Legacy-edge dispositions — generated from the register

GENERATED FILE — do not hand-edit. Every edit is overwritten on the next run, and -Check fails while it survives. Produced by tools/scripts/build-boundary/generate-legacy-edge-dispositions.ps1, which generate-build-boundary-report.ps1 invokes in the same pass — so this document and the report are always generated from one state of the tree.

Generated 2026-09-15 (UTC).

Source of truth. Live rows ARE the pins in legacy-edge-register.json — key, seam, owner, sunset and foreign-project count are read from it, never transcribed. Retired rows come from legacy-edge-resolvers.json, the retirement ledger, because a resolved pin is DELETED from the register (pins are shrink-only and expire on use) and so the register cannot carry its own history. A row here can therefore never name a pin the register does not, which is exactly what the hand-maintained version of this table did: on 2026-08-17 about 65 of its 151 rows named pins that no longer existed, and the nine that had been struck implied the other 142 had been checked. They had not.

Regenerate / verify:

pwsh tools/scripts/build-boundary/generate-build-boundary-report.ps1          # report + this file
pwsh tools/scripts/build-boundary/generate-build-boundary-report.ps1 -Check   # fails if either is stale

A resolver is never guessed. A retired row cites the commit that severed the edge only where a human verified it; otherwise it reads retired-resolver-unrecorded and shows the commit that deregistered the pin, which is a starting point and not an attribution — the two are frequently different commits (a bookkeeping sweep deletes the pin days after the fix).

The dated MBI-4 hand compilation is preserved at legacy-edge-dispositions-2026-08-06-mbi4-compilation.md— its reasoning, gate-coverage findings (§6), undecided remainder (§7) and criteria state (§9) are point-in-time evidence that this generated table deliberately does not reproduce.

1. Counts

MeasureValue
Live pins in the register0
Library-impurity pins0
Retired pairs in the ledger249
— with a verified resolver66
— resolver unrecorded183
— superseded by a rename0
Measured violation pairs (report)0
Unpinned pairs (report)0
Stale pins (report)0
Grown pins (report)0

Reconciliation: the register holds 0 pins and the measured graph holds 0 violation pairs, with 0 unpinned and 0 stale required for the gate to pass. Those two numbers are produced by different tools from the same tree; if they disagree here, -Check is already red.

Live pins by disposition class

Disposition classPins

Live pins by owning program

Owning programPins

2. How a row is classified

The register’s targetSeam maps onto the build-coupling decision test in ../service-consolidation-review.md. The mapping is fail-closed: a seam value that is not in this table stops generation rather than being rendered unclassified.

Register targetSeamDisposition classDecision-test clauseMeaning
mergedies-by-consolidation1one domain lifecycle, or the mechanism holding the edge is deleted — no runtime seam is manufactured
apiowner-API seam2keep separate; consumer calls the owner’s API
eventevent seam2keep separate; consumer subscribes to a versioned event
artifactartifact seam2keep separate; consumer reads a content-addressed artifact
published-packagepackage/closed-SDK seam2keep separate; producer publishes an exact-version package, or a producer-owned closed client/contract project whose graph conformance proves it implementation-free
neutral-sdkneutral-SDK purification4a shared library’s own closure must stop reaching service implementation

A .Contracts/.Client name is not a disposition — clause 3 forbids that, and the closed graph is what admits the seam. published-package deliberately covers both a published package and a producer-owned closed source project; which one ships is the producer program’s call at its contract-freeze stage.

3. Live pins, by owning program

One row per register pin. Foreign projects is the pinned (shrink-only) count; where the measured graph is already below it, the measured value is shown first — that is a partially burned-down edge, not a discrepancy. Carrier is the producer-side project the consumer’s closure enters, i.e. the last hop of the pin’s shortest witness.

4. Library-impurity pins

A shared/neutral or client-SDK project whose OWN closure reaches service implementation. These are not consumer-key pairs: the project is the subject, and it clears by purification, not by a consumer changing anything.

None.

4a. Approved merge edges — D14 consolidations in progress (expiring)

NOT pins. Exact (consumer key x producer family) pairs an owner-approved D14 consolidation program is allowed to compile AHEAD of its S9/S10 window (2026-08-24 DC-40 amendment). Each cites its program and EXPIRES the moment the pair leaves the derived graph; the reverse direction is never covered and fails like any new edge. Family re-classification itself still happens only when the owning program lands its stage evidence (README).

None.

5. Retired pins — the burn-down ledger

Pairs that were pinned and are not any more, oldest first. Deregistered is the commit that removed the pin from the register (machine-derived from the register’s git history, always present). Resolver is the commit that actually severed the edge, and appears only where a human verified it — the two are often different, so an unrecorded resolver is left unrecorded.

