Files
git.stella-ops.org/docs/implplan/SPRINT_130_scanner_surface.md
master 69c59defdc
Some checks failed
Docs CI / lint-and-preview (push) Has been cancelled
feat: Implement Runtime Facts ingestion service and NDJSON reader
- Added RuntimeFactsNdjsonReader for reading NDJSON formatted runtime facts.
- Introduced IRuntimeFactsIngestionService interface and its implementation.
- Enhanced Program.cs to register new services and endpoints for runtime facts.
- Updated CallgraphIngestionService to include CAS URI in stored artifacts.
- Created RuntimeFactsValidationException for validation errors during ingestion.
- Added tests for RuntimeFactsIngestionService and RuntimeFactsNdjsonReader.
- Implemented SignalsSealedModeMonitor for compliance checks in sealed mode.
- Updated project dependencies for testing utilities.
2025-11-10 07:56:15 +02:00

2.8 KiB

Sprint 130 - Scanner & Surface

Phase focus: Scanner.I — Deno analyzer bring-up.

  • Depends on: Sprint 110.A · AdvisoryAI (schema + advisory feeds)
  • Feeds: Sprint 131 (Scanner.II) once artifacts below land.

Execute the tasks below strictly in order; each artifact unblocks the next analyzer stage.

Order Task ID State Summary Owner / Source Depends On
1 SCANNER-ANALYZERS-DENO-26-001 DONE Build the deterministic input normalizer + VFS merger for deno.json(c), import maps, lockfiles, vendor trees, $DENO_DIR, and OCI layers so analyzers have a canonical file view. Deno Analyzer Guild (src/Scanner/StellaOps.Scanner.Analyzers.Lang.Deno)
2 SCANNER-ANALYZERS-DENO-26-002 DONE Implement the module graph resolver covering static/dynamic imports, npm bridge, cache lookups, built-ins, WASM/JSON assertions, and annotate edges with their resolution provenance. Deno Analyzer Guild (src/Scanner/StellaOps.Scanner.Analyzers.Lang.Deno) SCANNER-ANALYZERS-DENO-26-001
3 SCANNER-ANALYZERS-DENO-26-003 DONE Ship the npm/node compatibility adapter that maps npm: specifiers, evaluates exports conditionals, and logs builtin usage for policy overlays. Deno Analyzer Guild (src/Scanner/StellaOps.Scanner.Analyzers.Lang.Deno) SCANNER-ANALYZERS-DENO-26-002
4 SCANNER-ANALYZERS-DENO-26-004 DONE Add the permission/capability analyzer covering FS/net/env/process/crypto/FFI/workers plus dynamic-import + literal fetch heuristics with reason codes. Deno Analyzer Guild (src/Scanner/StellaOps.Scanner.Analyzers.Lang.Deno) SCANNER-ANALYZERS-DENO-26-003
5 SCANNER-ANALYZERS-DENO-26-005 DONE Build bundle/binary inspectors for eszip and deno compile executables to recover graphs, configs, embedded resources, and snapshots. Deno Analyzer Guild (src/Scanner/StellaOps.Scanner.Analyzers.Lang.Deno) SCANNER-ANALYZERS-DENO-26-004
6 SCANNER-ANALYZERS-DENO-26-006 DONE Implement the OCI/container adapter that stitches per-layer Deno caches, vendor trees, and compiled binaries back into provenance-aware analyzer inputs. Deno Analyzer Guild (src/Scanner/StellaOps.Scanner.Analyzers.Lang.Deno) SCANNER-ANALYZERS-DENO-26-005
7 SCANNER-ANALYZERS-DENO-26-007 DOING Produce AOC-compliant observation writers (entrypoints, modules, capability edges, workers, warnings, binaries) with deterministic reason codes. Deno Analyzer Guild (src/Scanner/StellaOps.Scanner.Analyzers.Lang.Deno) SCANNER-ANALYZERS-DENO-26-006
8 SCANNER-ANALYZERS-DENO-26-008 TODO Finalize fixture + benchmark suite (vendor/npm/FFI/worker/dynamic import/bundle/cache/container cases) validating analyzer determinism and performance. Deno Analyzer Guild, QA Guild (src/Scanner/StellaOps.Scanner.Analyzers.Lang.Deno) SCANNER-ANALYZERS-DENO-26-007