Legacy-edge dispositions — generated from the register
GENERATED FILE — do not hand-edit. Every edit is overwritten on the next run, and
-Checkfails while it survives. Produced bytools/scripts/build-boundary/generate-legacy-edge-dispositions.ps1, whichgenerate-build-boundary-report.ps1invokes in the same pass — so this document and the report are always generated from one state of the tree.Generated 2026-09-15 (UTC).
Source of truth. Live rows ARE the pins in
legacy-edge-register.json— key, seam, owner, sunset and foreign-project count are read from it, never transcribed. Retired rows come fromlegacy-edge-resolvers.json, the retirement ledger, because a resolved pin is DELETED from the register (pins are shrink-only and expire on use) and so the register cannot carry its own history. A row here can therefore never name a pin the register does not, which is exactly what the hand-maintained version of this table did: on 2026-08-17 about 65 of its 151 rows named pins that no longer existed, and the nine that had been struck implied the other 142 had been checked. They had not.Regenerate / verify:
pwsh tools/scripts/build-boundary/generate-build-boundary-report.ps1 # report + this file pwsh tools/scripts/build-boundary/generate-build-boundary-report.ps1 -Check # fails if either is staleA resolver is never guessed. A retired row cites the commit that severed the edge only where a human verified it; otherwise it reads
retired-resolver-unrecordedand shows the commit that deregistered the pin, which is a starting point and not an attribution — the two are frequently different commits (a bookkeeping sweep deletes the pin days after the fix).The dated MBI-4 hand compilation is preserved at
legacy-edge-dispositions-2026-08-06-mbi4-compilation.md— its reasoning, gate-coverage findings (§6), undecided remainder (§7) and criteria state (§9) are point-in-time evidence that this generated table deliberately does not reproduce.
1. Counts
| Measure | Value |
|---|---|
| Live pins in the register | 0 |
| Library-impurity pins | 0 |
| Retired pairs in the ledger | 249 |
| — with a verified resolver | 66 |
| — resolver unrecorded | 183 |
| — superseded by a rename | 0 |
| Measured violation pairs (report) | 0 |
| Unpinned pairs (report) | 0 |
| Stale pins (report) | 0 |
| Grown pins (report) | 0 |
Reconciliation: the register holds 0 pins and the measured graph holds 0 violation pairs, with 0 unpinned and 0 stale required for the gate to pass. Those two numbers are produced by different tools from the same tree; if they disagree here, -Check is already red.
Live pins by disposition class
| Disposition class | Pins |
|---|
Live pins by owning program
| Owning program | Pins |
|---|
2. How a row is classified
The register’s targetSeam maps onto the build-coupling decision test in ../service-consolidation-review.md. The mapping is fail-closed: a seam value that is not in this table stops generation rather than being rendered unclassified.
Register targetSeam | Disposition class | Decision-test clause | Meaning |
|---|---|---|---|
merge | dies-by-consolidation | 1 | one domain lifecycle, or the mechanism holding the edge is deleted — no runtime seam is manufactured |
api | owner-API seam | 2 | keep separate; consumer calls the owner’s API |
event | event seam | 2 | keep separate; consumer subscribes to a versioned event |
artifact | artifact seam | 2 | keep separate; consumer reads a content-addressed artifact |
published-package | package/closed-SDK seam | 2 | keep separate; producer publishes an exact-version package, or a producer-owned closed client/contract project whose graph conformance proves it implementation-free |
neutral-sdk | neutral-SDK purification | 4 | a shared library’s own closure must stop reaching service implementation |
A .Contracts/.Client name is not a disposition — clause 3 forbids that, and the closed graph is what admits the seam. published-package deliberately covers both a published package and a producer-owned closed source project; which one ships is the producer program’s call at its contract-freeze stage.
3. Live pins, by owning program
One row per register pin. Foreign projects is the pinned (shrink-only) count; where the measured graph is already below it, the measured value is shown first — that is a partially burned-down edge, not a discrepancy. Carrier is the producer-side project the consumer’s closure enters, i.e. the last hop of the pin’s shortest witness.
4. Library-impurity pins
A shared/neutral or client-SDK project whose OWN closure reaches service implementation. These are not consumer-key pairs: the project is the subject, and it clears by purification, not by a consumer changing anything.
None.
4a. Approved merge edges — D14 consolidations in progress (expiring)
NOT pins. Exact (consumer key x producer family) pairs an owner-approved D14 consolidation program is allowed to compile AHEAD of its S9/S10 window (2026-08-24 DC-40 amendment). Each cites its program and EXPIRES the moment the pair leaves the derived graph; the reverse direction is never covered and fails like any new edge. Family re-classification itself still happens only when the owning program lands its stage evidence (README).
None.
5. Retired pins — the burn-down ledger
Pairs that were pinned and are not any more, oldest first. Deregistered is the commit that removed the pin from the register (machine-derived from the register’s git history, always present). Resolver is the commit that actually severed the edge, and appears only where a human verified it — the two are often different, so an unrecorded resolver is left unrecorded.
| Consumer key | Producer family | Retired | Status | Resolver | Deregistered | Pinned owner | Note |
|---|---|---|---|---|---|---|---|
export-web | signals | 2026-08-02 | retired-resolver-unrecorded | — | 4159ae78f5 | SPRINT_20260722_020 | |
export-worker | signals | 2026-08-02 | retired-resolver-unrecorded | — | 4159ae78f5 | SPRINT_20260722_020 | |
policy-engine | signals | 2026-08-02 | retired-resolver-unrecorded | — | 4159ae78f5 | SPRINT_20260722_007 | |
vexhub-web | evidence-locker | 2026-08-02 | retired-resolver-unrecorded | — | a21ad75ec5 | SPRINT_20260722_011 | |
vexhub-web | replay | 2026-08-02 | retired-resolver-unrecorded | — | a21ad75ec5 | SPRINT_20260722_020 | |
vexhub-web | sbomservice | 2026-08-02 | retired-resolver-unrecorded | — | a21ad75ec5 | SPRINT_20260722_020 | |
vexhub-web | scheduler | 2026-08-02 | retired-resolver-unrecorded | — | a21ad75ec5 | SPRINT_20260722_012 | |
vexhub-web | signals | 2026-08-02 | retired-resolver-unrecorded | — | a21ad75ec5 | SPRINT_20260722_020 | |
vexlens-web | authority | 2026-08-02 | retired-resolver-unrecorded | — | 48571c85b6 | SPRINT_20260722_016 | |
vexlens-web | evidence-locker | 2026-08-02 | retired-resolver-unrecorded | — | a21ad75ec5 | SPRINT_20260722_011 | |
vexlens-web | issuer-directory | 2026-08-02 | retired-resolver-unrecorded | — | 48571c85b6 | SPRINT_20260722_016 | |
vexlens-web | replay | 2026-08-02 | retired-resolver-unrecorded | — | a21ad75ec5 | SPRINT_20260722_020 | |
vexlens-web | sbomservice | 2026-08-02 | retired-resolver-unrecorded | — | a21ad75ec5 | SPRINT_20260722_020 | |
vexlens-web | scheduler | 2026-08-02 | retired-resolver-unrecorded | — | a21ad75ec5 | SPRINT_20260722_012 | |
vexlens-web | signals | 2026-08-02 | retired-resolver-unrecorded | — | a21ad75ec5 | SPRINT_20260722_020 | |
export-web | sbomservice | 2026-08-03 | retired-resolver-unrecorded | — | fe8b66ca79 | SPRINT_20260722_020 | |
export-web | scheduler | 2026-08-03 | retired-resolver-unrecorded | — | 80756a1ef2 | SPRINT_20260722_012 | |
export-worker | sbomservice | 2026-08-03 | retired-resolver-unrecorded | — | fe8b66ca79 | SPRINT_20260722_020 | |
export-worker | scheduler | 2026-08-03 | retired-resolver-unrecorded | — | 80756a1ef2 | SPRINT_20260722_012 | |
policy-engine | sbomservice | 2026-08-03 | retired-resolver-unrecorded | — | fe8b66ca79 | SPRINT_20260722_020 | |
policy-engine | scheduler | 2026-08-03 | retired-resolver-unrecorded | — | 80756a1ef2 | SPRINT_20260722_012 | |
advisory-ai-web | excititor | 2026-08-05 | retired-resolver-unrecorded | — | 08f6db4e7d | SPRINT_20260722_003 | |
advisory-ai-web | findings-ledger | 2026-08-05 | retired-resolver-unrecorded | — | 7441571ec2 | SPRINT_20260722_010 | |
advisory-ai-web | opsmemory | 2026-08-05 | retired-resolver-unrecorded | — | 8f2b14c5c4 | SPRINT_20260722_013 | |
advisory-ai-web | scanner | 2026-08-05 | retired-resolver-unrecorded | — | 74f054f765 | SPRINT_20260722_017 | |
advisory-ai-worker | excititor | 2026-08-05 | retired-resolver-unrecorded | — | 08f6db4e7d | SPRINT_20260722_003 | |
advisory-ai-worker | findings-ledger | 2026-08-05 | retired-resolver-unrecorded | — | 7441571ec2 | SPRINT_20260722_010 | |
advisory-ai-worker | opsmemory | 2026-08-05 | retired-resolver-unrecorded | — | 8f2b14c5c4 | SPRINT_20260722_013 | |
advisory-ai-worker | scanner | 2026-08-05 | retired-resolver-unrecorded | — | 74f054f765 | SPRINT_20260722_017 | |
agent-core | evidence-locker | 2026-08-05 | retired-resolver-unrecorded | — | 5d1c74331c | SPRINT_20260722_011 | |
agent-core | signer | 2026-08-05 | retired-resolver-unrecorded | — | da89f92665 | SPRINT_20260722_019 | |
airgap-controller | attestor | 2026-08-05 | retired-resolver-unrecorded | — | 6ad5bdfd25 | SPRINT_20260722_011 | |
airgap-time | attestor | 2026-08-05 | retired-resolver-unrecorded | — | 6ad5bdfd25 | SPRINT_20260722_011 | |
attestor | scanner | 2026-08-05 | retired-resolver-unrecorded | — | 74f054f765 | SPRINT_20260722_017 | |
attestor | signer | 2026-08-05 | retired-resolver-unrecorded | — | 07de59cdd4 | SPRINT_20260722_019 | |
attestor-tileproxy | signer | 2026-08-05 | retired-resolver-unrecorded | — | 07de59cdd4 | SPRINT_20260722_019 | |
authority | attestor | 2026-08-05 | retired-resolver-unrecorded | — | 6ad5bdfd25 | SPRINT_20260722_011 | |
binaryindex-web | scanner | 2026-08-05 | retired-resolver-unrecorded | — | 74f054f765 | SPRINT_20260722_017 | |
concelier | scanner | 2026-08-05 | retired-resolver-unrecorded | — | 74f054f765 | SPRINT_20260722_017 | |
evidence-locker-web | signer | 2026-08-05 | retired-resolver-unrecorded | — | 07de59cdd4 | SPRINT_20260722_019 | |
excititor-web | scanner | 2026-08-05 | retired-resolver-unrecorded | — | 74f054f765 | SPRINT_20260722_017 | |
excititor-worker | scanner | 2026-08-05 | retired-resolver-unrecorded | — | 74f054f765 | SPRINT_20260722_017 | |
export-web | evidence-locker | 2026-08-05 | retired-resolver-unrecorded | — | f03f7a280b | SPRINT_20260722_011 | |
export-web | replay | 2026-08-05 | retired-resolver-unrecorded | — | 2cd6521cd2 | SPRINT_20260722_020 | |
export-worker | evidence-locker | 2026-08-05 | retired-resolver-unrecorded | — | f03f7a280b | SPRINT_20260722_011 | |
export-worker | replay | 2026-08-05 | retired-resolver-unrecorded | — | 2cd6521cd2 | SPRINT_20260722_020 | |
findings-ledger-web | binaryindex | 2026-08-05 | retired-resolver-unrecorded | — | 2c7556cf4a | SPRINT_20260722_014 | |
findings-ledger-web | concelier | 2026-08-05 | retired-resolver-unrecorded | — | 2c7556cf4a | SPRINT_20260722_003 | |
findings-ledger-web | policy | 2026-08-05 | retired-resolver-unrecorded | — | 2c7556cf4a | SPRINT_20260722_007 | |
findings-ledger-web | replay | 2026-08-05 | retired-resolver-unrecorded | — | 2c7556cf4a | SPRINT_20260722_020 | |
findings-ledger-web | scanner | 2026-08-05 | retired-resolver-unrecorded | — | 2c7556cf4a | SPRINT_20260722_010 | |
findings-ledger-web | signals | 2026-08-05 | retired-resolver-unrecorded | — | 2c7556cf4a | SPRINT_20260722_010 | |
findings-ledger-web | signer | 2026-08-05 | retired-resolver-unrecorded | — | 07de59cdd4 | SPRINT_20260722_019 | |
findings-security-web | findings-ledger | 2026-08-05 | retired-resolver-unrecorded | — | 2c7556cf4a | SPRINT_20260722_010 | |
findings-vulncorrelation | findings-ledger | 2026-08-05 | retired-resolver-unrecorded | — | 2c7556cf4a | SPRINT_20260722_010 | |
integrations-web | attestor | 2026-08-05 | retired-resolver-unrecorded | — | 300012e388 | SPRINT_20260722_011 | |
integrations-web | binaryindex | 2026-08-05 | retired-resolver-unrecorded | — | 300012e388 | SPRINT_20260722_014 | |
integrations-web | evidence-locker | 2026-08-05 | retired-resolver-unrecorded | — | 300012e388 | SPRINT_20260722_011 | |
integrations-web | policy | 2026-08-05 | retired-resolver-unrecorded | — | 300012e388 | SPRINT_20260722_007 | |
integrations-web | replay | 2026-08-05 | retired-resolver-unrecorded | — | 300012e388 | SPRINT_20260722_020 | |
integrations-web | signals | 2026-08-05 | retired-resolver-unrecorded | — | 300012e388 | SPRINT_20260722_020 | |
integrations-web | signer | 2026-08-05 | retired-resolver-unrecorded | — | 300012e388 | SPRINT_20260722_019 | |
notify-web | attestor | 2026-08-05 | retired-resolver-unrecorded | — | 6ad5bdfd25 | SPRINT_20260722_011 | |
notify-web | notifier | 2026-08-05 | retired-resolver-unrecorded | — | a5b589522d | SPRINT_20260722_015 | |
opsmemory-web | attestor | 2026-08-05 | retired-resolver-unrecorded | — | 7441571ec2 | SPRINT_20260722_011 | |
opsmemory-web | evidence-locker | 2026-08-05 | retired-resolver-unrecorded | — | 7441571ec2 | SPRINT_20260722_011 | |
opsmemory-web | findings-ledger | 2026-08-05 | retired-resolver-unrecorded | — | 7441571ec2 | SPRINT_20260722_010 | |
platform | findings-ledger | 2026-08-05 | retired-resolver-unrecorded | — | 2c7556cf4a | SPRINT_20260722_026 | |
policy-engine | evidence-locker | 2026-08-05 | retired-resolver-unrecorded | — | 470218621f | SPRINT_20260722_011 | |
policy-engine | signer | 2026-08-05 | retired-resolver-unrecorded | — | 07de59cdd4 | SPRINT_20260722_019 | |
release-orchestrator | evidence-locker | 2026-08-05 | retired-resolver-unrecorded | — | 5d1c74331c | SPRINT_20260722_011 | |
sbomservice | scanner | 2026-08-05 | retired-resolver-unrecorded | — | 74f054f765 | SPRINT_20260722_017 | |
scanner-web | evidence-locker | 2026-08-05 | retired-resolver-unrecorded | — | 470218621f | SPRINT_20260722_011 | |
scanner-web | signer | 2026-08-05 | retired-resolver-unrecorded | — | da89f92665 | SPRINT_20260722_019 | |
scanner-worker | evidence-locker | 2026-08-05 | retired-resolver-unrecorded | — | 5d1c74331c | SPRINT_20260722_011 | |
scanner-worker | signer | 2026-08-05 | retired-resolver-unrecorded | — | da89f92665 | SPRINT_20260722_019 | |
signer | attestor | 2026-08-05 | retired-resolver-unrecorded | — | 6ad5bdfd25 | SPRINT_20260722_011 | |
unknowns-web | scanner | 2026-08-05 | retired-resolver-unrecorded | — | 74f054f765 | SPRINT_20260722_017 | |
vexhub-web | attestor | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_011 | |
vexhub-web | concelier | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_003 | |
vexhub-web | excititor | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_003 | |
vexhub-web | policy | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_007 | |
vexhub-web | reachgraph | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_023 | |
vexhub-web | scanner | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_017 | |
vexhub-web | signer | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_019 | |
vexhub-web | vexlens | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_022 | |
vexlens-web | attestor | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_011 | |
vexlens-web | concelier | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_003 | |