Consumer keyProducer familyRetiredStatusResolverDeregisteredPinned ownerNote
export-websignals2026-08-02retired-resolver-unrecorded4159ae78f5SPRINT_20260722_020
export-workersignals2026-08-02retired-resolver-unrecorded4159ae78f5SPRINT_20260722_020
policy-enginesignals2026-08-02retired-resolver-unrecorded4159ae78f5SPRINT_20260722_007
vexhub-webevidence-locker2026-08-02retired-resolver-unrecordeda21ad75ec5SPRINT_20260722_011
vexhub-webreplay2026-08-02retired-resolver-unrecordeda21ad75ec5SPRINT_20260722_020
vexhub-websbomservice2026-08-02retired-resolver-unrecordeda21ad75ec5SPRINT_20260722_020
vexhub-webscheduler2026-08-02retired-resolver-unrecordeda21ad75ec5SPRINT_20260722_012
vexhub-websignals2026-08-02retired-resolver-unrecordeda21ad75ec5SPRINT_20260722_020
vexlens-webauthority2026-08-02retired-resolver-unrecorded48571c85b6SPRINT_20260722_016
vexlens-webevidence-locker2026-08-02retired-resolver-unrecordeda21ad75ec5SPRINT_20260722_011
vexlens-webissuer-directory2026-08-02retired-resolver-unrecorded48571c85b6SPRINT_20260722_016
vexlens-webreplay2026-08-02retired-resolver-unrecordeda21ad75ec5SPRINT_20260722_020
vexlens-websbomservice2026-08-02retired-resolver-unrecordeda21ad75ec5SPRINT_20260722_020
vexlens-webscheduler2026-08-02retired-resolver-unrecordeda21ad75ec5SPRINT_20260722_012
vexlens-websignals2026-08-02retired-resolver-unrecordeda21ad75ec5SPRINT_20260722_020
export-websbomservice2026-08-03retired-resolver-unrecordedfe8b66ca79SPRINT_20260722_020
export-webscheduler2026-08-03retired-resolver-unrecorded80756a1ef2SPRINT_20260722_012
export-workersbomservice2026-08-03retired-resolver-unrecordedfe8b66ca79SPRINT_20260722_020
export-workerscheduler2026-08-03retired-resolver-unrecorded80756a1ef2SPRINT_20260722_012
policy-enginesbomservice2026-08-03retired-resolver-unrecordedfe8b66ca79SPRINT_20260722_020
policy-enginescheduler2026-08-03retired-resolver-unrecorded80756a1ef2SPRINT_20260722_012
advisory-ai-webexcititor2026-08-05retired-resolver-unrecorded08f6db4e7dSPRINT_20260722_003
advisory-ai-webfindings-ledger2026-08-05retired-resolver-unrecorded7441571ec2SPRINT_20260722_010
advisory-ai-webopsmemory2026-08-05retired-resolver-unrecorded8f2b14c5c4SPRINT_20260722_013
advisory-ai-webscanner2026-08-05retired-resolver-unrecorded74f054f765SPRINT_20260722_017
advisory-ai-workerexcititor2026-08-05retired-resolver-unrecorded08f6db4e7dSPRINT_20260722_003
advisory-ai-workerfindings-ledger2026-08-05retired-resolver-unrecorded7441571ec2SPRINT_20260722_010
advisory-ai-workeropsmemory2026-08-05retired-resolver-unrecorded8f2b14c5c4SPRINT_20260722_013
advisory-ai-workerscanner2026-08-05retired-resolver-unrecorded74f054f765SPRINT_20260722_017
agent-coreevidence-locker2026-08-05retired-resolver-unrecorded5d1c74331cSPRINT_20260722_011
agent-coresigner2026-08-05retired-resolver-unrecordedda89f92665SPRINT_20260722_019
airgap-controllerattestor2026-08-05retired-resolver-unrecorded6ad5bdfd25SPRINT_20260722_011
airgap-timeattestor2026-08-05retired-resolver-unrecorded6ad5bdfd25SPRINT_20260722_011
attestorscanner2026-08-05retired-resolver-unrecorded74f054f765SPRINT_20260722_017
attestorsigner2026-08-05retired-resolver-unrecorded07de59cdd4SPRINT_20260722_019
attestor-tileproxysigner2026-08-05retired-resolver-unrecorded07de59cdd4SPRINT_20260722_019
authorityattestor2026-08-05retired-resolver-unrecorded6ad5bdfd25SPRINT_20260722_011
binaryindex-webscanner2026-08-05retired-resolver-unrecorded74f054f765SPRINT_20260722_017
concelierscanner2026-08-05retired-resolver-unrecorded74f054f765SPRINT_20260722_017
evidence-locker-websigner2026-08-05retired-resolver-unrecorded07de59cdd4SPRINT_20260722_019
excititor-webscanner2026-08-05retired-resolver-unrecorded74f054f765SPRINT_20260722_017
excititor-workerscanner2026-08-05retired-resolver-unrecorded74f054f765SPRINT_20260722_017
export-webevidence-locker2026-08-05retired-resolver-unrecordedf03f7a280bSPRINT_20260722_011
export-webreplay2026-08-05retired-resolver-unrecorded2cd6521cd2SPRINT_20260722_020
export-workerevidence-locker2026-08-05retired-resolver-unrecordedf03f7a280bSPRINT_20260722_011
export-workerreplay2026-08-05retired-resolver-unrecorded2cd6521cd2SPRINT_20260722_020
findings-ledger-webbinaryindex2026-08-05retired-resolver-unrecorded2c7556cf4aSPRINT_20260722_014
findings-ledger-webconcelier2026-08-05retired-resolver-unrecorded2c7556cf4aSPRINT_20260722_003
findings-ledger-webpolicy2026-08-05retired-resolver-unrecorded2c7556cf4aSPRINT_20260722_007
findings-ledger-webreplay2026-08-05retired-resolver-unrecorded2c7556cf4aSPRINT_20260722_020
findings-ledger-webscanner2026-08-05retired-resolver-unrecorded2c7556cf4aSPRINT_20260722_010
findings-ledger-websignals2026-08-05retired-resolver-unrecorded2c7556cf4aSPRINT_20260722_010
findings-ledger-websigner2026-08-05retired-resolver-unrecorded07de59cdd4SPRINT_20260722_019
findings-security-webfindings-ledger2026-08-05retired-resolver-unrecorded2c7556cf4aSPRINT_20260722_010
findings-vulncorrelationfindings-ledger2026-08-05retired-resolver-unrecorded2c7556cf4aSPRINT_20260722_010
integrations-webattestor2026-08-05retired-resolver-unrecorded300012e388SPRINT_20260722_011
integrations-webbinaryindex2026-08-05retired-resolver-unrecorded300012e388SPRINT_20260722_014
integrations-webevidence-locker2026-08-05retired-resolver-unrecorded300012e388SPRINT_20260722_011
integrations-webpolicy2026-08-05retired-resolver-unrecorded300012e388SPRINT_20260722_007
integrations-webreplay2026-08-05retired-resolver-unrecorded300012e388SPRINT_20260722_020
integrations-websignals2026-08-05retired-resolver-unrecorded300012e388SPRINT_20260722_020
integrations-websigner2026-08-05retired-resolver-unrecorded300012e388SPRINT_20260722_019
notify-webattestor2026-08-05retired-resolver-unrecorded6ad5bdfd25SPRINT_20260722_011
notify-webnotifier2026-08-05retired-resolver-unrecordeda5b589522dSPRINT_20260722_015
opsmemory-webattestor2026-08-05retired-resolver-unrecorded7441571ec2SPRINT_20260722_011
opsmemory-webevidence-locker2026-08-05retired-resolver-unrecorded7441571ec2SPRINT_20260722_011
opsmemory-webfindings-ledger2026-08-05retired-resolver-unrecorded7441571ec2SPRINT_20260722_010
platformfindings-ledger2026-08-05retired-resolver-unrecorded2c7556cf4aSPRINT_20260722_026
policy-engineevidence-locker2026-08-05retired-resolver-unrecorded470218621fSPRINT_20260722_011
policy-enginesigner2026-08-05retired-resolver-unrecorded07de59cdd4SPRINT_20260722_019
release-orchestratorevidence-locker2026-08-05retired-resolver-unrecorded5d1c74331cSPRINT_20260722_011
sbomservicescanner2026-08-05retired-resolver-unrecorded74f054f765SPRINT_20260722_017
scanner-webevidence-locker2026-08-05retired-resolver-unrecorded470218621fSPRINT_20260722_011
scanner-websigner2026-08-05retired-resolver-unrecordedda89f92665SPRINT_20260722_019
scanner-workerevidence-locker2026-08-05retired-resolver-unrecorded5d1c74331cSPRINT_20260722_011
scanner-workersigner2026-08-05retired-resolver-unrecordedda89f92665SPRINT_20260722_019
signerattestor2026-08-05retired-resolver-unrecorded6ad5bdfd25SPRINT_20260722_011
unknowns-webscanner2026-08-05retired-resolver-unrecorded74f054f765SPRINT_20260722_017
vexhub-webattestor2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_011
vexhub-webconcelier2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_003
