Customers
Compare — What changed between two recorded releases, from the ledger alone: artifacts that moved to a new digest, where each repository went, and the pull requests, commits, and issues in between. Environments
Conflicting — An environment state: fresh reports disagree about which release runs there. Every side is listed. Environments
CSAF VEX — A standard document format for vulnerability decisions. A release's decisions export as CSAF 2.0 VEX. VEX
Customer — An organization whose environments only administrators and the people granted that customer can see. Customers
Customer notes — Release notes for the people who use a release, made from the internal items ticked as customer visible and checked to be a subset of them. Release notes
CycloneDX — A standard bill of materials format. An artifact's bill exports as CycloneDX with its findings and decisions. Bills of materials
D
Decision — See VEX decision.
Deployment — A report that a release runs in an environment, saying who or what made it:
manual, pipeline, observed, or unspecified. Corrected, never edited.
Environments
Digest — The content address of an artifact, such as sha256:…. A record pins artifacts by
digest so a moving tag cannot change what the record says shipped.
Release records
E
Environment — A place a release runs, such as production or a customer's installation.
Environments
F
Finding — One vulnerability in one component of an artifact, from a scan. Vulnerability scanning
Freeze — An optional lock on a release branch while a version is validated, restored when the release is released or rejected. It needs a permission you grant the host yourself.
I
Internal notes — A release's notes for the team, drafted from its changes, each item linked to the pull requests and issues it came from. Release notes
M
Maintained — The page listing every project's release lines, the ones that need someone first. Release lines
Manual step — Something an environment has to do on upgrade beyond deploying, settled per environment as done, not needed, or failed. Environments
O
OpenVEX — A standard document format for vulnerability decisions that scanners such as Grype apply. VEX
P
Project — One thing you release: its repositories, tracker, artifacts, and environments.
Public notes — Notes for anyone to read, the shape of customer notes and held to the same subset check. Release notes
Publish — Writing a release's notes as the body of its release on the git host. An explicit act that needs a permission you grant. Release notes
R
Release line — A series of versions you keep supporting after a newer one ships. Release lines
Release record — Logmarq's account of one version: its pinned source and artifacts, its changes, status, and history. Release records
Reported — An environment state: the latest report is still fresh. Environments
Rescan — A scan Logmarq runs again on a schedule for releases reported running and the newest release of each maintained line. Vulnerability scanning
Response package — A reviewed bundle you send one audience about a release, frozen on review so what was sent can be told later. Customer-response packages
S
SBOM — Software bill of materials. See Bill of materials.
SPDX — A standard bill of materials format. An artifact's bill exports as SPDX. Bills of materials
Stale — An environment state: the latest report is older than the environment's freshness window. Environments
Status — Where a release stands: recorded, validating, released, or rejected.
U
Unknown — An environment state: nothing is recorded there, or everything recorded was corrected away. Environments
Unresolved artifact — A declared artifact Logmarq could not pin to a digest, kept on the record as a warning with its reason. Release records
V
Vendor VEX — A supplier's statements about whether vulnerabilities in their component affect you. Shown beside findings, never counted as your decision until you adopt one. VEX
Version pattern — Which tags are versions, such as v*.*.*, or which versions join a release
line, such as v1.5.*. Release records
VEX decision — Your recorded answer to whether a vulnerability affects a release: not affected, affected, fixed, or under investigation. VEX