StellaOps Contracts
Formal contract specifications for the cross-module interfaces of the StellaOps release control plane. Each contract pins the data models, APIs, schemas, and integration points that modules depend on, so teams can build against a stable shape rather than another module’s current code.
Audience: implementers and reviewers who consume or produce a cross-module interface, and planners who need to know which contracts unblock which sprint tasks.
The repository under
src/is the source of truth. Contracts are reconciled against code in passes but can lag; where a contract and the code disagree, the code wins. Many documents below carry an inline reconciliation note pointing at the verifying source files.
Purpose
Contracts serve as the authoritative reference for:
- Data model definitions (request/response shapes)
- API endpoint specifications
- Integration requirements between modules
- Dependency documentation for sprint planning
Contract Index
| Contract | ID | Unblocks | Status |
|---|---|---|---|
| Advisory Key | CONTRACT-ADVISORY-KEY-001 | 6+ tasks | Published |
| Risk Scoring | CONTRACT-RISK-SCORING-002 | 5+ tasks | Published |
| Mirror Bundle | CONTRACT-MIRROR-BUNDLE-003 | 8+ tasks | Published |
| Sealed Mode | CONTRACT-SEALED-MODE-004 | 4+ tasks | Published |
| VEX Lens | CONTRACT-VEX-LENS-005 | 2+ tasks | Published |
| Verification Policy | CONTRACT-VERIFICATION-POLICY-006 | 4+ tasks | Published |
| Policy Studio | CONTRACT-POLICY-STUDIO-007 | 3+ tasks | Published |
| Authority Effective Write | CONTRACT-AUTHORITY-EFFECTIVE-WRITE-008 | 2+ tasks | Published |
| Export Bundle | CONTRACT-EXPORT-BUNDLE-009 | 1+ tasks | Published |
| Crypto Provider Registry | CONTRACT-CRYPTO-PROVIDER-REGISTRY-010 | 1+ tasks | Published |
| Findings Ledger RLS | CONTRACT-FINDINGS-LEDGER-RLS-011 | 2 tasks | Published |
| API Governance Baseline | CONTRACT-API-GOVERNANCE-BASELINE-012 | 10+ tasks | Published |
| Scanner PHP Analyzer | CONTRACT-SCANNER-PHP-ANALYZER-013 | 1 task | Published |
| Scanner Surface | CONTRACT-SCANNER-SURFACE-014 | 1 task | Published |
| RichGraph v1 | CONTRACT-RICHGRAPH-V1-015 | 40+ tasks | Published |
| Asset Registry v1 | CONTRACT-ASSET-REGISTRY-V1-016 | NIS2 N4, DORA RoI/TLPT | Published |
| Asset Inventory Sync v1 | CONTRACT-ASSET-INVENTORY-SYNC-V1-071 | NIS2 N4 offline/federated sync | Published |
| NIS2 Control Register v1 | CONTRACT-NIS2-CONTROL-REGISTER-V1-017 | NIS2 N1 | Published |
| NIS2 SoA v1 | CONTRACT-NIS2-SOA-V1-018 | NIS2 N1/N3 | Published |
| NIS2 KPI Telemetry Schema v1 | CONTRACT-NIS2-KPI-TELEMETRY-V1-019 | NIS2 N3 | Published |
| NIS2 Effectiveness Report v1 | CONTRACT-NIS2-EFFECTIVENESS-REPORT-V1-062 | NIS2 N3 monthly export | Published |
| DORA Incident Classification v1 | CONTRACT-DORA-INCIDENT-CLASSIFICATION-V1-020 | DORA D1 | Published |
| DORA Register of Information v1 | CONTRACT-DORA-ROI-V1-021 | DORA D2 | Draft |
| DORA Info Sharing Event v1 | CONTRACT-DORA-INFO-SHARING-EVENT-V1-022 | DORA D4 | Draft |
| TLPT Scope v1 | CONTRACT-TLPT-SCOPE-V1-023 | DORA D3 | Draft |
| TLPT Baseline v1 | CONTRACT-TLPT-BASELINE-V1-024 | DORA D3 | Draft |
| DORA Major Incident Report v1 | CONTRACT-DORA-MAJOR-INCIDENT-REPORT-V1-025 | DORA D1 | Draft |
| ENISA Incident Reporting v1 | CONTRACT-ENISA-INCIDENT-REPORTING-V1-026 | CRA B1 | Draft |
| CRA Technical File v1 | CONTRACT-CRA-TECH-FILE-V1-027 | CRA B2 | Draft |
| NIS2 Incident Report Envelope v1 | CONTRACT-NIS2-INCIDENT-REPORT-ENVELOPE-V1-028 | NIS2 N2 | Draft |
| CRA Conformity Dossier v1 | CONTRACT-CRA-CONFORMITY-DOSSIER-V1-029 | CRA B3 | Draft |
| Product Update Manifest v1 | CONTRACT-PRODUCT-UPDATE-MANIFEST-V1-030 | CRA A2 | Published |
| TLPT Evidence Pack v1 | CONTRACT-TLPT-EVIDENCE-PACK-V1-031 | DORA D3 | Draft |
| Standards Mapping v1 | CONTRACT-STANDARDS-MAPPING-V1-032 | NIS2 N5, CRA standards evidence | Draft |
| EU Runtime API Contracts v1 | CONTRACT-EU-RUNTIME-API-V1-033 | EU live API unblockers | Draft |
| EU Signing Payload Registry v1 | CONTRACT-EU-SIGNING-PAYLOAD-REGISTRY-V1-203 | EU signing/verifier consumers | Published |
| Stella Product CSAF Advisory v1 | CONTRACT-STELLA-PRODUCT-CSAF-ADVISORY-V1-003 | CRA A1 product advisory feed | Published |
| OpenPGP Encryption Provider v1 | CONTRACT-OPENPGP-ENCRYPTION-PROVIDER-V1-051 | NIS2 N2 PGP-email fallback | Published |
Additional Contracts & Decisions
The following contract and decision documents also live in this directory. The status column reflects each document’s own status header; — indicates the document declares no explicit status field.