vexhub-webexcititor2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_003
vexhub-webpolicy2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_007
vexhub-webreachgraph2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_023
vexhub-webscanner2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_017
vexhub-websigner2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_019
vexhub-webvexlens2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_022
vexlens-webattestor2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_011
vexlens-webconcelier2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_003
vexlens-webexcititor2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_003
vexlens-webpolicy2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_007
vexlens-webreachgraph2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_023
vexlens-webscanner2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_017
vexlens-websigner2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_019
vexlens-webvexhub2026-08-05retired-resolver-unrecordeda8472b6e10SPRINT_20260722_003
agent-coreintegrations2026-08-09retired-resolver-unrecordedbec6a5c69fSPRINT_20260722_024
agent-corerelease-orchestrator2026-08-09retired-resolver-unrecordedbec6a5c69fSPRINT_20260722_018
agent-corereplay2026-08-09retired-resolver-unrecorded261fc5ea86SPRINT_20260722_020
concelierreplay2026-08-09retired-resolver-unrecorded261fc5ea86SPRINT_20260722_020
platformagent-core2026-08-09retired-resolver-unrecordedbec6a5c69fSPRINT_20260722_026
platformreplay2026-08-09retired-resolver-unrecorded261fc5ea86SPRINT_20260722_026
platformunknowns2026-08-09retired-resolver-unrecordedb4975169e2SPRINT_20260722_026
policy-enginereplay2026-08-09retired-resolver-unrecorded261fc5ea86SPRINT_20260722_020
release-orchestratoragent-core2026-08-09retired-resolver-unrecordedbec6a5c69fSPRINT_20260722_018
release-orchestratorreplay2026-08-09retired-resolver-unrecorded261fc5ea86SPRINT_20260722_020
scanner-webreplay2026-08-09retired-resolver-unrecorded261fc5ea86SPRINT_20260722_020
scanner-websignals2026-08-09retired-resolver-unrecorded1a7ad55306SPRINT_20260722_020
scanner-workerreplay2026-08-09retired-resolver-unrecorded261fc5ea86SPRINT_20260722_020
scanner-workersignals2026-08-09retired-resolver-unrecorded1a7ad55306SPRINT_20260722_020
scanner-workerunknowns2026-08-09retired-resolver-unrecordedb4975169e2SPRINT_20260722_020
timeline-webreplay2026-08-09retired-resolver-unrecorded261fc5ea86SPRINT_20260722_020
binaryindex-websymbols2026-08-10resolvedSPRINT_20260730_001 MBI-3b480dd6307SPRINT_20260722_014PIN DELETED 2026-08-10 (SPRINT_20260730_001 MBI-3): BinaryIndex.DeltaSig repointed to the closed StellaOps.Symbols.Contracts, so this edge died with the extraction. Row struck 2026-08-17 — it had been stale in this table for a week after the register row went.
findings-ledger-webevidence-locker2026-08-10resolved8745312a198745312a19SPRINT_20260722_011One ProjectReference swap: StellaOps.Findings.Ledger pointed at StellaOps.EvidenceLocker.Core for a single static PII helper (CapsulePiiGuard.FindPiiViolations) whose namespace has lived in the producer’s CLOSED .Contracts project since extraction, so the locker’s domain core was being dragged into two deployables for nothing. Retired ahead of the 011 consolidation it was scheduled behind. Read-across: check the producer’s .Contracts before scheduling a consumer’s edge behind that producer’s merge.
integrations-webscanner2026-08-10retired-resolver-unrecorded1ec5702a94SPRINT_20260722_017
notify-webevidence-locker2026-08-10resolved8745312a198745312a19SPRINT_20260722_011Same resolver and same swap as findings-ledger-web -> evidence-locker; both witnesses ran through StellaOps.Findings.Ledger.
platformsymbols2026-08-10retired-resolver-unrecordedb480dd6307SPRINT_20260722_026
scanner-workersymbols2026-08-10resolvedMBI-3b480dd6307SPRINT_20260722_014PIN DELETED 2026-08-10 (MBI-3): same extraction; same week-long table drift.
signalsscanner2026-08-10retired-resolver-unrecorded1ec5702a94SPRINT_20260722_017
advisory-ai-webpolicy2026-08-11retired-resolver-unrecordedb30a1f2cbcSPRINT_20260722_007
advisory-ai-workerpolicy2026-08-11retired-resolver-unrecordedb30a1f2cbcSPRINT_20260722_007
agent-corepolicy2026-08-11retired-resolver-unrecordedab61e8205dSPRINT_20260722_007
binaryindex-webpolicy2026-08-11retired-resolver-unrecordedab61e8205dSPRINT_20260722_007
concelierpolicy2026-08-11retired-resolver-unrecordedab61e8205dSPRINT_20260722_007
excititor-webpolicy2026-08-11retired-resolver-unrecordedab61e8205dSPRINT_20260722_007
excititor-workerpolicy2026-08-11retired-resolver-unrecordedab61e8205dSPRINT_20260722_007
export-webpolicy2026-08-11retired-resolver-unrecorded69654c8029SPRINT_20260722_007
export-workerpolicy2026-08-11retired-resolver-unrecorded69654c8029SPRINT_20260722_007
release-orchestratorpolicy2026-08-11retired-resolver-unrecordedab61e8205dSPRINT_20260722_007
sbomservicepolicy2026-08-11retired-resolver-unrecordedab61e8205dSPRINT_20260722_007
scanner-workerpolicy2026-08-11retired-resolver-unrecordedab61e8205dSPRINT_20260722_007
unknowns-webattestor2026-08-11retired-resolver-unrecordedab61e8205dSPRINT_20260722_011
unknowns-webconcelier2026-08-11retired-resolver-unrecordedab61e8205dSPRINT_20260722_003
unknowns-webpolicy2026-08-11retired-resolver-unrecordedab61e8205dSPRINT_20260722_007
advisory-ai-webattestor2026-08-17resolvedb30a1f2cbc94fd3896c4SPRINT_20260722_011PIN DELETED 2026-08-17: resolved by b30a1f2cbc(POL-F5 stage 2a), NOT by the concelier resolver. AdvisoryAI reached Attestor only THROUGH StellaOps.Policy; repointing it to the closed StellaOps.Policy.Contracts — whose graph reaches no Attestor — killed the path. Worth keeping: the same consumer’s attestor and concelier pins died to different commits in different sprints, so one citation for both would have been wrong.
advisory-ai-webconcelier2026-08-17resolved3419d519df94fd3896c4SPRINT_20260722_003PIN DELETED 2026-08-17: resolved by 3419d519df, which removed AdvisoryAI’s last three Concelier references (Concelier.Core, .RawModels, .Persistence) together with the provider files that were their only consumers. The long-standing “14 (pin says 15)” drift note in this row dies with it.
advisory-ai-workerattestor2026-08-17resolvedb30a1f2cbc94fd3896c4SPRINT_20260722_011PIN DELETED 2026-08-17: same resolver, b30a1f2cbc.
advisory-ai-workerconcelier2026-08-17resolved3419d519df94fd3896c4SPRINT_20260722_003PIN DELETED 2026-08-17: same resolver, 3419d519df.
doctor-webscheduler2026-08-17resolved009 DOC-5 stage 4c3246bacb2SPRINT_20260722_012PIN DELETED 2026-08-17 (009 DOC-5 stage 4): the CONSUMER deployable is retired, so the edge has no live violation to pin. Predicted by the §812 disposition below, which called this “not applicable — the consumer deployable is owner-decided to retire”.
export-webfindings-ledger2026-08-17resolvedSPRINT_20260730_001 MBI-5c. The rename chain is COMPLETE: this pair was renamed into offlinekit-web|findings by the ExportCenter/OfflineKit consolidation, and that successor pin is itself now retired – StellaOps.Findings.DoraRoi was reclassified domain-neutral-shared and relocated to src/__Libraries/, so no offlinekit key compiles a Findings-owned project any more. supersededBy is kept as history; the ledger rule that a rename must point at a LIVE pin no longer applies once the chain ends in a resolution rather than another pin.0b6452223fSPRINT_20260722_010Producer family relabelled findings-ledger -> findings by FND-8 c2 in 0b6452223f; verified in that commit register diff, which changes producerFamily on exactly these three pins and severs no edge. The edge did not retire - it is the live row named in supersededBy.
export-workerfindings-ledger2026-08-17resolvedSPRINT_20260730_001 MBI-5c. The rename chain is COMPLETE: this pair was renamed into offlinekit-worker|findings by the ExportCenter/OfflineKit consolidation, and that successor pin is itself now retired – StellaOps.Findings.DoraRoi was reclassified domain-neutral-shared and relocated to src/__Libraries/, so no offlinekit key compiles a Findings-owned project any more. supersededBy is kept as history; the ledger rule that a rename must point at a LIVE pin no longer applies once the chain ends in a resolution rather than another pin.0b6452223fSPRINT_20260722_010Producer family relabelled findings-ledger -> findings by FND-8 c2 in 0b6452223f; same commit and same rename as export-web. The edge did not retire.
findings-ledger-webattestor2026-08-17resolved90352bc2f590352bc2f5SPRINT_20260722_010SPRINT_20260722_010 F-R0817-1: three submission types git mv’d out of StellaOps.Attestor.Core into a closed StellaOps.Attestor.Contracts, byte-identically and with the namespace preserved, so none of the 20 other Attestor.Core consumers changed a line. The register’s published-package seam was measured wrong for this edge against client-sdk-seam.md section 1 - a package is justified only when the consumer ships outside the monorepo, and findings-web does not, so the closed source seam was the correct choice. Last build-boundary blocker on FND-8’s host composition.
findings-vulncorrelationconcelier2026-08-17resolved652421d7bf94fd3896c4SPRINT_20260722_003PIN DELETED 2026-08-17: resolved by 652421d7bf, which removed the HOST’s own Concelier.SbomIntegration reference — the edge this row names. 0ac1b5d30a is the commit usually cited and it is not the resolver: it retargeted the Application and Tests projects, which mattered but did not kill the pinned edge.
notify-webfindings-ledger2026-08-17resolveddocs-archive/implplan/SPRINT_20260722_015_Notify_service_consolidation_program.md#ntf-9-live-nis2-handoff-cutover0b6452223fSPRINT_20260722_010Producer family relabelled findings-ledger -> findings by FND-8 c2 in 0b6452223f; same commit and same rename as export-web. The edge did not retire. NTF-9 subsequently retired the successor Notify-to-Findings implementation edge after the two-tenant owner proof.
scanner-webbinaryindex2026-08-17resolved014 BIN-5c3246bacb2SPRINT_20260722_014PIN DELETED 2026-08-17 (014 BIN-5): closure emptied to ZERO. Not by moving anything — D-BIN5-6 was ruled and the shared disassembly stack (Disassembly(+.Abstractions), Semantic, Decompiler, Ghidra, Contracts) is classified domain-neutral-shared, so all six of this key’s foreign projects stopped being violations where they stand.
agent-coreconcelier2026-08-18resolved65b18b509ffae623f5b3SPRINT_20260722_003deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by 65b18b509f (2026-08-18 11:04), which removed BOTH of StellaOps.Attestor.ProofChain’s references into src/Concelier – StellaOps.Feedser.Core and StellaOps.Concelier.SourceIntel – carrying the five record families into Evidence/ under a new namespace (copy, not move: both DLLs ship in 72 committed prebuilt bundles). ProofChain was this consumer’s only surviving path into the concelier family, so the pair fell out with that one two-edge cut; six consumer keys retired together for that reason. Verified: the commit’s diff removes exactly those two ProjectReferences. resolverCitation is null because the commit names no sprint and one must not be invented. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff.
attestorconcelier2026-08-18resolved65b18b509ffae623f5b3SPRINT_20260722_003deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by 65b18b509f (2026-08-18 11:04), which removed BOTH of StellaOps.Attestor.ProofChain’s references into src/Concelier – StellaOps.Feedser.Core and StellaOps.Concelier.SourceIntel – carrying the five record families into Evidence/ under a new namespace (copy, not move: both DLLs ship in 72 committed prebuilt bundles). ProofChain was this consumer’s only surviving path into the concelier family, so the pair fell out with that one two-edge cut; six consumer keys retired together for that reason. Verified: the commit’s diff removes exactly those two ProjectReferences. resolverCitation is null because the commit names no sprint and one must not be invented. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff.
export-webconcelier2026-08-18resolved65b18b509ffae623f5b3SPRINT_20260722_003deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by 65b18b509f (2026-08-18 11:04), which removed BOTH of StellaOps.Attestor.ProofChain’s references into src/Concelier – StellaOps.Feedser.Core and StellaOps.Concelier.SourceIntel – carrying the five record families into Evidence/ under a new namespace (copy, not move: both DLLs ship in 72 committed prebuilt bundles). ProofChain was this consumer’s only surviving path into the concelier family, so the pair fell out with that one two-edge cut; six consumer keys retired together for that reason. Verified: the commit’s diff removes exactly those two ProjectReferences. resolverCitation is null because the commit names no sprint and one must not be invented. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff.
export-workerconcelier2026-08-18resolved65b18b509ffae623f5b3SPRINT_20260722_003deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by 65b18b509f (2026-08-18 11:04), which removed BOTH of StellaOps.Attestor.ProofChain’s references into src/Concelier – StellaOps.Feedser.Core and StellaOps.Concelier.SourceIntel – carrying the five record families into Evidence/ under a new namespace (copy, not move: both DLLs ship in 72 committed prebuilt bundles). ProofChain was this consumer’s only surviving path into the concelier family, so the pair fell out with that one two-edge cut; six consumer keys retired together for that reason. Verified: the commit’s diff removes exactly those two ProjectReferences. resolverCitation is null because the commit names no sprint and one must not be invented. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff.
platformconcelier2026-08-18resolved65b18b509ffae623f5b3SPRINT_20260722_026deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by 65b18b509f (2026-08-18 11:04), which removed BOTH of StellaOps.Attestor.ProofChain’s references into src/Concelier – StellaOps.Feedser.Core and StellaOps.Concelier.SourceIntel – carrying the five record families into Evidence/ under a new namespace (copy, not move: both DLLs ship in 72 committed prebuilt bundles). ProofChain was this consumer’s only surviving path into the concelier family, so the pair fell out with that one two-edge cut; six consumer keys retired together for that reason. Verified: the commit’s diff removes exactly those two ProjectReferences. resolverCitation is null because the commit names no sprint and one must not be invented. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff.
