Files
git.stella-ops.org/docs/implplan/SPRINT_110_ingestion_evidence.md
master 7b01c7d6ac
Some checks failed
Docs CI / lint-and-preview (push) Has been cancelled
feat: Add comprehensive product advisories for improved scanner functionality
- Introduced a blueprint for explainable quiet alerts, detailing phases for SBOM, VEX readiness, and attestations.
- Developed a roadmap for deterministic diff-aware rescans, enhancing scanner speed and efficiency.
- Implemented a hash-based SBOM layer cache to optimize container scans by reusing previous results.
- Created a multi-runtime reachability corpus to validate function-level reachability across various programming languages.
- Proposed a stable SBOM model using SPDX 3.0.1 for persistence and CycloneDX 1.6 for interchange.
- Established a validation plan for quiet scans, focusing on provenance and CI integration.
- Documented guidelines for the Findings Ledger module, outlining roles, execution rules, and testing protocols.
2025-11-17 00:09:26 +02:00

9.7 KiB
Raw Blame History

Sprint 110 · Ingestion & Evidence

Topic & Scope

  • Finalise Advisory AI guardrail evidence (docs, SBOM feeds, policy knobs) while keeping customer rollout unblocked.
  • Land Concelier structured caching + telemetry so Link-Not-Merge schemas can feed downstream consoles, air-gap bundles, and attestations.
  • Prepare Excititor chunk API, telemetry, and attestation contracts for deterministic VEX evidence delivery.
  • Staff and kick off the Mirror assembler so deterministic bundles, DSSE/TUF metadata, and CLI/Export Center automation can start.

Dependencies & Concurrency

  • Upstream: Sprint 100.A (Attestor) must remain green; Excititor/Concelier depend on Link-Not-Merge schema set (CONCELIER-LNM-21-*, CARTO-GRAPH-21-002). Advisory AI docs require SBOM/CLI/Policy/DevOps deliverables (SBOM-AIAI-31-001, CLI-VULN-29-001, CLI-VEX-30-001, POLICY-ENGINE-31-001, DEVOPS-AIAI-31-001).
  • Sprint 110 peers (111119 range) stay independent; no intra-decade dependencies are permitted.
  • Evidence Locker contract and Mirror staffing decisions affect Excititor attestation work and Mirror tracks respectively.

Documentation Prerequisites

  • docs/modules/advisory-ai/architecture.md
  • docs/modules/concelier/architecture.md
  • docs/modules/excititor/architecture.md
  • docs/modules/export-center/architecture.md
  • docs/modules/airgap/architecture.md (timeline + bundle requirements)