Contract Categories
Core Data Models
- Advisory Key - Vulnerability ID canonicalization
- VEX Lens - VEX observation correlation
- Risk Scoring - Finding prioritization
Air-Gap / Offline
- Mirror Bundle - Bundle format for offline transport
- Sealed Mode - Sealed environment operation
- Asset Inventory Sync v1 - Deterministic offline/federated Asset Registry event delta bundle
Security / Attestation
- Verification Policy - Attestation verification rules
- Crypto Provider Registry - Pluggable crypto
- Product Update Manifest v1 - Signed Stella release image, SBOM, support, and advisory-fix manifest
- EU Signing Payload Registry v1 - EU compliance DSSE payload media types, schema pins, signer profiles, and offline verifier behavior
- Stella Product CSAF Advisory v1 - Stella-as-manufacturer CSAF 2.0 advisory source model, canonical export, and offline DSSE verification contract
- OpenPGP Encryption Provider v1 - OpenPGP public-key email encryption provider boundary and ciphertext hash evidence contract
Policy Management
- Policy Studio - Policy editing and compilation
- Authority Effective Write - Policy attachment
- NIS2 Control Register v1 - NIS2 Article 21 control register schema
- NIS2 SoA v1 - Statement of Applicability export shape
- NIS2 Effectiveness Report v1 - Monthly 13-area effectiveness report bundle and offline verifier contract
Telemetry
- NIS2 KPI Telemetry Schema v1 - Thirteen-area NIS2 KPI metric naming, labels, and thresholds
Incident Reporting
- DORA Incident Classification v1 - Seven-criteria DORA ICT incident classification facts
- DORA Major Incident Report v1 - Deterministic DORA major-incident XBRL/iXBRL report envelope
- DORA Info Sharing Event v1 - STIX 2.1-aligned DORA Article 45 sharing batch
- ENISA Incident Reporting v1 - Deterministic CRA Article 14 ENISA SRP handoff envelope
- NIS2 Incident Report Envelope v1 - Deterministic NIS2 Article 23 CSIRT/NCA handoff envelope
Register Reporting
- DORA Register of Information v1 - Deterministic local B.01-B.14 RoI projection and bundle index contract
TLPT
- TLPT Scope v1 - Deterministic white-team scoping document for DORA TLPT preparation
- TLPT Baseline v1 - Replay manifest for freezing TLPT feed, policy, dependency graph, and asset state
- TLPT Evidence Pack v1 - Long-lived signed EvidenceLocker capsule for DORA TLPT evidence packs
Export
- Export Bundle - Scheduled export jobs
- CRA Technical File v1 - Deterministic CRA Annex VII technical documentation bundle index with DSSE default, optional cadenced envelope, and regulatory audit ledger recording
- CRA Conformity Dossier v1 - Deterministic CRA conformity-assessment dossier overlays for Module A, B+C, and H
- Standards Mapping v1 - Deterministic ISO/IEC/ETSI/JRC standards mapping bundle
- NIS2 Effectiveness Report v1 - Deterministic signed monthly NIS2 effectiveness JSON bundle
Tenancy / Database
- Findings Ledger RLS - Row-Level Security and partitioning
SDK & API Governance
- API Governance Baseline - OpenAPI freeze and SDK generation
- EU Runtime API Contracts v1 - Graph asset registry runtime APIs and source-service client boundaries
Scanner
- Scanner PHP Analyzer - PHP language analyzer bootstrap
- Scanner Surface - Surface analysis framework
- SBOM Scope Property Registry v1 -
stellaops.scope.*declared→deployed component properties
Reachability / Evidence
- RichGraph v1 - Function-level reachability graph schema
Related Resources
API Documentation
Module Architecture
JSON Schemas
The Attestor schema paths below are relative to the monorepo root (the src/ tree); they resolve in a full source checkout but not in a docs-only mirror.
- Verification Policy Schema
- Risk Profile Schema
The Mirror Bundle has no standalone JSON Schema; its canonical shape is defined inline in Mirror Bundle.
Contract Lifecycle
- Draft - Contract under development
- Published - Contract is stable and ready for implementation
- Deprecated - Contract is being phased out
- Retired - Contract is no longer valid
Contributing
When updating contracts:
- Increment version number
- Update
Last Updateddate - Document breaking changes
- Update
Unblockssection if tasks change - Add cross-references to related contracts
Sprint Integration
Contracts unblock BLOCKED tasks in sprint files. When a contract is published:
- Update the sprint file task status from
BLOCKEDtoTODO - Add note:
Unblocked by CONTRACT-xxx (docs/contracts/xxx.md) - Remove the blocked reason
