CoolFace
Datasetpublic

SZLHOLDINGS/model-bom

SZLHOLDINGS Model BOM Registry Canonical CycloneDX 1.5 Model BOM registry for all 44 public models under the SZLHOLDINGS organization. Provenance Generated 2026-08-30 by szl_estate_audit from live Hugging Face Hub metadata (model listings, repository file siblings, and card data). Each BOM is a pretty-printed CycloneDX 1.5 JSON document carrying a unique urn:uuid serial number. File layout bom-index.json - machine-readable index: one entry per… See the full description on the dataset page: https://huggingface.co/datasets/SZLHOLDINGS/model-bom.

sourceHugging Faceotherupdated 25d agoView on Hugging Face
0likes378downloads
Dataset Card

SZLHOLDINGS Model BOM Registry

Canonical CycloneDX 1.5 Model BOM registry for all 44 public models under the SZLHOLDINGS organization.

Provenance

Generated 2026-08-30 by szl_estate_audit from live Hugging Face Hub metadata (model listings, repository file siblings, and card data). Each BOM is a pretty-printed CycloneDX 1.5 JSON document carrying a unique urn:uuid serial number.

File layout

  • —bom-index.json - machine-readable index: one entry per model with model (full Hub id), bom (BOM file name), and sha256 of the exact BOM bytes.
  • —models/<name>.cdx.json - one Model BOM per model repo, where <name> is the model repository name under SZLHOLDINGS (44 files total).

What each BOM records

  • —metadata.component (type machine-learning-model): bom-ref hf:SZLHOLDINGS/<name>, declared license, an external reference to the Hub page, and audit properties: szl:base_model, szl:downloads, szl:likes, szl:last_modified, szl:pipeline_tag, szl:heldout_eval, szl:publication_eligible.
  • —components[]: every file in the model repository, each annotated with a governance role (weights, config, documentation, support).
  • —dependencies[]: the model's dependency closure over its own repository files.

Doctrine gate: szl:publication_eligible

szl:publication_eligible=false (with szl:heldout_eval = "MISSING - required before publication") marks a model that is tracked in the estate but not cleared for publication under SZL doctrine: a held-out evaluation receipt must be attached and verified before the flag can flip to true. Values reflect Hub state at audit time (2026-08-30).

Per-repo copies

The same BOM is intended to live at bom/model-bom.cdx.json inside each model repository. Those per-repo writes are additive-only (never overwriting existing files) and are currently pending a write-scoped credential for models/SZLHOLDINGS/*; they will land once that authorization exists. Until then, this dataset is the canonical registry of record.

Refresh log

  • —2026-08-31: additive refresh. Added models/szl-energy-attest.cdx.json for SZLHOLDINGS/szl-energy-attest (created 2026-08-31), bringing coverage to 44/44 public models. The new BOM follows the same CycloneDX 1.5 schema (build_model_bom 1.0.0 conventions) and was built from live Hub metadata read via the HF connector; the bom-index.json sha256 is over the exact uploaded bytes. The other 43 BOMs are unchanged from the 2026-08-30 szl_estate_audit generation.
  • —2026-08-31 (second pass, estate alignment): DATASET_LICENSE_REGISTER.csv extended 28 → 30 rows so the register covers all 30 public datasets. Added SZLHOLDINGS/model-bom (self-listing for inventory completeness) and SZLHOLDINGS/szl-frontier-covenant (REVIEW-REQUIRED pending content audit). Model coverage unchanged at 44/44. Live Hub enumeration at commit time, read via the HF API and connector listing: 44 models / 30 datasets / 47 Spaces. Register sha256 at this refresh: eba61399702c794b75aeb82b7d0a233f460fa7910cc431f2e4c0436932b035c0.