vexlens-web | excititor | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_003 | |
vexlens-web | policy | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_007 | |
vexlens-web | reachgraph | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_023 | |
vexlens-web | scanner | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_017 | |
vexlens-web | signer | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_019 | |
vexlens-web | vexhub | 2026-08-05 | retired-resolver-unrecorded | — | a8472b6e10 | SPRINT_20260722_003 | |
agent-core | integrations | 2026-08-09 | retired-resolver-unrecorded | — | bec6a5c69f | SPRINT_20260722_024 | |
agent-core | release-orchestrator | 2026-08-09 | retired-resolver-unrecorded | — | bec6a5c69f | SPRINT_20260722_018 | |
agent-core | replay | 2026-08-09 | retired-resolver-unrecorded | — | 261fc5ea86 | SPRINT_20260722_020 | |
concelier | replay | 2026-08-09 | retired-resolver-unrecorded | — | 261fc5ea86 | SPRINT_20260722_020 | |
platform | agent-core | 2026-08-09 | retired-resolver-unrecorded | — | bec6a5c69f | SPRINT_20260722_026 | |
platform | replay | 2026-08-09 | retired-resolver-unrecorded | — | 261fc5ea86 | SPRINT_20260722_026 | |
platform | unknowns | 2026-08-09 | retired-resolver-unrecorded | — | b4975169e2 | SPRINT_20260722_026 | |
policy-engine | replay | 2026-08-09 | retired-resolver-unrecorded | — | 261fc5ea86 | SPRINT_20260722_020 | |
release-orchestrator | agent-core | 2026-08-09 | retired-resolver-unrecorded | — | bec6a5c69f | SPRINT_20260722_018 | |
release-orchestrator | replay | 2026-08-09 | retired-resolver-unrecorded | — | 261fc5ea86 | SPRINT_20260722_020 | |
scanner-web | replay | 2026-08-09 | retired-resolver-unrecorded | — | 261fc5ea86 | SPRINT_20260722_020 | |
scanner-web | signals | 2026-08-09 | retired-resolver-unrecorded | — | 1a7ad55306 | SPRINT_20260722_020 | |
scanner-worker | replay | 2026-08-09 | retired-resolver-unrecorded | — | 261fc5ea86 | SPRINT_20260722_020 | |
scanner-worker | signals | 2026-08-09 | retired-resolver-unrecorded | — | 1a7ad55306 | SPRINT_20260722_020 | |
scanner-worker | unknowns | 2026-08-09 | retired-resolver-unrecorded | — | b4975169e2 | SPRINT_20260722_020 | |
timeline-web | replay | 2026-08-09 | retired-resolver-unrecorded | — | 261fc5ea86 | SPRINT_20260722_020 | |
binaryindex-web | symbols | 2026-08-10 | resolved | SPRINT_20260730_001 MBI-3 | b480dd6307 | SPRINT_20260722_014 | PIN DELETED 2026-08-10 (SPRINT_20260730_001 MBI-3): BinaryIndex.DeltaSig repointed to the closed StellaOps.Symbols.Contracts, so this edge died with the extraction. Row struck 2026-08-17 — it had been stale in this table for a week after the register row went. |
findings-ledger-web | evidence-locker | 2026-08-10 | resolved | 8745312a19 | 8745312a19 | SPRINT_20260722_011 | One ProjectReference swap: StellaOps.Findings.Ledger pointed at StellaOps.EvidenceLocker.Core for a single static PII helper (CapsulePiiGuard.FindPiiViolations) whose namespace has lived in the producer’s CLOSED .Contracts project since extraction, so the locker’s domain core was being dragged into two deployables for nothing. Retired ahead of the 011 consolidation it was scheduled behind. Read-across: check the producer’s .Contracts before scheduling a consumer’s edge behind that producer’s merge. |
integrations-web | scanner | 2026-08-10 | retired-resolver-unrecorded | — | 1ec5702a94 | SPRINT_20260722_017 | |
notify-web | evidence-locker | 2026-08-10 | resolved | 8745312a19 | 8745312a19 | SPRINT_20260722_011 | Same resolver and same swap as findings-ledger-web -> evidence-locker; both witnesses ran through StellaOps.Findings.Ledger. |
platform | symbols | 2026-08-10 | retired-resolver-unrecorded | — | b480dd6307 | SPRINT_20260722_026 | |
scanner-worker | symbols | 2026-08-10 | resolved | MBI-3 | b480dd6307 | SPRINT_20260722_014 | PIN DELETED 2026-08-10 (MBI-3): same extraction; same week-long table drift. |
signals | scanner | 2026-08-10 | retired-resolver-unrecorded | — | 1ec5702a94 | SPRINT_20260722_017 | |
advisory-ai-web | policy | 2026-08-11 | retired-resolver-unrecorded | — | b30a1f2cbc | SPRINT_20260722_007 | |
advisory-ai-worker | policy | 2026-08-11 | retired-resolver-unrecorded | — | b30a1f2cbc | SPRINT_20260722_007 | |
agent-core | policy | 2026-08-11 | retired-resolver-unrecorded | — | ab61e8205d | SPRINT_20260722_007 | |
binaryindex-web | policy | 2026-08-11 | retired-resolver-unrecorded | — | ab61e8205d | SPRINT_20260722_007 | |
concelier | policy | 2026-08-11 | retired-resolver-unrecorded | — | ab61e8205d | SPRINT_20260722_007 | |
excititor-web | policy | 2026-08-11 | retired-resolver-unrecorded | — | ab61e8205d | SPRINT_20260722_007 | |
excititor-worker | policy | 2026-08-11 | retired-resolver-unrecorded | — | ab61e8205d | SPRINT_20260722_007 | |
export-web | policy | 2026-08-11 | retired-resolver-unrecorded | — | 69654c8029 | SPRINT_20260722_007 | |
export-worker | policy | 2026-08-11 | retired-resolver-unrecorded | — | 69654c8029 | SPRINT_20260722_007 | |
release-orchestrator | policy | 2026-08-11 | retired-resolver-unrecorded | — | ab61e8205d | SPRINT_20260722_007 | |
sbomservice | policy | 2026-08-11 | retired-resolver-unrecorded | — | ab61e8205d | SPRINT_20260722_007 | |
scanner-worker | policy | 2026-08-11 | retired-resolver-unrecorded | — | ab61e8205d | SPRINT_20260722_007 | |
unknowns-web | attestor | 2026-08-11 | retired-resolver-unrecorded | — | ab61e8205d | SPRINT_20260722_011 | |
unknowns-web | concelier | 2026-08-11 | retired-resolver-unrecorded | — | ab61e8205d | SPRINT_20260722_003 | |
unknowns-web | policy | 2026-08-11 | retired-resolver-unrecorded | — | ab61e8205d | SPRINT_20260722_007 | |
advisory-ai-web | attestor | 2026-08-17 | resolved | b30a1f2cbc | 94fd3896c4 | SPRINT_20260722_011 | PIN DELETED 2026-08-17: resolved by b30a1f2cbc(POL-F5 stage 2a), NOT by the concelier resolver. AdvisoryAI reached Attestor only THROUGH StellaOps.Policy; repointing it to the closed StellaOps.Policy.Contracts — whose graph reaches no Attestor — killed the path. Worth keeping: the same consumer’s attestor and concelier pins died to different commits in different sprints, so one citation for both would have been wrong. |
advisory-ai-web | concelier | 2026-08-17 | resolved | 3419d519df | 94fd3896c4 | SPRINT_20260722_003 | PIN DELETED 2026-08-17: resolved by 3419d519df, which removed AdvisoryAI’s last three Concelier references (Concelier.Core, .RawModels, .Persistence) together with the provider files that were their only consumers. The long-standing “14 (pin says 15)” drift note in this row dies with it. |
advisory-ai-worker | attestor | 2026-08-17 | resolved | b30a1f2cbc | 94fd3896c4 | SPRINT_20260722_011 | PIN DELETED 2026-08-17: same resolver, b30a1f2cbc. |
advisory-ai-worker | concelier | 2026-08-17 | resolved | 3419d519df | 94fd3896c4 | SPRINT_20260722_003 | PIN DELETED 2026-08-17: same resolver, 3419d519df. |
doctor-web | scheduler | 2026-08-17 | resolved | 009 DOC-5 stage 4 | c3246bacb2 | SPRINT_20260722_012 | PIN DELETED 2026-08-17 (009 DOC-5 stage 4): the CONSUMER deployable is retired, so the edge has no live violation to pin. Predicted by the §812 disposition below, which called this “not applicable — the consumer deployable is owner-decided to retire”. |
export-web | findings-ledger | 2026-08-17 | resolved | SPRINT_20260730_001 MBI-5c. The rename chain is COMPLETE: this pair was renamed into offlinekit-web|findings by the ExportCenter/OfflineKit consolidation, and that successor pin is itself now retired – StellaOps.Findings.DoraRoi was reclassified domain-neutral-shared and relocated to src/__Libraries/, so no offlinekit key compiles a Findings-owned project any more. supersededBy is kept as history; the ledger rule that a rename must point at a LIVE pin no longer applies once the chain ends in a resolution rather than another pin. | 0b6452223f | SPRINT_20260722_010 | Producer family relabelled findings-ledger -> findings by FND-8 c2 in 0b6452223f; verified in that commit register diff, which changes producerFamily on exactly these three pins and severs no edge. The edge did not retire - it is the live row named in supersededBy. |
