Some checks failed
Docs CI / lint-and-preview (push) Has been cancelled
- Implemented LdapDistinguishedNameHelper for escaping RDN and filter values. - Created AuthorityCredentialAuditContext and IAuthorityCredentialAuditContextAccessor for managing credential audit context. - Developed StandardCredentialAuditLogger with tests for success, failure, and lockout events. - Introduced AuthorityAuditSink for persisting audit records with structured logging. - Added CryptoPro related classes for certificate resolution and signing operations.
4.9 KiB
4.9 KiB
Sprint 122 - Ingestion & Evidence · 110.C) Excititor.IV
Active items only. Completed/historic work now resides in docs/implplan/archived_sprints_tasks.md (updated 2025-11-08).
[Ingestion & Evidence] 110.C) Excititor.IV Depends on: Sprint 110.C - Excititor.III Summary: Ingestion & Evidence focus on Excititor (phase IV).
Prep: Read
docs/modules/excititor/architecture.mdand the relevant ExcititorAGENTS.mdfiles before updating these tasks.
Task ID State Task description Owners (Source) EXCITITOR-OBS-52-001 Timeline eventsTODO Emit timeline_evententries for VEX ingest/linking/outcome changes with trace IDs, justification summaries, and evidence placeholders. Dependencies: EXCITITOR-OBS-51-001.Excititor Core Guild (src/Excititor/__Libraries/StellaOps.Excititor.Core) EXCITITOR-OBS-53-001 Evidence snapshotsTODO Build evidence payloads for VEX statements (raw doc, normalization diff, precedence notes) and push to evidence locker with Merkle manifests. Dependencies: EXCITITOR-OBS-52-001. Excititor Core Guild, Evidence Locker Guild (src/Excititor/__Libraries/StellaOps.Excititor.Core) EXCITITOR-OBS-54-001 Attestation & verificationTODO Attach DSSE attestations to VEX batch processing, verify chain-of-custody via Provenance library, and link attestation IDs to timeline + ledger. Dependencies: EXCITITOR-OBS-53-001. Excititor Core Guild, Provenance Guild (src/Excititor/__Libraries/StellaOps.Excititor.Core) EXCITITOR-OBS-55-001 Incident modeTODO Implement incident sampling bump, additional raw payload retention, and activation events for VEX pipelines with redaction guard rails. Dependencies: EXCITITOR-OBS-54-001. Excititor Core Guild, DevOps Guild (src/Excititor/__Libraries/StellaOps.Excititor.Core) EXCITITOR-ORCH-32-001 Worker SDK adoptionTODO Integrate orchestrator worker SDK in Excititor ingestion jobs, emit heartbeats/progress/artifact hashes, and register source metadata. Excititor Worker Guild (src/Excititor/StellaOps.Excititor.Worker) EXCITITOR-ORCH-33-001 Control complianceTODO Honor orchestrator pause/throttle/retry actions, classify error outputs, and persist restart checkpoints. Dependencies: EXCITITOR-ORCH-32-001. Excititor Worker Guild (src/Excititor/StellaOps.Excititor.Worker) EXCITITOR-ORCH-34-001 Backfill & circuit breakerTODO Implement orchestrator-driven backfills, apply circuit breaker reset rules, and ensure artifact dedupe alignment. Dependencies: EXCITITOR-ORCH-33-001. Excititor Worker Guild (src/Excititor/StellaOps.Excititor.Worker) EXCITITOR-POLICY-02-002 – Diagnostics for scoring signals Team Excititor Policy BACKLOG – Update diagnostics reports to surface missing severity/KEV/EPSS mappings, coefficient overrides, and provide actionable recommendations for policy tuning. EXCITITOR-POLICY-02-001 (src/Excititor/__Libraries/StellaOps.Excititor.Policy) EXCITITOR-POLICY-20-001 Policy selection endpointsTODO Provide VEX lookup APIs supporting PURL/advisory batching, scope filtering, and tenant enforcement with deterministic ordering + pagination. Dependencies: EXCITITOR-POLICY-02-002. Excititor WebService Guild (src/Excititor/StellaOps.Excititor.WebService) EXCITITOR-POLICY-20-002 Scope-aware linksetsTODO Enhance VEX linkset extraction with scope resolution (product/component) + version range matching to boost policy join accuracy; refresh fixtures/tests. Dependencies: EXCITITOR-POLICY-20-001. Excititor Core Guild, Policy Guild (src/Excititor/__Libraries/StellaOps.Excititor.Core) EXCITITOR-POLICY-20-003 Selection cursorsTODO Introduce VEX selection cursor collections + indexes powering incremental policy runs; bundle change-stream checkpoint migrations and Offline Kit tooling. Dependencies: EXCITITOR-POLICY-20-002. Excititor Storage Guild (src/Excititor/__Libraries/StellaOps.Excititor.Storage.Mongo) EXCITITOR-POLICY-23-001 Evidence indexesTODO Provide indexes/materialized views for policy runtime (status, justification, product PURL) to accelerate queries; document contract. Dependencies: EXCITITOR-POLICY-20-003. Excititor Core Guild (src/Excititor/__Libraries/StellaOps.Excititor.Core) EXCITITOR-POLICY-23-002 Event guaranteesTODO Ensure vex.linkset.updatedevents include correlation confidence, conflict summaries, and idempotent ids for evaluator consumption. Dependencies: EXCITITOR-POLICY-23-001.Excititor Core Guild, Platform Events Guild (src/Excititor/__Libraries/StellaOps.Excititor.Core) EXCITITOR-RISK-66-001 VEX gate providerTODO Supply VEX status and justification data for risk engine gating with full source provenance. Excititor Core Guild, Risk Engine Guild (src/Excititor/__Libraries/StellaOps.Excititor.Core) EXCITITOR-RISK-66-002 Reachability inputsTODO Provide component/product scoping metadata enabling reachability and runtime factor mapping. Dependencies: EXCITITOR-RISK-66-001. Excititor Core Guild (src/Excititor/__Libraries/StellaOps.Excititor.Core)