CI / Check (pull_request) Successful in 5m47s
CI / Detect Changes (pull_request) Has been skipped
CI / Deploy Agent (pull_request) Has been skipped
CI / Deploy Dashboard (pull_request) Has been skipped
CI / Deploy Docs (pull_request) Has been skipped
CI / Deploy MCP (pull_request) Has been skipped
Onboard a PLC/SPS target with a git repo (or source archive) of exported control logic and get the same results as an upload — the natural way CODESYS projects are version-controlled, so each scan is a git pull rather than a blob re-upload. - scan_matrix: the PLC control-logic requirement is satisfied by a PlcProject *or* a code artifact (git repo / source archive). - plan: resolve_artifact binds the PLC scan to the PlcProject if present, else the code artifact. - orchestrator: a PLC/SPS target routes to the control-logic scanner over the clone (not the SAST/semgrep pipeline), then still runs DAST for a reachable device. - plc::sbom::collect_sbom: the control-app SBOM now also comes from any `.projectarchive` committed inside the working tree (a git repo / extracted archive), in addition to an uploaded archive. Docs: new guide page "PLC / SPS (CODESYS)" documenting the best-case git repo layout (commit PLCopen XML exports for SAST + the .projectarchive for the SBOM; don't commit only the binary .project). UI: onboarding wizard shows the same guidance for PLC/SPS targets. Implements the git-ingest follow-up from #166 / #165. Tracker #167. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>