Skip to content

feat: trace quotation source provenance - #8

Merged
yigitcan-ozturk merged 4 commits into
mainfrom
feature/quotation-provenance
Aug 28, 2026
Merged

yigitcan-ozturk merged 4 commits into
mainfrom
feature/quotation-provenance

Conversation

@yigitcan-ozturk

Copy link
Copy Markdown
Owner

What changed

  • attach namespaced rfqdiff_source provenance to every file-loaded quotation
  • record source filename, input format and SHA-256 fingerprint
  • record CSV row numbers and XLSX row/sheet locations
  • reserve rfqdiff_source so input data cannot spoof tool-generated provenance
  • carry provenance through scoring and machine-readable JSON output
  • add source provenance columns to CSV/XLSX comparison reports
  • add dedicated provenance tests and adapt quote-loading coverage
  • document integrity scope and remove provenance from the roadmap

Compatibility

  • scoring semantics and configurable weights are unchanged
  • existing upstream metadata such as currency normalization remains preserved
  • only file-loaded quotations gain the additive rfqdiff_source field
  • full local filesystem paths are not embedded in output

Security and audit boundary

The SHA-256 fingerprint supports input integrity and traceability. It is not a digital signature and does not prove quotation authorship or approval.

Why

Procurement comparisons need a reproducible link between a scored supplier row and the input artifact that produced it. This adds that traceability without turning rfqdiff into a document-authentication system.

@yigitcan-ozturk
yigitcan-ozturk merged commit 235081a into main Aug 28, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant