About Stella Ops
Stella Ops delivers sub‑5 second container scanning you can run completely offline, extend with hot‑load plug‑ins, and redistribute under the AGPL‑3.0‑or‑later licence.
Open by design
- 100 % AGPL‑3.0‑or‑later — no “open‑core” traps.
-
Every release ships a
.spdx.json
SBOM and acosign
signature so you can audit the exact bits you run. - All planning, design discussions and CI logs are public in our Gitea repo.
- Forks are encouraged; if you add features, open a PR — community support follows the donation‑funded governance model.
Open
Source and SBOM for every build. Cosign‑signed, SPDX‑documented.
Sovereign
Runs 100 % offline; Offline Update Kit refreshes feeds monthly.
Modular
Hot‑load .NET plug‑ins, OPA/Rego policy engine, REST v2 SDKs.
Road‑map at a glance
Q3 2025
- One‑command installer (Compose).
- Dark‑mode UI and accessibility pass.
- Free‑tier quota service (333 scans / day).
Q4 2025
- Rego policy‑as‑code engine (β).
- Self‑update channel via Offline Update Kit.
- REST v2 API freeze + typed client SDKs.
Licence & governance
Released under GNU Affero GPL v3 or later. Lazy‑consensus governs design decisions; two maintainer approvals merge non‑trivial PRs.
Want to influence the roadmap? Open a proposal issue or join #stellaops on Matrix.