export-worker | findings-ledger | 2026-08-17 | resolved | SPRINT_20260730_001 MBI-5c. The rename chain is COMPLETE: this pair was renamed into offlinekit-worker|findings by the ExportCenter/OfflineKit consolidation, and that successor pin is itself now retired – StellaOps.Findings.DoraRoi was reclassified domain-neutral-shared and relocated to src/__Libraries/, so no offlinekit key compiles a Findings-owned project any more. supersededBy is kept as history; the ledger rule that a rename must point at a LIVE pin no longer applies once the chain ends in a resolution rather than another pin. | 0b6452223f | SPRINT_20260722_010 | Producer family relabelled findings-ledger -> findings by FND-8 c2 in 0b6452223f; same commit and same rename as export-web. The edge did not retire. |
findings-ledger-web | attestor | 2026-08-17 | resolved | 90352bc2f5 | 90352bc2f5 | SPRINT_20260722_010 | SPRINT_20260722_010 F-R0817-1: three submission types git mv’d out of StellaOps.Attestor.Core into a closed StellaOps.Attestor.Contracts, byte-identically and with the namespace preserved, so none of the 20 other Attestor.Core consumers changed a line. The register’s published-package seam was measured wrong for this edge against client-sdk-seam.md section 1 - a package is justified only when the consumer ships outside the monorepo, and findings-web does not, so the closed source seam was the correct choice. Last build-boundary blocker on FND-8’s host composition. |
findings-vulncorrelation | concelier | 2026-08-17 | resolved | 652421d7bf | 94fd3896c4 | SPRINT_20260722_003 | PIN DELETED 2026-08-17: resolved by 652421d7bf, which removed the HOST’s own Concelier.SbomIntegration reference — the edge this row names. 0ac1b5d30a is the commit usually cited and it is not the resolver: it retargeted the Application and Tests projects, which mattered but did not kill the pinned edge. |
notify-web | findings-ledger | 2026-08-17 | resolved | docs-archive/implplan/SPRINT_20260722_015_Notify_service_consolidation_program.md#ntf-9-live-nis2-handoff-cutover | 0b6452223f | SPRINT_20260722_010 | Producer family relabelled findings-ledger -> findings by FND-8 c2 in 0b6452223f; same commit and same rename as export-web. The edge did not retire. NTF-9 subsequently retired the successor Notify-to-Findings implementation edge after the two-tenant owner proof. |
scanner-web | binaryindex | 2026-08-17 | resolved | 014 BIN-5 | c3246bacb2 | SPRINT_20260722_014 | PIN DELETED 2026-08-17 (014 BIN-5): closure emptied to ZERO. Not by moving anything — D-BIN5-6 was ruled and the shared disassembly stack (Disassembly(+.Abstractions), Semantic, Decompiler, Ghidra, Contracts) is classified domain-neutral-shared, so all six of this key’s foreign projects stopped being violations where they stand. |
agent-core | concelier | 2026-08-18 | resolved | 65b18b509f | fae623f5b3 | SPRINT_20260722_003 | deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by 65b18b509f (2026-08-18 11:04), which removed BOTH of StellaOps.Attestor.ProofChain’s references into src/Concelier – StellaOps.Feedser.Core and StellaOps.Concelier.SourceIntel – carrying the five record families into Evidence/ under a new namespace (copy, not move: both DLLs ship in 72 committed prebuilt bundles). ProofChain was this consumer’s only surviving path into the concelier family, so the pair fell out with that one two-edge cut; six consumer keys retired together for that reason. Verified: the commit’s diff removes exactly those two ProjectReferences. resolverCitation is null because the commit names no sprint and one must not be invented. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff. |
attestor | concelier | 2026-08-18 | resolved | 65b18b509f | fae623f5b3 | SPRINT_20260722_003 | deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by 65b18b509f (2026-08-18 11:04), which removed BOTH of StellaOps.Attestor.ProofChain’s references into src/Concelier – StellaOps.Feedser.Core and StellaOps.Concelier.SourceIntel – carrying the five record families into Evidence/ under a new namespace (copy, not move: both DLLs ship in 72 committed prebuilt bundles). ProofChain was this consumer’s only surviving path into the concelier family, so the pair fell out with that one two-edge cut; six consumer keys retired together for that reason. Verified: the commit’s diff removes exactly those two ProjectReferences. resolverCitation is null because the commit names no sprint and one must not be invented. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff. |
export-web | concelier | 2026-08-18 | resolved | 65b18b509f | fae623f5b3 | SPRINT_20260722_003 | deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by 65b18b509f (2026-08-18 11:04), which removed BOTH of StellaOps.Attestor.ProofChain’s references into src/Concelier – StellaOps.Feedser.Core and StellaOps.Concelier.SourceIntel – carrying the five record families into Evidence/ under a new namespace (copy, not move: both DLLs ship in 72 committed prebuilt bundles). ProofChain was this consumer’s only surviving path into the concelier family, so the pair fell out with that one two-edge cut; six consumer keys retired together for that reason. Verified: the commit’s diff removes exactly those two ProjectReferences. resolverCitation is null because the commit names no sprint and one must not be invented. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff. |
export-worker | concelier | 2026-08-18 | resolved | 65b18b509f | fae623f5b3 | SPRINT_20260722_003 | deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by 65b18b509f (2026-08-18 11:04), which removed BOTH of StellaOps.Attestor.ProofChain’s references into src/Concelier – StellaOps.Feedser.Core and StellaOps.Concelier.SourceIntel – carrying the five record families into Evidence/ under a new namespace (copy, not move: both DLLs ship in 72 committed prebuilt bundles). ProofChain was this consumer’s only surviving path into the concelier family, so the pair fell out with that one two-edge cut; six consumer keys retired together for that reason. Verified: the commit’s diff removes exactly those two ProjectReferences. resolverCitation is null because the commit names no sprint and one must not be invented. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff. |
platform | concelier | 2026-08-18 | resolved | 65b18b509f | fae623f5b3 | SPRINT_20260722_026 | deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by 65b18b509f (2026-08-18 11:04), which removed BOTH of StellaOps.Attestor.ProofChain’s references into src/Concelier – StellaOps.Feedser.Core and StellaOps.Concelier.SourceIntel – carrying the five record families into Evidence/ under a new namespace (copy, not move: both DLLs ship in 72 committed prebuilt bundles). ProofChain was this consumer’s only surviving path into the concelier family, so the pair fell out with that one two-edge cut; six consumer keys retired together for that reason. Verified: the commit’s diff removes exactly those two ProjectReferences. resolverCitation is null because the commit names no sprint and one must not be invented. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff. |