platformworkflow2026-08-18resolvedc9c3ee4bcf7ac5915b99SPRINT_20260722_026Severed by deleting WorkflowMigrationModulePlugin, its using, and Platform.Database’s ProjectReference to StellaOps.Workflow.DataStore.PostgreSQL. Verified rather than assumed: after the change a csproj-graph walk resolved Platform.Database to 137 projects with ZERO Workflow projects reachable, so the pin’s foreignProjectCount of 3 described nothing that existed, and Platform.Database built clean without the reference — proof the edge was consumed only by the deleted plugin. Safety measured BEFORE the edit: Platform.Database was the only external referencer of that project, and no reader of wf_host_locks or any workflow table exists outside src/Workflow/. This was retirable without the product decision W3-15 still owes (deploy Workflow later on its own database vs archive it) because platform-web migrating another service’s schema is the X15/DC-26 defect in BOTH branches; src/Workflow/ itself is untouched. Consequence carried forward: platform-web no longer creates the workflow schema on a fresh database, and the ~440 kB already converged on existing databases is central-migration residue that is NOT dropped here (destructive approval, W3-15 M5). Read-across: a pin whose owningSprint is the central-migrator retirement (026) can still be burned early by the OWNING family’s own program — this one was burned by 020, not by 026.
policy-engineattestor2026-08-18resolved0543ff2d4b0543ff2d4bSPRINT_20260722_011Resolved by SPRINT_20260722_007 POL-F3, NOT by 011’s attestation-contract seam. The pin’s target seam was ‘published-package’ on the premise that Policy needed an attestation contract; it never did. policy-engine’s ONLY path into the Attestor family was Policy.Engine -> Scanner.ProofSpine -> Attestor.GraphRoot -> Attestor.Core, and ProofSpine’s only consumer in Policy was Vex/VexProofSpineService.cs, which no host registered and no caller invoked (the type appeared in exactly one file across all of src/). Deleting the dead service retired GraphRoot, Attestor.Core AND ProofChain together. Worth keeping: a pin’s recorded target seam is a HYPOTHESIS about why the edge exists, and this one was wrong for three years of project time - measure what the consumer actually uses before designing the seam.
policy-enginescanner2026-08-18resolved0543ff2d4b0543ff2d4bSPRINT_20260722_017Resolved by SPRINT_20260722_007 POL-F3 with the same deletion that retired policy-engine|attestor: Vex/VexProofSpineService.cs was the sole consumer of StellaOps.Scanner.ProofSpine and was never registered or invoked. No Scanner API seam was needed and the ‘classify ProofSpine as a closed client SDK’ question 017 was holding is moot for Policy. A revived VEX proof-spine feature rides a Scanner-owned seam, never this compile edge.
release-orchestratorconcelier2026-08-18resolved65b18b509ffae623f5b3SPRINT_20260722_003deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by 65b18b509f (2026-08-18 11:04), which removed BOTH of StellaOps.Attestor.ProofChain’s references into src/Concelier – StellaOps.Feedser.Core and StellaOps.Concelier.SourceIntel – carrying the five record families into Evidence/ under a new namespace (copy, not move: both DLLs ship in 72 committed prebuilt bundles). ProofChain was this consumer’s only surviving path into the concelier family, so the pair fell out with that one two-edge cut; six consumer keys retired together for that reason. Verified: the commit’s diff removes exactly those two ProjectReferences. resolverCitation is null because the commit names no sprint and one must not be invented. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff.
release-orchestratorsigner2026-08-18retired-resolver-unrecorded36f13a714cSPRINT_20260722_019
sbomserviceattestor2026-08-18resolvedc7aa9a54e9fae623f5b3SPRINT_20260722_011deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by c7aa9a54e9 (2026-08-18 11:14), which removed SbomService’s StellaOps.Excititor.Persistence ProjectReference – a VEX-delta read that never returned a row. SECOND-ORDER: sbomservice reached the ATTESTOR family only via Excititor.Persistence -> Excititor.Core -> Attestor.StandardPredicates, so cutting an old-plane edge closed an unrelated family pair. Verified: the commit’s diff removes exactly that reference, and this pair’s recorded witness routes through it. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff.
sbomserviceconcelier2026-08-18resolvedc7aa9a54e9fae623f5b3SPRINT_20260722_003deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by c7aa9a54e9 (2026-08-18 11:14), which removed SbomService’s StellaOps.Excititor.Persistence ProjectReference – a VEX-delta read that never returned a row. Verified: the commit’s diff removes exactly that reference, and this pair’s recorded witness routes through it. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff.
sbomserviceexcititor2026-08-18resolvedc7aa9a54e9fae623f5b3SPRINT_20260722_003deregisteredIn fae623f5b3 is a SWEEP ARTIFACT, not the resolver: that commit’s author intended four docs files and a plain git commit swept another lane’s staged register/report work in from the shared index. It severed no edge. Resolved by c7aa9a54e9 (2026-08-18 11:14), which removed SbomService’s StellaOps.Excititor.Persistence ProjectReference – a VEX-delta read that never returned a row. Verified: the commit’s diff removes exactly that reference, and this pair’s recorded witness routes through it. Attribution measured by concelier-tranche (restore one commit’s csproj to pre-tranche state, recompute, see which pairs reappear as UNPINNED); spot-verified here against the resolver commit’s own diff.
platformremediation2026-08-19retired-resolver-unrecordeddb34e0e09cSPRINT_20260722_026
notify-websigner2026-08-20resolved6fbeeb75d5799e18c757SPRINT_20260722_019Source commit 6fbeeb75d5 removed notify-web’s direct ProjectReference to StellaOps.Signer.Infrastructure and the NCS connector’s Signer.Contracts reference, leaving the default-off Signer HTTP API as the custody seam. The prior published-package target was a hypothesis superseded by the owner-directed API decision; boundary commit 799e18c757 only deregistered the already-dead pair.
export-websigner2026-08-21resolved6040e9a86f6040e9a86fSPRINT_20260722_019SGN-7’s source commit extracted the shared DSSE/Sigstore vocabulary from Signer implementation and repointed the surviving consumers to custody-safe seams; export-web’s last Signer implementation path and its pin were removed in that same commit.
export-workersigner2026-08-21resolved6040e9a86f6040e9a86fSPRINT_20260722_019SGN-7’s source commit extracted the shared DSSE/Sigstore vocabulary from Signer implementation and repointed the surviving consumers to custody-safe seams; export-worker’s last Signer implementation path and its pin were removed in that same commit.
platformsigner2026-08-21resolved6040e9a86f6040e9a86fSPRINT_20260722_026SGN-7’s source commit extracted the shared DSSE/Sigstore vocabulary from Signer implementation and repointed the surviving consumers to custody-safe seams; Platform’s last Signer implementation path and its pin were removed in that same commit.
