StellaOps Contracts

Formal contract specifications for the cross-module interfaces of the StellaOps release control plane. Each contract pins the data models, APIs, schemas, and integration points that modules depend on, so teams can build against a stable shape rather than another module’s current code.

Audience: implementers and reviewers who consume or produce a cross-module interface, and planners who need to know which contracts unblock which sprint tasks.

The repository under src/ is the source of truth. Contracts are reconciled against code in passes but can lag; where a contract and the code disagree, the code wins. Many documents below carry an inline reconciliation note pointing at the verifying source files.

Purpose

Contracts serve as the authoritative reference for:

Contract Index

ContractIDUnblocksStatus
Advisory KeyCONTRACT-ADVISORY-KEY-0016+ tasksPublished
Risk ScoringCONTRACT-RISK-SCORING-0025+ tasksPublished
Mirror BundleCONTRACT-MIRROR-BUNDLE-0038+ tasksPublished
Sealed ModeCONTRACT-SEALED-MODE-0044+ tasksPublished
VEX LensCONTRACT-VEX-LENS-0052+ tasksPublished
Verification PolicyCONTRACT-VERIFICATION-POLICY-0064+ tasksPublished
Policy StudioCONTRACT-POLICY-STUDIO-0073+ tasksPublished
Authority Effective WriteCONTRACT-AUTHORITY-EFFECTIVE-WRITE-0082+ tasksPublished
Export BundleCONTRACT-EXPORT-BUNDLE-0091+ tasksPublished
Crypto Provider RegistryCONTRACT-CRYPTO-PROVIDER-REGISTRY-0101+ tasksPublished
Findings Ledger RLSCONTRACT-FINDINGS-LEDGER-RLS-0112 tasksPublished
API Governance BaselineCONTRACT-API-GOVERNANCE-BASELINE-01210+ tasksPublished
Scanner PHP AnalyzerCONTRACT-SCANNER-PHP-ANALYZER-0131 taskPublished
Scanner SurfaceCONTRACT-SCANNER-SURFACE-0141 taskPublished
RichGraph v1CONTRACT-RICHGRAPH-V1-01540+ tasksPublished
Asset Registry v1CONTRACT-ASSET-REGISTRY-V1-016NIS2 N4, DORA RoI/TLPTPublished
Asset Inventory Sync v1CONTRACT-ASSET-INVENTORY-SYNC-V1-071NIS2 N4 offline/federated syncPublished
NIS2 Control Register v1CONTRACT-NIS2-CONTROL-REGISTER-V1-017NIS2 N1Published
NIS2 SoA v1CONTRACT-NIS2-SOA-V1-018NIS2 N1/N3Published
NIS2 KPI Telemetry Schema v1CONTRACT-NIS2-KPI-TELEMETRY-V1-019NIS2 N3Published
NIS2 Effectiveness Report v1CONTRACT-NIS2-EFFECTIVENESS-REPORT-V1-062NIS2 N3 monthly exportPublished
DORA Incident Classification v1CONTRACT-DORA-INCIDENT-CLASSIFICATION-V1-020DORA D1Published
DORA Register of Information v1CONTRACT-DORA-ROI-V1-021DORA D2Draft
DORA Info Sharing Event v1CONTRACT-DORA-INFO-SHARING-EVENT-V1-022DORA D4Draft
TLPT Scope v1CONTRACT-TLPT-SCOPE-V1-023DORA D3Draft
TLPT Baseline v1CONTRACT-TLPT-BASELINE-V1-024DORA D3Draft
DORA Major Incident Report v1CONTRACT-DORA-MAJOR-INCIDENT-REPORT-V1-025DORA D1Draft
ENISA Incident Reporting v1CONTRACT-ENISA-INCIDENT-REPORTING-V1-026CRA B1Draft
CRA Technical File v1CONTRACT-CRA-TECH-FILE-V1-027CRA B2Draft
NIS2 Incident Report Envelope v1CONTRACT-NIS2-INCIDENT-REPORT-ENVELOPE-V1-028NIS2 N2Draft
CRA Conformity Dossier v1CONTRACT-CRA-CONFORMITY-DOSSIER-V1-029CRA B3Draft
Product Update Manifest v1CONTRACT-PRODUCT-UPDATE-MANIFEST-V1-030CRA A2Published
TLPT Evidence Pack v1CONTRACT-TLPT-EVIDENCE-PACK-V1-031DORA D3Draft
Standards Mapping v1CONTRACT-STANDARDS-MAPPING-V1-032NIS2 N5, CRA standards evidenceDraft
EU Runtime API Contracts v1CONTRACT-EU-RUNTIME-API-V1-033EU live API unblockersDraft
EU Signing Payload Registry v1CONTRACT-EU-SIGNING-PAYLOAD-REGISTRY-V1-203EU signing/verifier consumersPublished
Stella Product CSAF Advisory v1CONTRACT-STELLA-PRODUCT-CSAF-ADVISORY-V1-003CRA A1 product advisory feedPublished
OpenPGP Encryption Provider v1CONTRACT-OPENPGP-ENCRYPTION-PROVIDER-V1-051NIS2 N2 PGP-email fallbackPublished