platform | workflow | 2026-08-18 | resolved | c9c3ee4bcf | 7ac5915b99 | SPRINT_20260722_026 | Severed by deleting WorkflowMigrationModulePlugin, its using, and Platform.Database’s ProjectReference to StellaOps.Workflow.DataStore.PostgreSQL. Verified rather than assumed: after the change a csproj-graph walk resolved Platform.Database to 137 projects with ZERO Workflow projects reachable, so the pin’s foreignProjectCount of 3 described nothing that existed, and Platform.Database built clean without the reference — proof the edge was consumed only by the deleted plugin. Safety measured BEFORE the edit: Platform.Database was the only external referencer of that project, and no reader of wf_host_locks or any workflow table exists outside src/Workflow/. This was retirable without the product decision W3-15 still owes (deploy Workflow later on its own database vs archive it) because platform-web migrating another service’s schema is the X15/DC-26 defect in BOTH branches; src/Workflow/ itself is untouched. Consequence carried forward: platform-web no longer creates the workflow schema on a fresh database, and the ~440 kB already converged on existing databases is central-migration residue that is NOT dropped here (destructive approval, W3-15 M5). Read-across: a pin whose owningSprint is the central-migrator retirement (026) can still be burned early by the OWNING family’s own program — this one was burned by 020, not by 026. |
policy-engine | attestor | 2026-08-18 | resolved | 0543ff2d4b | 0543ff2d4b | SPRINT_20260722_011 | Resolved by SPRINT_20260722_007 POL-F3, NOT by 011’s attestation-contract seam. The pin’s target seam was ‘published-package’ on the premise that Policy needed an attestation contract; it never did. policy-engine’s ONLY path into the Attestor family was Policy.Engine -> Scanner.ProofSpine -> Attestor.GraphRoot -> Attestor.Core, and ProofSpine’s only consumer in Policy was Vex/VexProofSpineService.cs, which no host registered and no caller invoked (the type appeared in exactly one file across all of src/). Deleting the dead service retired GraphRoot, Attestor.Core AND ProofChain together. Worth keeping: a pin’s recorded target seam is a HYPOTHESIS about why the edge exists, and this one was wrong for three years of project time - measure what the consumer actually uses before designing the seam. |
policy-engine | scanner | 2026-08-18 | resolved | 0543ff2d4b | 0543ff2d4b | SPRINT_20260722_017 | Resolved by SPRINT_20260722_007 POL-F3 with the same deletion that retired policy-engine|attestor: Vex/VexProofSpineService.cs was the sole consumer of StellaOps.Scanner.ProofSpine and was never registered or invoked. No Scanner API seam was needed and the ‘classify ProofSpine as a closed client SDK’ question 017 was holding is moot for Policy. A revived VEX proof-spine feature rides a Scanner-owned seam, never this compile edge. |
release-orchestrator | concelier | 2026-08-18 | resolved | 65b18b509f | fae623f5b3 | SPRINT_20260722_003 | deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by 65b18b509f (2026-08-18 11:04), which removed BOTH of StellaOps.Attestor.ProofChain’s references into src/Concelier – StellaOps.Feedser.Core and StellaOps.Concelier.SourceIntel – carrying the five record families into Evidence/ under a new namespace (copy, not move: both DLLs ship in 72 committed prebuilt bundles). ProofChain was this consumer’s only surviving path into the concelier family, so the pair fell out with that one two-edge cut; six consumer keys retired together for that reason. Verified: the commit’s diff removes exactly those two ProjectReferences. resolverCitation is null because the commit names no sprint and one must not be invented. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff. |
release-orchestrator | signer | 2026-08-18 | retired-resolver-unrecorded | — | 36f13a714c | SPRINT_20260722_019 | |
sbomservice | attestor | 2026-08-18 | resolved | c7aa9a54e9 | fae623f5b3 | SPRINT_20260722_011 | deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by c7aa9a54e9 (2026-08-18 11:14), which removed SbomService’s StellaOps.Excititor.Persistence ProjectReference – a VEX-delta read that never returned a row. SECOND-ORDER: sbomservice reached the ATTESTOR family only via Excititor.Persistence -> Excititor.Core -> Attestor.StandardPredicates, so cutting an old-plane edge closed an unrelated family pair. Verified: the commit’s diff removes exactly that reference, and this pair’s recorded witness routes through it. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff. |
sbomservice | concelier | 2026-08-18 | resolved | c7aa9a54e9 | fae623f5b3 | SPRINT_20260722_003 | deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by c7aa9a54e9 (2026-08-18 11:14), which removed SbomService’s StellaOps.Excititor.Persistence ProjectReference – a VEX-delta read that never returned a row. Verified: the commit’s diff removes exactly that reference, and this pair’s recorded witness routes through it. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff. |
sbomservice | excititor | 2026-08-18 | resolved | c7aa9a54e9 | fae623f5b3 | SPRINT_20260722_003 | deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by c7aa9a54e9 (2026-08-18 11:14), which removed SbomService’s StellaOps.Excititor.Persistence ProjectReference – a VEX-delta read that never returned a row. Verified: the commit’s diff removes exactly that reference, and this pair’s recorded witness routes through it. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff. |
platform | remediation | 2026-08-19 | retired-resolver-unrecorded | — | db34e0e09c | SPRINT_20260722_026 | |
notify-web | signer | 2026-08-20 | resolved | 6fbeeb75d5 | 799e18c757 | SPRINT_20260722_019 | Source commit 6fbeeb75d5 removed notify-web’s direct ProjectReference to StellaOps.Signer.Infrastructure and the NCS connector’s Signer.Contracts reference, leaving the default-off Signer HTTP API as the custody seam. The prior published-package target was a hypothesis superseded by the owner-directed API decision; boundary commit 799e18c757 only deregistered the already-dead pair. |
export-web | signer | 2026-08-21 | resolved | 6040e9a86f | 6040e9a86f | SPRINT_20260722_019 | SGN-7’s source commit extracted the shared DSSE/Sigstore vocabulary from Signer implementation and repointed the surviving consumers to custody-safe seams; export-web’s last Signer implementation path and its pin were removed in that same commit. |
export-worker | signer | 2026-08-21 | resolved | 6040e9a86f | 6040e9a86f | SPRINT_20260722_019 | SGN-7’s source commit extracted the shared DSSE/Sigstore vocabulary from Signer implementation and repointed the surviving consumers to custody-safe seams; export-worker’s last Signer implementation path and its pin were removed in that same commit. |
platform | signer | 2026-08-21 | resolved | 6040e9a86f | 6040e9a86f | SPRINT_20260722_026 | SGN-7’s source commit extracted the shared DSSE/Sigstore vocabulary from Signer implementation and repointed the surviving consumers to custody-safe seams; Platform’s last Signer implementation path and its pin were removed in that same commit. |
advisory-ai-web | evidence-locker | 2026-08-22 | resolved | ADR-038 / SPRINT_20260730_001 MBI-5 | 63ba8f350e | SPRINT_20260722_011 | AAI-9 gate 10 renamed the continuation deployable key to advisoryai-web; the edge did not retire at that point. The rename chain now terminates in MBI-5’s ADR-038 ownership correction: Evidence Pack is AdvisoryAI-owned service-family code, so the canonical successor pair is resolved without a live action. |
advisory-ai-worker | evidence-locker | 2026-08-22 | resolved | ADR-038 / SPRINT_20260730_001 MBI-5 | 63ba8f350e | SPRINT_20260722_011 | AAI-9 gate 10 renamed the continuation deployable key to advisoryai-worker; the edge did not retire at that point. The rename chain now terminates in MBI-5’s ADR-038 ownership correction: Evidence Pack is AdvisoryAI-owned service-family code, so the canonical successor pair is resolved without a live action. |
