docs consolidation work
This commit is contained in:
@@ -7,7 +7,7 @@ This repository is the source of truth for StellaOps direction. The roadmap is e
|
||||
- A capability is "done" when the required evidence exists and is reproducible (see `docs/roadmap/maturity-model.md`).
|
||||
|
||||
## Now (Foundation)
|
||||
- Deterministic scan pipeline: image -> SBOMs (SPDX 3.0.1 + CycloneDX 1.6) with stable identifiers and replayable outputs.
|
||||
- Deterministic scan pipeline: image -> SBOMs (SPDX 3.0.1 + CycloneDX 1.7) with stable identifiers and replayable outputs.
|
||||
- Advisory ingestion with offline-friendly mirrors, normalization, and deterministic merges.
|
||||
- VEX-first triage: OpenVEX ingestion/consensus with explainable, stable verdicts.
|
||||
- Policy gates: deterministic policy evaluation (OPA/Rego where applicable) with audit-friendly decision traces.
|
||||
|
||||
Reference in New Issue
Block a user