Additional Contracts & Decisions

The following contract and decision documents also live in this directory. The status column reflects each document’s own status header; indicates the document declares no explicit status field.

ContractIDStatus
Assurance Pack v1CONTRACT-ASSURANCE-PACK-V1-001Draft
Assurance Control Register v1CONTRACT-ASSURANCE-CONTROL-REGISTER-V1-002Draft
Assurance Evidence Export v1CONTRACT-ASSURANCE-EVIDENCE-EXPORT-V1-003Draft
Assurance Reporting Timeline v1CONTRACT-ASSURANCE-REPORTING-TIMELINE-V1-004Draft
Assurance Setup Prerequisites v1CONTRACT-ASSURANCE-SETUP-PREREQUISITES-V1-005Draft
Stella Supplier Evidence Profile v1CONTRACT-STELLA-SUPPLIER-EVIDENCE-V1-001Draft
Stella Product Security Metadata v1Active
Product CVD Policy v1Active
Product Lifecycle v1Active
Operator Compliance Config v1Active (initial Authority implementation)
Tenant Compliance Profile v1Active (initial sprint implementation)
EU Regulatory Artifact Ledger v1Active (initial implementation)
EU Regulatory Audit Events v1Active (initial implementation)
Artifact Canonical Record v1Draft
Canonical SBOM Identifier v1Draft
SBOM Scope Property Registry v1CONTRACT-SBOM-SCOPE-PROPERTIES-V1Published
Triage Auto-Suppress Predicate v1Draft
Vuln Surface v1
Function Map v1
Remediation PR Predicate v1
Execution Evidence Predicate v1Active
Beacon Attestation Predicate v1Active
Witness Schema v1Draft
Federated Consent v1
Federated Telemetry v1
Change-Trace JSON SchemaDraft
Change-Trace Trust-Delta FormulaDraft
Build-ID & Code-ID PropagationCONTRACT-BUILDID-PROPAGATION-401Published
Init-Section Synthetic RootsCONTRACT-INIT-ROOTS-401Published
Native Toolchain DecisionDECISION-NATIVE-TOOLCHAIN-401Published
CAS InfrastructureApproved
Authority Crypto ProviderApproved
Authority Routing DecisionDECISION-AUTH-001Default-approved
Web Gateway Tenant RBACApproved
Rate Limit DesignApproved
Sealed Install EnforcementApproved
Redaction Defaults DecisionDECISION-SECURITY-001Default-approved
Dossier Sequencing DecisionDECISION-DOCS-001Default-approved

Contract Categories

Core Data Models

Air-Gap / Offline

Security / Attestation

Policy Management

Telemetry

Incident Reporting

Register Reporting

TLPT

Export

Tenancy / Database

SDK & API Governance

Scanner

Reachability / Evidence

API Documentation

Module Architecture

JSON Schemas

The Attestor schema paths below are relative to the monorepo root (the src/ tree); they resolve in a full source checkout but not in a docs-only mirror.

The Mirror Bundle has no standalone JSON Schema; its canonical shape is defined inline in Mirror Bundle.

Contract Lifecycle

  1. Draft - Contract under development
  2. Published - Contract is stable and ready for implementation
  3. Deprecated - Contract is being phased out
  4. Retired - Contract is no longer valid

Contributing

When updating contracts:

  1. Increment version number
  2. Update Last Updated date
  3. Document breaking changes
  4. Update Unblocks section if tasks change
  5. Add cross-references to related contracts

Sprint Integration

Contracts unblock BLOCKED tasks in sprint files. When a contract is published:

  1. Update the sprint file task status from BLOCKED to TODO
  2. Add note: Unblocked by CONTRACT-xxx (docs/contracts/xxx.md)
  3. Remove the blocked reason