findings-vulncorrelation | scanner | 2026-08-22 | resolved | a494941d30 | a494941d30 | SPRINT_20260722_017 | The resolver commit moved the surface-manifest wire records byte-identically into the closed Scanner.Surface.Contracts seam and repointed Findings, so Findings no longer compiles Scanner’s filesystem implementation. |
integrations-web | concelier | 2026-08-22 | resolved | 1ebea598b1 | 49a06dbcea | SPRINT_20260722_003 | The resolver commit moved the unchanged StellaOps.VulnMatch.Core assembly from its misleading shared-tree Concelier classification into the Vulnerabilities producer tree, classified it as a conformance-verified closed artifact-consumer SDK, and repointed Integrations. The matcher algorithm and runtime call site did not change; only the false implementation ownership edge retired. Integrations’ separate raw vuln-schema read remains a runtime blocker and is not claimed here. |
policy-engine | concelier | 2026-08-22 | resolved | 1ebea598b1 | 49a06dbcea | SPRINT_20260722_003 | The resolver commit moved the unchanged StellaOps.VulnMatch.Core assembly from its misleading shared-tree Concelier classification into the Vulnerabilities producer tree, classified it as a conformance-verified closed artifact-consumer SDK, and repointed Policy. Policy keeps the same matcher assembly and behavior through an allowed owner-controlled seam; its 57-project closure now has zero foreign implementation pairs. |
scanner-web | release-orchestrator | 2026-08-22 | resolved | 7ff376eab3 | 7ff376eab3 | SPRINT_20260722_018 | The resolver commit moved the unchanged StellaOps.Runtime.Contracts assembly from the ReleaseOrchestrator family tree into the neutral shared-library tree and repointed Scanner. Assembly identity, namespaces, DTOs and wire schema identifiers are unchanged; only the false source ownership edge retired. |
scanner-worker | reachgraph | 2026-08-22 | resolved | 5383eb4ae5 | 5383eb4ae5 | SPRINT_20260722_023 | The resolver commit extracted the five reachgraph.min@v1 wire records byte-identically into the closed ReachGraph.Contracts seam and repointed Scanner Worker, preserving its POST /v1/reachgraphs runtime boundary without compiling producer implementation. |
airgap-time | airgap-controller | 2026-08-23 | resolved | 7abb168298 | 7abb168298 | SPRINT_20260722_025 | The resolver commit deleted a DEAD ProjectReference: AirGap.Importer declares 13 namespaces and airgap-time’s own source names only Auth.Abstractions, Auth.ServerIntegration and Router.AspNet outside its own root. The one consumer that uses Importer types without declaring them (StellaOps.AirGap.Persistence.Tests, via StellaOps.AirGap.Importer.Versioning) keeps compiling through its own AirGap.Controller reference, verified by building all four consumers. airgap-time now measures ZERO violation pairs (closure 24 -> 20) and Attestor leaves its foreign top-level list, which it had entered only through the Importer. Does not pre-empt OK-10’s deletion of the host. |
attestor-tileproxy | attestor | 2026-08-23 | resolved | 05508e0f9b | 05508e0f9b | SPRINT_20260722_011 | The resolver commit deleted TWO dead ProjectReferences: the tile proxy’s six source files reference only its own namespaces plus StellaOps.Auth.ServerIntegration.Tenancy, and nothing from StellaOps.Attestor.Core.* or StellaOps.Attestor.TrustRepo*. The pin was classified published-package, i.e. costed as a contract extraction, and needed none: the host compiled producer implementation it never called. attestor-tileproxy now measures ZERO violation pairs (closure 26 -> 19) and its remaining foreign top-levels are all P19-legal, so the key is complete rather than merely reduced. |
scanner-web | notify | 2026-08-23 | resolved | d6fdeb6168 | d6fdeb6168 | SPRINT_20260722_015 | The resolver commit deleted a DEAD ProjectReference: Scanner.WebService compiled and shipped StellaOps.Notify.Models while no source file in the host referenced it (zero ‘Notify’ tokens in its .cs, and that csproj was the only one in all of src/Scanner naming Notify). The 2026-08-17 measured publish ground truth lists Notify.Models among scanner-web’s 134 compiled projects, so this was a real shipped edge, not a bookkeeping artifact. No behaviour changed; ‘Notify’ also left scanner-web’s foreign top-level directory list (18 -> 17). |
airgap-controller | airgap-time | 2026-08-24 | resolved | f94a99128330cbaaecaa470a8cbc04390a01b274 | 0d413c8671 | SPRINT_20260722_025 | Source commit f94a991283 repointed airgap-controller from the StellaOps.AirGap.Time ASP.NET host to the neutral AirGap.Policy and AirGap.Time.Verification libraries. TimeAnchor remains verifier-owned; the three staleness types moved byte-identically to Policy; the historical host assembly forwards all four public types. Boundary commit 0d413c8671 only deregistered the already-stale pin and regenerated the measured graph. Controller Release publish contains both neutral libraries and no Time-host dependency or DLL; neither commit is evidence of a live host, route, schema, data or configuration change. |
platform | airgap-time | 2026-08-24 | resolved | f94a99128330cbaaecaa470a8cbc04390a01b274 | 0d413c8671 | SPRINT_20260722_026 | SECOND-ORDER: Platform reached airgap-time only through Platform.Persistence -> AirGap.Persistence -> AirGap.Controller -> AirGap.Time. Source commit f94a991283 removed the final Controller -> Time-host hop, so the transitive platform|airgap-time pair disappeared while Platform still compiles AirGap.Persistence and AirGap.Controller. Boundary commit 0d413c8671 only deregistered the already-stale pin. This does not complete the central-migrator retirement or evidence any artifact publication, deployment, database move, route swap or live activation. |
platform | graph | 2026-08-24 | resolved | 133c6a51f89a5328f14cebacce202dfa7f64f199 | bb511fbe4b | SPRINT_20260722_026 | Published-main source commit 133c6a51f89a5328f14cebacce202dfa7f64f199 removed GraphMigrationModulePlugin and Platform.Persistence’s direct ProjectReference to StellaOps.Graph.Indexer.Persistence, eliminating platform|graph from the measured source graph. Boundary commit a6d212904b only deregistered the already-stale pin. This is source-staged closure; neither commit is evidence of an artifact build, promotion, recreate, database move, route swap, or live activation. |
platform | reachgraph | 2026-08-24 | resolved | 133c6a51f89a5328f14cebacce202dfa7f64f199 | bb511fbe4b | SPRINT_20260722_026 | Published-main source commit 133c6a51f89a5328f14cebacce202dfa7f64f199 removed ReachGraphMigrationModulePlugin and Platform.Persistence’s direct ProjectReference to StellaOps.ReachGraph.Persistence, eliminating platform|reachgraph from the measured source graph. Boundary commit a6d212904b only deregistered the already-stale pin. This is source-staged closure; neither commit is evidence of an artifact build, promotion, recreate, database move, route swap, or live activation. |
platform | sbomservice | 2026-08-24 | resolved | c5b8f2d9febd7dc130865a51aac1e3c97df18092 | 4d92b5c64a | SPRINT_20260722_026 | Source commit c5b8f2d9fe removed the orphaned SbomLineageMigrationModulePlugin, Platform-owned wrapper migrations, and Platform.Persistence’s direct ProjectReference to StellaOps.SbomService.Lineage. Boundary commit 4d92b5c64a only deregistered the already-stale platform|sbomservice pin and regenerated the measured graph. Canonical SbomService persistence remains owned and startup-migrated by sbomservice-web; neither commit is evidence of live cleanup, database mutation, deployment, or route activation. |