Task Board

Wave Task ID Status Owner(s) Dependencies Notes
110.A Advisory AI DOCS-AIAI-31-004 DOING Docs Guild · Console Guild CONSOLE-VULN-29-001; CONSOLE-VEX-30-001; SBOM-AIAI-31-001/003 Guardrail console doc drafted; screenshots + SBOM evidence pending.
110.A Advisory AI AIAI-31-009 DONE (2025-11-12) Advisory AI Guild Regression suite + AdvisoryAI:Guardrails config landed with perf budgets.
110.A Advisory AI AIAI-31-008 BLOCKED Advisory AI Guild AIAI-31-006; AIAI-31-007 Blocked pending policy knob deliverables (AIAI-31-006/007).
110.A Advisory AI SBOM-AIAI-31-003 BLOCKED SBOM Service Guild SBOM-AIAI-31-001; CLI-VULN-29-001; CLI-VEX-30-001 Needs SBOM delta kit + CLI deliverables before validation can proceed.
110.A Advisory AI DOCS-AIAI-31-005/006/008/009 BLOCKED Docs Guild DOCS-AIAI-31-004; CLI-VULN-29-001; CLI-VEX-30-001; POLICY-ENGINE-31-001; DEVOPS-AIAI-31-001 CLI/policy/ops docs paused pending upstream artefacts.
110.B Concelier CONCELIER-AIAI-31-002 BLOCKED Concelier Core · Concelier WebService Guilds CONCELIER-GRAPH-21-001/002; CARTO-GRAPH-21-002 Blocked: Link-Not-Merge schema still not approved; cannot finalize structured field/caching.
110.B Concelier CONCELIER-AIAI-31-003 DONE (2025-11-12) Concelier Observability Guild Telemetry counters/histograms live for Advisory AI dashboards.
110.B Concelier CONCELIER-AIRGAP-56-001..58-001 BLOCKED Concelier Core · AirGap Guilds Link-Not-Merge schema; Evidence Locker attestation contract Blocked until schema approval + attestation scope sign-off.
110.B Concelier CONCELIER-CONSOLE-23-001..003 BLOCKED Concelier Console Guild Link-Not-Merge schema Blocked pending Link-Not-Merge schema approval.
110.B Concelier CONCELIER-ATTEST-73-001/002 BLOCKED Concelier Core · Evidence Locker Guild CONCELIER-AIAI-31-002; Evidence Locker contract Blocked until structured caching lands and Evidence Locker contract finalises.
110.B Concelier FEEDCONN-ICSCISA-02-012 / FEEDCONN-KISA-02-008 BLOCKED Concelier Feed Owners Feed owner remediation plan Overdue provenance refreshes require schedule from feed owners.
110.C Excititor EXCITITOR-AIAI-31-001 DONE (2025-11-09) Excititor Web/Core Guilds Normalised VEX justification projections shipped.
110.C Excititor EXCITITOR-AIAI-31-002 BLOCKED Excititor Web/Core Guilds Link-Not-Merge schema; Evidence Locker contract Blocked until schema + ingest contract approved.
110.C Excititor EXCITITOR-AIAI-31-003 BLOCKED Excititor Observability Guild EXCITITOR-AIAI-31-002 Blocked behind EXCITITOR-AIAI-31-002.
110.C Excititor EXCITITOR-AIAI-31-004 BLOCKED Docs Guild · Excititor Guild EXCITITOR-AIAI-31-002 Blocked until chunk API finalized.
110.C Excititor EXCITITOR-ATTEST-01-003 / 73-001 / 73-002 BLOCKED Excititor Guild · Evidence Locker Guild EXCITITOR-AIAI-31-002; Evidence Locker contract Blocked pending chunk API + Evidence Locker attestation scope.
110.C Excititor EXCITITOR-AIRGAP-56/57/58 · EXCITITOR-CONN-TRUST-01-001 BLOCKED Excititor Guild · AirGap Guilds Link-Not-Merge schema; attestation plan Blocked until schema + attestation readiness.
110.D Mirror MIRROR-CRT-56-001 BLOCKED Mirror Creator Guild Staffing decision Blocked: no owner assigned; kickoff slipped past 2025-11-15.
110.D Mirror MIRROR-CRT-56-002 BLOCKED Mirror Creator · Security Guilds MIRROR-CRT-56-001; PROV-OBS-53-001 Blocked until MIRROR-CRT-56-001 staffed.
110.D Mirror MIRROR-CRT-57-001/002 BLOCKED Mirror Creator Guild · AirGap Time Guild MIRROR-CRT-56-001; AIRGAP-TIME-57-001 Blocked; upstream staffing unresolved.
110.D Mirror MIRROR-CRT-58-001/002 BLOCKED Mirror Creator Guild · CLI Guild · Exporter Guild MIRROR-CRT-56-001; EXPORT-OBS-54-001; CLI-AIRGAP-56-001 Blocked until assembler staffed and upstream contracts agreed.
110.D Mirror EXPORT-OBS-51-001 / 54-001 · AIRGAP-TIME-57-001 · CLI-AIRGAP-56-001 · PROV-OBS-53-001 BLOCKED Exporter Guild · AirGap Time Guild · CLI Guild MIRROR-CRT-56-001 staffing Blocked pending MIRROR-CRT-56-001 ownership.

Execution Log

Date (UTC) Update Owner
2025-11-13 Refreshed wave tracker, decisions, and contingency plan ahead of 1415 Nov checkpoints; outstanding asks: SBOM/CLI/Policy/DevOps ETAs, Link-Not-Merge approval, Mirror staffing. Sprint 110 leads
2025-11-09 Captured initial wave scope, interlocks, and risks covering SBOM/CLI/Policy/DevOps artefacts, Link-Not-Merge schemas, Excititor justification backlog, and Mirror assembler commitments. Sprint 110 leads
2025-11-16 Updated task board: marked Advisory AI packaging, Concelier air-gap/console/attestation tracks, Excititor chunk/attestation/air-gap tracks, and all Mirror tracks as BLOCKED pending schema approvals, Evidence Locker contract, and Mirror staffing decisions. Implementer
2025-11-16 Marked CONCELIER-AIAI-31-002 BLOCKED (waiting on Link-Not-Merge schema approval); progressed DOCS-AIAI-31-004 doc draft. Implementer

Decisions & Risks

Decisions in flight

Decision Blocking work Accountable owner(s) Due date
Confirm SBOM/CLI/Policy/DevOps delivery dates DOCS-AIAI backlog, SBOM-AIAI-31-003, AIAI-31-008 SBOM Service · CLI · Policy · DevOps guild leads 2025-11-14
Approve Link-Not-Merge schema (CONCELIER-GRAPH-21-001/002, CARTO-GRAPH-21-002) CONCELIER-AIAI-31-002, EXCITITOR-AIAI-31-002/003/004, air-gap + attestation tasks Concelier Core · Cartographer Guild · SBOM Service Guild 2025-11-14
Assign MIRROR-CRT-56-001 owner Entire Mirror wave + Export Center + AirGap Time automation Mirror Creator Guild · Exporter Guild · AirGap Time Guild 2025-11-15
Evidence Locker attestation scope sign-off EXCITITOR-ATTEST-01-003/73-001/73-002; CONCELIER-ATTEST-73-001/002 Evidence Locker Guild · Excititor Guild · Concelier Guild 2025-11-15
Approve DOCS-AIAI-31-004 screenshot plan Publication of console guardrail doc Docs Guild · Console Guild 2025-11-15

Risk outlook (2025-11-13)

Risk Impact Mitigation / owner
SBOM/CLI/Policy/DevOps artefacts slip past 14 Nov Advisory AI docs + SBOM feeds stay blocked, delaying customer rollout & dependent sprints. Lock ETAs during 14 Nov interlock; escalate to Advisory AI leadership if commitments slip.
Link-Not-Merge schema approval delayed Concelier/Excititor APIs, console overlays, and air-gap bundles remain gated. Close 14 Nov review with migration notes; unblock tasks immediately after approval.
Excititor attestation backlog stalls VEX evidence + air-gap parity cannot progress; Mirror support drifts. Use 15 Nov sequencing session to lock order, reserve engineering capacity.
MIRROR-CRT-56-001 remains unstaffed DSSE/TUF, OCI/time-anchor, CLI, Export Center automation cannot start (Sprint 125 slips). Assign owner at kickoff; reallocate Export/AirGap engineers if needed.
Connector refreshes (ICSCISA/KISA) remain overdue Advisory AI may serve stale advisories; telemetry accuracy suffers. Feed owners to publish remediation plan + interim mitigations by 15 Nov stand-up.

Next Checkpoints

Date (UTC) Session Goal Impacted wave(s) Prep owner(s)
2025-11-14 Advisory AI customer surfaces follow-up Capture SBOM/CLI/Policy/DevOps ETAs to restart DOCS/SBOM work. 110.A Advisory AI · SBOM · CLI · Policy · DevOps guild leads
2025-11-14 Link-Not-Merge schema review Approve schema payloads + migration notes. 110.B · 110.C Concelier Core · Cartographer Guild · SBOM Service Guild
2025-11-15 Excititor attestation sequencing Lock Evidence Locker contract + backlog order. 110.C Excititor Web/Core · Evidence Locker Guild
2025-11-15 Mirror evidence kickoff Assign MIRROR-CRT-56-001 owner, confirm staffing, outline DSSE/TUF + OCI milestones. 110.D Mirror Creator · Exporter · AirGap Time · Security guilds

Appendix

  • Detailed coordination artefacts, contingency playbook, and historical notes previously held in this sprint now live at docs/implplan/archived/SPRINT_110_ingestion_evidence_2025-11-13.md.