CRA Publication Preflight
This page is for operators preparing Stella’s own product-security disclosures under the EU Cyber Resilience Act. CRA publication preflight separates local evidence readiness (can the pack produce a deterministic artifact?) from live public publication readiness (are the public mailbox, intake key, advisory route, and lifecycle records verified?). The two are reported as independent lines so a blocked public preflight never silently blocks local evidence work.
Claim boundary: manufacturer-self for Stella product-security publication.
Publication preflight is a gate, not an exporter: it checks public-facing inputs. The deterministic evidence bundle itself is produced by the CRA technical file surface, and both belong to the CRA Assurance Packs.
Source Docs
- Assurance Setup Prerequisites v1
- Stella Product CSAF Advisory Contract v1
- Product CSAF Notify channel
- EU compliance decisions log
- CRA gap-closure research
Readiness Lines
| Readiness line | Meaning |
|---|---|
| Local signed export readiness | The pack can produce a deterministic local evidence or advisory artifact. |
| Live public publication readiness | Public metadata, routes, mailbox, key lineage, and support lifecycle records are verified for publication. |
These lines must be shown separately in setup, CLI, and Web surfaces. A blocked public publication preflight must not block CRA technical-file generation.
Required Public Inputs
The preflight should verify at least:
- reachable product-security contact mailbox;
- published public encryption-capable intake key or subkey;
- advisory feed route and schema pin;
- support lifecycle metadata for the relevant release train;
- generic dedicated rotation and escalation contacts;
- audit record tying the checks to the release or publication action.
Private keys, mailbox credentials, and provider secrets must never appear in setup responses, logs, or CLI output.
Setup Wizard Handoff
The optional setup assurance step shows CRA Product Security readiness as two separate lines:
- local signed export readiness for technical-file/advisory artifacts;
- live public publication readiness for Stella-as-manufacturer product-security publication.
The live-publication line must mention mailbox delivery/access, a non-expired encryption-capable intake key certified by website lineage, product-security rotation roles, and support lifecycle/publication metadata. It must not tell customer tenants to configure Stella’s manufacturer mailbox for their own local evidence packs.
Change Log
| Date (UTC) | Update |
|---|---|
| 2026-06-16 | Reconciled to verified code: ExportCenter and Notify report local signed-export readiness separately from live-publication readiness (signedExportReady/livePublicationReady, operatorHandoffReady/autoSubmitReady), so a blocked public preflight never blocks local evidence. The remaining live-publication blockers are operational/process (mailbox delivery+access, non-expired intake key, rotation, support-lifecycle metadata) — tracked as G4 in cra-gap-closure-plan.md and CRA-Q1 in decisions-log.md, not a code gap. |