sbomservice | integrations | 2026-08-24 | resolved | 79c5e6f987 | c44da0266a | SPRINT_20260722_024 | The resolver commit switched SbomService’s credential wire vocabulary to the exact offline Integrations.RegistryCredentials.Contracts package and its generic registry transport to the neutral StellaOps.Oci.RegistryClient foundation. The producer implementation graph Integrations.Contracts -> Integrations.Core plus Integrations.DockerV2 retired from the consumer closure (3 -> 0); isolated Release publish succeeds with src/Integrations absent. |
scanner-web | authority | 2026-08-24 | resolved | 0ed6b0b2f4377b512c49603ee10f572200044be2 | 85649f118e | SPRINT_20260722_016 | Source commit 0ed6b0b2f4 replaced Scanner’s borrowed Authority.Persistence OfflineKit audit DTO/interface with an equivalent Scanner-owned internal contract, preserving the registered no-op behavior while removing both Authority implementation projects from scanner-web’s closure. Boundary commit 562cc68b16 only deregistered the already-stale pin and regenerated the measured graph. Neither commit is evidence of durable audit emission, image publication, deployment, database mutation, route change, or live activation. |
platform | integrations | 2026-08-26 | resolved | d3358c84319b0da835e944d70f360f7df526d9c5 | 05437474ea | SPRINT_20260722_026 | Source commit d3358c8431 removed Platform’s Release Orchestrator implementation and persistence closure, which had been the remaining transitive carrier into Integrations.Contracts/Core. Platform’s runtime crypto-control call remains an explicit HTTP owner seam resolved only from STELLAOPS_INTEGRATIONS_URL, so no Integrations source project enters the Platform build. Boundary commit f1cad26a03 only deregistered the stale pin and regenerated the measured graph. Neither commit publishes an image, deploys, mutates a database, or proves live activation. |
platform | release-orchestrator | 2026-08-26 | resolved | d3358c84319b0da835e944d70f360f7df526d9c5 | 05437474ea | SPRINT_20260722_026 | Source commit d3358c8431 deleted Platform’s Release Orchestrator environment, scripts, EvidenceThread, federation, persistence, and deployment implementation graph. The surviving topology projection crosses a tenant-scoped signed HTTP owner API and a producer-owned zero-reference Topology.Contracts project classified as a closed cross-service client SDK; Platform compiles no Release Orchestrator implementation. Boundary commit f1cad26a03 only deregistered the stale pin and regenerated the measured graph. Neither commit publishes an image, deploys, mutates a database, or proves live activation. |
scanner-worker | binaryindex | 2026-08-26 | resolved | 0f3c71e3eab819ecdffb80dbeaa275b14e986fb3 | 0f3c71e3ea | SPRINT_20260722_014 | The source commit moved Scanner’s stateless rebuild/determinism engine into Scanner.BuildProvenance, retained repository-backed ground-truth tooling in BinaryIndex, and removed Scanner Worker’s final BinaryIndex implementation reference. The same commit deleted the now-stale register pin; no runtime, database, image, deployment, publication or live-state action is attributed. |
advisoryai-web | evidence-locker | 2026-08-27 | resolved | ADR-038 / SPRINT_20260730_001 MBI-5 | 4ceb5181b9 | SPRINT_20260722_011 | MBI-5 corrected the carrier inversion against accepted ADR-038 and current source: StellaOps.Evidence.Pack is AdvisoryAI analytical service-family code, served and persisted only by AdvisoryAI. Reclassifying its owner resolves the false EvidenceLocker pair; the same bounded correction replaces its namespace-dead AdvisoryAI.Attestation ProjectReference with the neutral Canonical.Json dependency it had carried transitively. No route, database, image, deployment or live state changes. |
advisoryai-worker | evidence-locker | 2026-08-27 | resolved | ADR-038 / SPRINT_20260730_001 MBI-5 | 4ceb5181b9 | SPRINT_20260722_011 | MBI-5 corrected the carrier inversion against accepted ADR-038 and current source: StellaOps.Evidence.Pack is AdvisoryAI analytical service-family code, served and persisted only by AdvisoryAI. Reclassifying its owner resolves the false EvidenceLocker pair; the same bounded correction replaces its namespace-dead AdvisoryAI.Attestation ProjectReference with the neutral Canonical.Json dependency it had carried transitively. No route, database, image, deployment or live state changes. |
export-web | timeline | 2026-08-27 | resolved | ce396303c9cf4d06100334d05673d29a4227ce83 | ce396303c9 | SPRINT_20260722_020 | The Q-5 source commit deleted behavior-dead TimelineEvidenceClient plus the three TimelineIndexer.Core ProjectReferences that carried Export Web, Export Worker and Platform into Timeline implementation. Timeline’s owner evidence endpoint and the separate HTTP-audit/event-publication paths remain; no live action is attributed. |
export-worker | timeline | 2026-08-27 | resolved | ce396303c9cf4d06100334d05673d29a4227ce83 | ce396303c9 | SPRINT_20260722_020 | The Q-5 source commit deleted behavior-dead TimelineEvidenceClient plus the three TimelineIndexer.Core ProjectReferences that carried Export Web, Export Worker and Platform into Timeline implementation. Timeline’s owner evidence endpoint and the separate HTTP-audit/event-publication paths remain; no live action is attributed. |
platform | timeline | 2026-08-27 | resolved | ce396303c9cf4d06100334d05673d29a4227ce83 | ce396303c9 | SPRINT_20260722_026 | SECOND-ORDER: Platform reached TimelineIndexer.Core only through Platform.Persistence -> ExportCenter.Infrastructure. The Q-5 source commit removed that dormant ExportCenter reference, so platform|timeline disappeared without a Platform source edit. Platform’s remaining central-migrator work is unaffected; no live action is attributed. |
scanner-web | airgap-controller | 2026-08-27 | resolved | 639095de2b | 639095de2b | SPRINT_20260722_025 | Q-25 moved the canonical import/status/manifest/validate transport and verified-carrier custody into OfflineKit, deleted Scanner’s duplicate OfflineKit API and its StellaOps.AirGap.Importer ProjectReference, and repointed CLI, Console, and gateway callers to /api/offlinekit/v1. The source commit therefore removes the scanner-web -> airgap-controller implementation pair while leaving content activation and the live Scanner-data disposition to OK-7/OK-10. |
agent-core | attestor | 2026-08-28 | retired-resolver-unrecorded | — | 742c9c60e1 | SPRINT_20260722_011 | |
findings-ledger-web | findings | 2026-08-28 | retired-resolver-unrecorded | — | d75e91e1a1 | SPRINT_20260722_010 | |
findings-security-web | findings | 2026-08-28 | retired-resolver-unrecorded | — | d75e91e1a1 | SPRINT_20260722_010 | |
release-orchestrator | attestor | 2026-08-28 | retired-resolver-unrecorded | — | 742c9c60e1 | SPRINT_20260722_011 | |
scanner-web | attestor | 2026-08-28 | retired-resolver-unrecorded | — | 742c9c60e1 | SPRINT_20260722_011 | |
scanner-web | concelier | 2026-08-28 | retired-resolver-unrecorded | — | d75e91e1a1 | SPRINT_20260722_003 | |
scanner-web | integrations | 2026-08-28 | retired-resolver-unrecorded | — | a95191ec48 | SPRINT_20260722_024 | |
scanner-web | policy | 2026-08-28 | retired-resolver-unrecorded | — | d75e91e1a1 | SPRINT_20260722_017 | |
scanner-worker | attestor | 2026-08-28 | retired-resolver-unrecorded | — | 742c9c60e1 | SPRINT_20260722_011 | |
scanner-worker | concelier | 2026-08-28 | retired-resolver-unrecorded | — | d75e91e1a1 | SPRINT_20260722_003 | |
scanner-worker | integrations | 2026-08-28 | retired-resolver-unrecorded | — | a95191ec48 | SPRINT_20260722_024 | |
binaryindex-web | attestor | 2026-09-04 | retired-resolver-unrecorded | — | ba3f7e3503 | SPRINT_20260722_011 | |