advisory-ai-webevidence-locker2026-08-22resolvedADR-038 / SPRINT_20260730_001 MBI-563ba8f350eSPRINT_20260722_011AAI-9 gate 10 renamed the continuation deployable key to advisoryai-web; the edge did not retire at that point. The rename chain now terminates in MBI-5’s ADR-038 ownership correction: Evidence Pack is AdvisoryAI-owned service-family code, so the canonical successor pair is resolved without a live action.
advisory-ai-workerevidence-locker2026-08-22resolvedADR-038 / SPRINT_20260730_001 MBI-563ba8f350eSPRINT_20260722_011AAI-9 gate 10 renamed the continuation deployable key to advisoryai-worker; the edge did not retire at that point. The rename chain now terminates in MBI-5’s ADR-038 ownership correction: Evidence Pack is AdvisoryAI-owned service-family code, so the canonical successor pair is resolved without a live action.
findings-vulncorrelationscanner2026-08-22resolveda494941d30a494941d30SPRINT_20260722_017The resolver commit moved the surface-manifest wire records byte-identically into the closed Scanner.Surface.Contracts seam and repointed Findings, so Findings no longer compiles Scanner’s filesystem implementation.
integrations-webconcelier2026-08-22resolved1ebea598b149a06dbceaSPRINT_20260722_003The resolver commit moved the unchanged StellaOps.VulnMatch.Core assembly from its misleading shared-tree Concelier classification into the Vulnerabilities producer tree, classified it as a conformance-verified closed artifact-consumer SDK, and repointed Integrations. The matcher algorithm and runtime call site did not change; only the false implementation ownership edge retired. Integrations’ separate raw vuln-schema read remains a runtime blocker and is not claimed here.
policy-engineconcelier2026-08-22resolved1ebea598b149a06dbceaSPRINT_20260722_003The resolver commit moved the unchanged StellaOps.VulnMatch.Core assembly from its misleading shared-tree Concelier classification into the Vulnerabilities producer tree, classified it as a conformance-verified closed artifact-consumer SDK, and repointed Policy. Policy keeps the same matcher assembly and behavior through an allowed owner-controlled seam; its 57-project closure now has zero foreign implementation pairs.
scanner-webrelease-orchestrator2026-08-22resolved7ff376eab37ff376eab3SPRINT_20260722_018The resolver commit moved the unchanged StellaOps.Runtime.Contracts assembly from the ReleaseOrchestrator family tree into the neutral shared-library tree and repointed Scanner. Assembly identity, namespaces, DTOs and wire schema identifiers are unchanged; only the false source ownership edge retired.
scanner-workerreachgraph2026-08-22resolved5383eb4ae55383eb4ae5SPRINT_20260722_023The resolver commit extracted the five reachgraph.min@v1 wire records byte-identically into the closed ReachGraph.Contracts seam and repointed Scanner Worker, preserving its POST /v1/reachgraphs runtime boundary without compiling producer implementation.
airgap-timeairgap-controller2026-08-23resolved7abb1682987abb168298SPRINT_20260722_025The resolver commit deleted a DEAD ProjectReference: AirGap.Importer declares 13 namespaces and airgap-time’s own source names only Auth.Abstractions, Auth.ServerIntegration and Router.AspNet outside its own root. The one consumer that uses Importer types without declaring them (StellaOps.AirGap.Persistence.Tests, via StellaOps.AirGap.Importer.Versioning) keeps compiling through its own AirGap.Controller reference, verified by building all four consumers. airgap-time now measures ZERO violation pairs (closure 24 -> 20) and Attestor leaves its foreign top-level list, which it had entered only through the Importer. Does not pre-empt OK-10’s deletion of the host.
attestor-tileproxyattestor2026-08-23resolved05508e0f9b05508e0f9bSPRINT_20260722_011The resolver commit deleted TWO dead ProjectReferences: the tile proxy’s six source files reference only its own namespaces plus StellaOps.Auth.ServerIntegration.Tenancy, and nothing from StellaOps.Attestor.Core.* or StellaOps.Attestor.TrustRepo*. The pin was classified published-package, i.e. costed as a contract extraction, and needed none: the host compiled producer implementation it never called. attestor-tileproxy now measures ZERO violation pairs (closure 26 -> 19) and its remaining foreign top-levels are all P19-legal, so the key is complete rather than merely reduced.
scanner-webnotify2026-08-23resolvedd6fdeb6168d6fdeb6168SPRINT_20260722_015The resolver commit deleted a DEAD ProjectReference: Scanner.WebService compiled and shipped StellaOps.Notify.Models while no source file in the host referenced it (zero ‘Notify’ tokens in its .cs, and that csproj was the only one in all of src/Scanner naming Notify). The 2026-08-17 measured publish ground truth lists Notify.Models among scanner-web’s 134 compiled projects, so this was a real shipped edge, not a bookkeeping artifact. No behaviour changed; ‘Notify’ also left scanner-web’s foreign top-level directory list (18 -> 17).
airgap-controllerairgap-time2026-08-24resolvedf94a99128330cbaaecaa470a8cbc04390a01b2740d413c8671SPRINT_20260722_025Source commit f94a991283 repointed airgap-controller from the StellaOps.AirGap.Time ASP.NET host to the neutral AirGap.Policy and AirGap.Time.Verification libraries. TimeAnchor remains verifier-owned; the three staleness types moved byte-identically to Policy; the historical host assembly forwards all four public types. Boundary commit 0d413c8671 only deregistered the already-stale pin and regenerated the measured graph. Controller Release publish contains both neutral libraries and no Time-host dependency or DLL; neither commit is evidence of a live host, route, schema, data or configuration change.
platformairgap-time2026-08-24resolvedf94a99128330cbaaecaa470a8cbc04390a01b2740d413c8671SPRINT_20260722_026SECOND-ORDER: Platform reached airgap-time only through Platform.Persistence -> AirGap.Persistence -> AirGap.Controller -> AirGap.Time. Source commit f94a991283 removed the final Controller -> Time-host hop, so the transitive platform|airgap-time pair disappeared while Platform still compiles AirGap.Persistence and AirGap.Controller. Boundary commit 0d413c8671 only deregistered the already-stale pin. This does not complete the central-migrator retirement or evidence any artifact publication, deployment, database move, route swap or live activation.
platformgraph2026-08-24resolved133c6a51f89a5328f14cebacce202dfa7f64f199bb511fbe4bSPRINT_20260722_026Published-main source commit 133c6a51f89a5328f14cebacce202dfa7f64f199 removed GraphMigrationModulePlugin and Platform.Persistence’s direct ProjectReference to StellaOps.Graph.Indexer.Persistence, eliminating platform|graph from the measured source graph. Boundary commit a6d212904b only deregistered the already-stale pin. This is source-staged closure; neither commit is evidence of an artifact build, promotion, recreate, database move, route swap, or live activation.
platformreachgraph2026-08-24resolved133c6a51f89a5328f14cebacce202dfa7f64f199bb511fbe4bSPRINT_20260722_026Published-main source commit 133c6a51f89a5328f14cebacce202dfa7f64f199 removed ReachGraphMigrationModulePlugin and Platform.Persistence’s direct ProjectReference to StellaOps.ReachGraph.Persistence, eliminating platform|reachgraph from the measured source graph. Boundary commit a6d212904b only deregistered the already-stale pin. This is source-staged closure; neither commit is evidence of an artifact build, promotion, recreate, database move, route swap, or live activation.
