4 · Feature Matrix — Stella Ops

(rev 2.0 · 14 Jul 2025)

CategoryCapabilityFree Tier (≤ 333 scans / day)Community Plug‑inCommercial Add‑OnNotes / ETA
SBOM IngestionTrivy‑JSON, SPDX‑JSON, CycloneDX‑JSONAuto‑detect on upload
Delta‑SBOM CacheWarm scans < 1 s
ScanningCVE lookup via local DBUpdate job ships weekly feeds
Licence‑risk detection⏳ (roadmap Q4‑2025)SPDX licence list
Policy EngineYAML rulesIn‑UI editor
OPA / Rego⏳ (β Q1‑2026)✅ plug‑inPlug‑in enables Rego
RegistryAnonymous internal registryStellaOps.Registry image
AttestationCosign signing⏳ (Q1‑2026)Requires StellaOpsAttestor
SLSA provenance v1.0⏳ (commercial 2026)Enterprise need
Rekor transparency log✅ plug‑inAir‑gap replica support
Quota & Throttling333 scans/day soft limitYellow banner at 200, wait‑wall post‑limit
Usage API (/quota)CI can poll remaining scans
User InterfaceDark / light modeAuto‑detect OS theme
Additional locale (Cyrillic)Default if Accept‑Language: bg or any other
Audit trailMongo history
DeploymentDocker Compose bundleSingle‑node
Helm chart (K8s)Horizontal scaling
High‑availability split services✅ (Add‑On)HA Redis & Mongo
Extensibility.NET hot‑load plug‑insN/AAGPL reference SDK
Community plug‑in marketplace⏳ (β Q2‑2026)Moderated listings
TelemetryOpt‑in anonymous metricsRequired for quota satisfaction KPI
Quota & TokensClient‑JWT issuance✅ (online 12 h token)/connect/token
Offline Client‑JWT (30 d)✅ via OUKRefreshed monthly in OUK

Legend: ✅ = Included ⏳ = Planned — = Not applicable
Rows marked “Commercial Add‑On” are optional paid components shipping outside the AGPL‑core; everything else is FOSS.


Last updated: 14 Jul 2025 (quota rev 2.0).