concelier | attestor | 2026-09-04 | retired-resolver-unrecorded | — | ba3f7e3503 | SPRINT_20260722_011 | |
evidence-locker-web | attestor | 2026-09-04 | retired-resolver-unrecorded | — | ba3f7e3503 | SPRINT_20260722_011 | |
excititor-web | attestor | 2026-09-04 | retired-resolver-unrecorded | — | ba3f7e3503 | SPRINT_20260722_011 | |
excititor-worker | attestor | 2026-09-04 | retired-resolver-unrecorded | — | ba3f7e3503 | SPRINT_20260722_011 | |
export-web | attestor | 2026-09-04 | retired-resolver-unrecorded | — | ba3f7e3503 | SPRINT_20260722_011 | |
export-web | evidence | 2026-09-04 | retired-resolver-unrecorded | — | e7aa21267b | SPRINT_20260722_011 | |
export-worker | attestor | 2026-09-04 | retired-resolver-unrecorded | — | ba3f7e3503 | SPRINT_20260722_011 | |
export-worker | evidence | 2026-09-04 | retired-resolver-unrecorded | — | e7aa21267b | SPRINT_20260722_011 | |
notifier-worker | notify | 2026-09-04 | retired-resolver-unrecorded | — | 60b2c77674 | SPRINT_20260722_015 | |
platform | attestor | 2026-09-04 | retired-resolver-unrecorded | — | ba3f7e3503 | SPRINT_20260722_026 | |
platform | evidence | 2026-09-05 | retired-resolver-unrecorded | — | 85290801d1 | SPRINT_20260722_011 | |
platform | authority | 2026-09-08 | retired-resolver-unrecorded | — | 86056143f2 | SPRINT_20260722_026 | |
platform | binaryindex | 2026-09-08 | retired-resolver-unrecorded | — | 86056143f2 | SPRINT_20260722_026 | |
platform | policy | 2026-09-08 | retired-resolver-unrecorded | — | 86056143f2 | SPRINT_20260722_026 | |
platform | issuer-directory | 2026-09-09 | resolved | b37466ce623b8e330d9f32be5bbe60f6f566e48e | b37466ce62 | SPRINT_20260722_026 | CM-2 removed the effective IssuerDirectory central migration plugin and its only Platform.Persistence implementation reference after the completed AUTH-9 fold. Authority migration 024 owns the separate issuer schema through the existing Authority ledger; the folded runtime registers no second migration host. The Platform graph shrank 82 to 80 projects, and its built deps.json has no IssuerDirectory or Authority.Persistence library. Source-only retirement; AUTH-10 retains predecessor-source cleanup and any old-schema drop. |
platform | notify | 2026-09-09 | resolved | d0d97b313034283f06e93953665e3ab3755b774b | d0d97b3130 | SPRINT_20260722_026 | CM-2 removed NotifyMigrationModulePlugin and its sole Platform.Persistence -> Notify.Persistence reference after the Notify cutover and predecessor retirement. The host build exposed one missing NIS2 payload contract, moved unchanged with its two routing records into the existing closed Notify.Contracts project. Platform’s measured graph is 82 projects with no Notify implementation; the host deps.json contains only Notify.Contracts and Notify.EventClient from that family. No live action is attributed. |
platform | airgap-controller | 2026-09-10 | resolved | 794a22106541fbf72012e11fb44be3ce6c1fdcc7 | 794a221065 | SPRINT_20260722_026 | OK-5 source retirement. The running Controller and airgap schema still require the approved retirement window. |
authority | issuer-directory | 2026-09-11 | retired-resolver-unrecorded | — | 0f2efb7692 | SPRINT_20260722_016 | |
binaryindex-web | concelier | 2026-09-11 | retired-resolver-unrecorded | — | 0146d5bbe4 | SPRINT_20260722_003 | |
binaryindex-web | evidence | 2026-09-11 | retired-resolver-unrecorded | — | 0146d5bbe4 | SPRINT_20260722_011 | |
binaryindex-web | excititor | 2026-09-11 | retired-resolver-unrecorded | — | 0146d5bbe4 | SPRINT_20260722_003 | |
concelier | evidence | 2026-09-11 | retired-resolver-unrecorded | — | 9b648b5534 | SPRINT_20260722_011 | |
concelier | excititor | 2026-09-11 | retired-resolver-unrecorded | — | 9b648b5534 | SPRINT_20260722_003 | |
excititor-web | concelier | 2026-09-11 | retired-resolver-unrecorded | — | 0146d5bbe4 | SPRINT_20260722_003 | |
excititor-web | evidence | 2026-09-11 | retired-resolver-unrecorded | — | 0146d5bbe4 | SPRINT_20260722_011 | |
excititor-worker | concelier | 2026-09-11 | retired-resolver-unrecorded | — | 0146d5bbe4 | SPRINT_20260722_003 | |
excititor-worker | evidence | 2026-09-11 | retired-resolver-unrecorded | — | 0146d5bbe4 | SPRINT_20260722_011 | |
notify-web | findings | 2026-09-11 | resolved | docs-archive/implplan/SPRINT_20260722_015_Notify_service_consolidation_program.md#ntf-9-live-nis2-handoff-cutover | 2492ff29e0 | SPRINT_20260722_010 | NTF-9 removes the in-process NIS2 emitter, adapter and foreign ProjectReference after live producer/consumer replay and independent tenant checkpoint proof. |
export-web | findings | 2026-09-12 | retired-resolver-unrecorded | — | 8888132e65 | SPRINT_20260722_010 | |
export-web | notify | 2026-09-12 | retired-resolver-unrecorded | — | 8888132e65 | SPRINT_20260722_015 | |
export-web | scanner | 2026-09-12 | retired-resolver-unrecorded | — | 8888132e65 | SPRINT_20260722_017 | |
export-worker | findings | 2026-09-12 | retired-resolver-unrecorded | — | 8888132e65 | SPRINT_20260722_010 | |
export-worker | notify | 2026-09-12 | retired-resolver-unrecorded | — | 8888132e65 | SPRINT_20260722_015 | |
export-worker | scanner | 2026-09-12 | retired-resolver-unrecorded | — | 8888132e65 | SPRINT_20260722_017 | |
platform | export-center | 2026-09-12 | retired-resolver-unrecorded | — | 12d3cdfa77 | SPRINT_20260722_026 | |
platform | packsregistry | 2026-09-12 | retired-resolver-unrecorded | — | 9865d0b4b5 | SPRINT_20260722_026 | |
platform | scanner | 2026-09-12 | retired-resolver-unrecorded | — | 12d3cdfa77 | SPRINT_20260722_026 | |
platform | scheduler | 2026-09-12 | retired-resolver-unrecorded | — | 9865d0b4b5 | SPRINT_20260722_026 | |
scheduler-web | notify | 2026-09-12 | retired-resolver-unrecorded | — | 9865d0b4b5 | SPRINT_20260722_015 | |
scheduler-web | scanner | 2026-09-12 | retired-resolver-unrecorded | — | fd91338c02 | SPRINT_20260722_017 | |
platform | evidence-locker | 2026-09-14 | retired-resolver-unrecorded | — | e58630dc3c | SPRINT_20260722_026 | |
agent-core | scanner | 2026-09-15 | retired-resolver-unrecorded | — | c84b4af142 | SPRINT_20260730_001 | |
jobengine-web | scanner | 2026-09-15 | retired-resolver-unrecorded | — | 44c06e7306 | SPRINT_20260730_001 | |
offlinekit-web | findings | 2026-09-15 | resolved | c0b6a793ef | c0b6a793ef | SPRINT_20260730_001 | |
offlinekit-web | scanner | 2026-09-15 | resolved | c4756e5905 | c4756e5905 | SPRINT_20260730_001 | |
offlinekit-worker | findings | 2026-09-15 | resolved | c0b6a793ef | c0b6a793ef | SPRINT_20260730_001 | |
offlinekit-worker | scanner | 2026-09-15 | resolved | c4756e5905 | c4756e5905 | SPRINT_20260730_001 | |
release-orchestrator | notify | 2026-09-15 | resolved | cd0ca2a124 | cd0ca2a124 | SPRINT_20260722_015 | |
release-orchestrator | scanner | 2026-09-15 | retired-resolver-unrecorded | — | b2232ab28f | SPRINT_20260730_001 | |
release-orchestrator | integrations | 2026-09-16 | retired-resolver-unrecorded | — | 734b7ba141 | SPRINT_20260730_001 |
6. How to record a retirement
When your lane severs an edge:
Delete the pin from
legacy-edge-register.jsonin the same commit as the source change.Regenerate:
pwsh tools/scripts/build-boundary/generate-build-boundary-report.ps1. The pair moves out of §3 by itself; nothing here is edited by hand.Record the resolver so the row does not land as
retired-resolver-unrecorded:pwsh tools/scripts/build-boundary/generate-legacy-edge-dispositions.ps1 -UpdateLedgerthen set
status: "resolved"andresolverCommit(the commit that severed the edge, which is not necessarily the one that deleted the pin) plus a one-linenoteon that entry inlegacy-edge-resolvers.json, and regenerate again.-UpdateLedgerpreserves those fields on every later run.