platformsbomservice2026-08-24resolvedc5b8f2d9febd7dc130865a51aac1e3c97df180924d92b5c64aSPRINT_20260722_026Source commit c5b8f2d9fe removed the orphaned SbomLineageMigrationModulePlugin, Platform-owned wrapper migrations, and Platform.Persistence’s direct ProjectReference to StellaOps.SbomService.Lineage. Boundary commit 4d92b5c64a only deregistered the already-stale platform|sbomservice pin and regenerated the measured graph. Canonical SbomService persistence remains owned and startup-migrated by sbomservice-web; neither commit is evidence of live cleanup, database mutation, deployment, or route activation.
sbomserviceintegrations2026-08-24resolved79c5e6f987c44da0266aSPRINT_20260722_024The resolver commit switched SbomService’s credential wire vocabulary to the exact offline Integrations.RegistryCredentials.Contracts package and its generic registry transport to the neutral StellaOps.Oci.RegistryClient foundation. The producer implementation graph Integrations.Contracts -> Integrations.Core plus Integrations.DockerV2 retired from the consumer closure (3 -> 0); isolated Release publish succeeds with src/Integrations absent.
scanner-webauthority2026-08-24resolved0ed6b0b2f4377b512c49603ee10f572200044be285649f118eSPRINT_20260722_016Source commit 0ed6b0b2f4 replaced Scanner’s borrowed Authority.Persistence OfflineKit audit DTO/interface with an equivalent Scanner-owned internal contract, preserving the registered no-op behavior while removing both Authority implementation projects from scanner-web’s closure. Boundary commit 562cc68b16 only deregistered the already-stale pin and regenerated the measured graph. Neither commit is evidence of durable audit emission, image publication, deployment, database mutation, route change, or live activation.
platformintegrations2026-08-26resolvedd3358c84319b0da835e944d70f360f7df526d9c505437474eaSPRINT_20260722_026Source commit d3358c8431 removed Platform’s Release Orchestrator implementation and persistence closure, which had been the remaining transitive carrier into Integrations.Contracts/Core. Platform’s runtime crypto-control call remains an explicit HTTP owner seam resolved only from STELLAOPS_INTEGRATIONS_URL, so no Integrations source project enters the Platform build. Boundary commit f1cad26a03 only deregistered the stale pin and regenerated the measured graph. Neither commit publishes an image, deploys, mutates a database, or proves live activation.
platformrelease-orchestrator2026-08-26resolvedd3358c84319b0da835e944d70f360f7df526d9c505437474eaSPRINT_20260722_026Source commit d3358c8431 deleted Platform’s Release Orchestrator environment, scripts, EvidenceThread, federation, persistence, and deployment implementation graph. The surviving topology projection crosses a tenant-scoped signed HTTP owner API and a producer-owned zero-reference Topology.Contracts project classified as a closed cross-service client SDK; Platform compiles no Release Orchestrator implementation. Boundary commit f1cad26a03 only deregistered the stale pin and regenerated the measured graph. Neither commit publishes an image, deploys, mutates a database, or proves live activation.
scanner-workerbinaryindex2026-08-26resolved0f3c71e3eab819ecdffb80dbeaa275b14e986fb30f3c71e3eaSPRINT_20260722_014The source commit moved Scanner’s stateless rebuild/determinism engine into Scanner.BuildProvenance, retained repository-backed ground-truth tooling in BinaryIndex, and removed Scanner Worker’s final BinaryIndex implementation reference. The same commit deleted the now-stale register pin; no runtime, database, image, deployment, publication or live-state action is attributed.
advisoryai-webevidence-locker2026-08-27resolvedADR-038 / SPRINT_20260730_001 MBI-54ceb5181b9SPRINT_20260722_011MBI-5 corrected the carrier inversion against accepted ADR-038 and current source: StellaOps.Evidence.Pack is AdvisoryAI analytical service-family code, served and persisted only by AdvisoryAI. Reclassifying its owner resolves the false EvidenceLocker pair; the same bounded correction replaces its namespace-dead AdvisoryAI.Attestation ProjectReference with the neutral Canonical.Json dependency it had carried transitively. No route, database, image, deployment or live state changes.
advisoryai-workerevidence-locker2026-08-27resolvedADR-038 / SPRINT_20260730_001 MBI-54ceb5181b9SPRINT_20260722_011MBI-5 corrected the carrier inversion against accepted ADR-038 and current source: StellaOps.Evidence.Pack is AdvisoryAI analytical service-family code, served and persisted only by AdvisoryAI. Reclassifying its owner resolves the false EvidenceLocker pair; the same bounded correction replaces its namespace-dead AdvisoryAI.Attestation ProjectReference with the neutral Canonical.Json dependency it had carried transitively. No route, database, image, deployment or live state changes.
export-webtimeline2026-08-27resolvedce396303c9cf4d06100334d05673d29a4227ce83ce396303c9SPRINT_20260722_020The Q-5 source commit deleted behavior-dead TimelineEvidenceClient plus the three TimelineIndexer.Core ProjectReferences that carried Export Web, Export Worker and Platform into Timeline implementation. Timeline’s owner evidence endpoint and the separate HTTP-audit/event-publication paths remain; no live action is attributed.
export-workertimeline2026-08-27resolvedce396303c9cf4d06100334d05673d29a4227ce83ce396303c9SPRINT_20260722_020The Q-5 source commit deleted behavior-dead TimelineEvidenceClient plus the three TimelineIndexer.Core ProjectReferences that carried Export Web, Export Worker and Platform into Timeline implementation. Timeline’s owner evidence endpoint and the separate HTTP-audit/event-publication paths remain; no live action is attributed.
platformtimeline2026-08-27resolvedce396303c9cf4d06100334d05673d29a4227ce83ce396303c9SPRINT_20260722_026SECOND-ORDER: Platform reached TimelineIndexer.Core only through Platform.Persistence -> ExportCenter.Infrastructure. The Q-5 source commit removed that dormant ExportCenter reference, so platform|timeline disappeared without a Platform source edit. Platform’s remaining central-migrator work is unaffected; no live action is attributed.
scanner-webairgap-controller2026-08-27resolved639095de2b639095de2bSPRINT_20260722_025Q-25 moved the canonical import/status/manifest/validate transport and verified-carrier custody into OfflineKit, deleted Scanner’s duplicate OfflineKit API and its StellaOps.AirGap.Importer ProjectReference, and repointed CLI, Console, and gateway callers to /api/offlinekit/v1. The source commit therefore removes the scanner-web -> airgap-controller implementation pair while leaving content activation and the live Scanner-data disposition to OK-7/OK-10.
agent-coreattestor2026-08-28retired-resolver-unrecorded742c9c60e1SPRINT_20260722_011
findings-ledger-webfindings2026-08-28retired-resolver-unrecordedd75e91e1a1SPRINT_20260722_010
findings-security-webfindings2026-08-28retired-resolver-unrecordedd75e91e1a1SPRINT_20260722_010
release-orchestratorattestor2026-08-28retired-resolver-unrecorded742c9c60e1SPRINT_20260722_011
scanner-webattestor2026-08-28retired-resolver-unrecorded742c9c60e1SPRINT_20260722_011
scanner-webconcelier2026-08-28retired-resolver-unrecordedd75e91e1a1SPRINT_20260722_003
scanner-webintegrations2026-08-28retired-resolver-unrecordeda95191ec48SPRINT_20260722_024
scanner-webpolicy2026-08-28retired-resolver-unrecordedd75e91e1a1SPRINT_20260722_017
scanner-workerattestor2026-08-28retired-resolver-unrecorded742c9c60e1SPRINT_20260722_011
scanner-workerconcelier2026-08-28retired-resolver-unrecordedd75e91e1a1SPRINT_20260722_003
scanner-workerintegrations2026-08-28retired-resolver-unrecordeda95191ec48SPRINT_20260722_024
binaryindex-webattestor2026-09-04retired-resolver-unrecordedba3f7e3503SPRINT_20260722_011
concelierattestor2026-09-04retired-resolver-unrecordedba3f7e3503SPRINT_20260722_011
evidence-locker-webattestor2026-09-04retired-resolver-unrecordedba3f7e3503SPRINT_20260722_011
excititor-webattestor2026-09-04retired-resolver-unrecordedba3f7e3503SPRINT_20260722_011
excititor-workerattestor2026-09-04retired-resolver-unrecordedba3f7e3503SPRINT_20260722_011
export-webattestor2026-09-04retired-resolver-unrecordedba3f7e3503SPRINT_20260722_011
export-webevidence2026-09-04retired-resolver-unrecordede7aa21267bSPRINT_20260722_011
export-workerattestor2026-09-04retired-resolver-unrecordedba3f7e3503SPRINT_20260722_011
export-workerevidence2026-09-04retired-resolver-unrecordede7aa21267bSPRINT_20260722_011
notifier-workernotify2026-09-04retired-resolver-unrecorded60b2c77674SPRINT_20260722_015
platformattestor2026-09-04retired-resolver-unrecordedba3f7e3503SPRINT_20260722_026
platformevidence2026-09-05retired-resolver-unrecorded85290801d1SPRINT_20260722_011
platformauthority2026-09-08retired-resolver-unrecorded86056143f2SPRINT_20260722_026
platformbinaryindex2026-09-08retired-resolver-unrecorded86056143f2SPRINT_20260722_026
platformpolicy2026-09-08retired-resolver-unrecorded86056143f2SPRINT_20260722_026
platformissuer-directory2026-09-09resolvedb37466ce623b8e330d9f32be5bbe60f6f566e48eb37466ce62SPRINT_20260722_026CM-2 removed the effective IssuerDirectory central migration plugin and its only Platform.Persistence implementation reference after the completed AUTH-9 fold. Authority migration 024 owns the separate issuer schema through the existing Authority ledger; the folded runtime registers no second migration host. The Platform graph shrank 82 to 80 projects, and its built deps.json has no IssuerDirectory or Authority.Persistence library. Source-only retirement; AUTH-10 retains predecessor-source cleanup and any old-schema drop.
platformnotify2026-09-09resolvedd0d97b313034283f06e93953665e3ab3755b774bd0d97b3130SPRINT_20260722_026CM-2 removed NotifyMigrationModulePlugin and its sole Platform.Persistence -> Notify.Persistence reference after the Notify cutover and predecessor retirement. The host build exposed one missing NIS2 payload contract, moved unchanged with its two routing records into the existing closed Notify.Contracts project. Platform’s measured graph is 82 projects with no Notify implementation; the host deps.json contains only Notify.Contracts and Notify.EventClient from that family. No live action is attributed.
platformairgap-controller2026-09-10resolved794a22106541fbf72012e11fb44be3ce6c1fdcc7794a221065SPRINT_20260722_026OK-5 source retirement. The running Controller and airgap schema still require the approved retirement window.
authorityissuer-directory2026-09-11retired-resolver-unrecorded0f2efb7692SPRINT_20260722_016
binaryindex-webconcelier2026-09-11retired-resolver-unrecorded0146d5bbe4SPRINT_20260722_003
binaryindex-webevidence2026-09-11retired-resolver-unrecorded0146d5bbe4SPRINT_20260722_011
binaryindex-webexcititor2026-09-11retired-resolver-unrecorded0146d5bbe4SPRINT_20260722_003
concelierevidence2026-09-11retired-resolver-unrecorded9b648b5534SPRINT_20260722_011
concelierexcititor2026-09-11retired-resolver-unrecorded9b648b5534SPRINT_20260722_003
excititor-webconcelier2026-09-11retired-resolver-unrecorded0146d5bbe4SPRINT_20260722_003
excititor-webevidence2026-09-11retired-resolver-unrecorded0146d5bbe4SPRINT_20260722_011
excititor-workerconcelier2026-09-11retired-resolver-unrecorded0146d5bbe4SPRINT_20260722_003
excititor-workerevidence2026-09-11retired-resolver-unrecorded0146d5bbe4SPRINT_20260722_011
notify-webfindings2026-09-11resolveddocs-archive/implplan/SPRINT_20260722_015_Notify_service_consolidation_program.md#ntf-9-live-nis2-handoff-cutover2492ff29e0SPRINT_20260722_010NTF-9 removes the in-process NIS2 emitter, adapter and foreign ProjectReference after live producer/consumer replay and independent tenant checkpoint proof.
export-webfindings2026-09-12retired-resolver-unrecorded8888132e65SPRINT_20260722_010
export-webnotify2026-09-12retired-resolver-unrecorded8888132e65SPRINT_20260722_015
export-webscanner2026-09-12retired-resolver-unrecorded8888132e65SPRINT_20260722_017
export-workerfindings2026-09-12retired-resolver-unrecorded8888132e65SPRINT_20260722_010
export-workernotify2026-09-12retired-resolver-unrecorded8888132e65SPRINT_20260722_015
export-workerscanner2026-09-12retired-resolver-unrecorded8888132e65SPRINT_20260722_017
platformexport-center2026-09-12retired-resolver-unrecorded12d3cdfa77SPRINT_20260722_026
platformpacksregistry2026-09-12retired-resolver-unrecorded9865d0b4b5SPRINT_20260722_026
platformscanner2026-09-12retired-resolver-unrecorded12d3cdfa77SPRINT_20260722_026
platformscheduler2026-09-12retired-resolver-unrecorded9865d0b4b5SPRINT_20260722_026
scheduler-webnotify2026-09-12retired-resolver-unrecorded9865d0b4b5SPRINT_20260722_015
scheduler-webscanner2026-09-12retired-resolver-unrecordedfd91338c02SPRINT_20260722_017
platformevidence-locker2026-09-14retired-resolver-unrecordede58630dc3cSPRINT_20260722_026
agent-corescanner2026-09-15retired-resolver-unrecordedc84b4af142SPRINT_20260730_001
jobengine-webscanner2026-09-15retired-resolver-unrecorded44c06e7306SPRINT_20260730_001
offlinekit-webfindings2026-09-15resolvedc0b6a793efc0b6a793efSPRINT_20260730_001
offlinekit-webscanner2026-09-15resolvedc4756e5905c4756e5905SPRINT_20260730_001
offlinekit-workerfindings2026-09-15resolvedc0b6a793efc0b6a793efSPRINT_20260730_001
offlinekit-workerscanner2026-09-15resolvedc4756e5905c4756e5905SPRINT_20260730_001
release-orchestratornotify2026-09-15resolvedcd0ca2a124cd0ca2a124SPRINT_20260722_015
release-orchestratorscanner2026-09-15retired-resolver-unrecordedb2232ab28fSPRINT_20260730_001
release-orchestratorintegrations2026-09-16retired-resolver-unrecorded734b7ba141SPRINT_20260730_001

6. How to record a retirement

When your lane severs an edge:

  1. Delete the pin from legacy-edge-register.json in the same commit as the source change.

  2. Regenerate: pwsh tools/scripts/build-boundary/generate-build-boundary-report.ps1. The pair moves out of §3 by itself; nothing here is edited by hand.

  3. Record the resolver so the row does not land as retired-resolver-unrecorded:

    pwsh tools/scripts/build-boundary/generate-legacy-edge-dispositions.ps1 -UpdateLedger
    

    then set status: "resolved" and resolverCommit (the commit that severed the edge, which is not necessarily the one that deleted the pin) plus a one-line note on that entry in legacy-edge-resolvers.json, and regenerate again. -UpdateLedger preserves those fields on every later run.