Third-Party Dependencies
Document Version: 1.1.5 Last Updated: 2026-05-31 SPDX License Identifier: BUSL-1.1 (StellaOps)
This document provides a comprehensive inventory of all third-party dependencies used in StellaOps, their licenses, and BUSL-1.1 compatibility status.
Summary
| Category | Count | License Types |
|---|---|---|
| Vendored/Bundled | 6 | MIT, BSD-3-Clause, LicenseRef-OASIS-Specification-Notice, Commercial |
| NuGet (Runtime) | ~100+ | MIT, Apache-2.0, BSD-3-Clause, PostgreSQL |
| NuGet (Dev/Test) | ~50+ | MIT, Apache-2.0 |
| npm (Runtime) | ~15 | MIT, Apache-2.0, ISC, 0BSD |
| npm (Dev) | ~30+ | MIT, Apache-2.0 |
| Infrastructure | 10 | PostgreSQL, MPL-2.0 (RabbitMQ; OpenBao is dev/test-only, not distributed), BSD-2-Clause, BSD-3-Clause, Apache-2.0, MIT, GPLv3 (separate process), AGPL-3.0 (separate service, mere aggregation) |
Canonical License Declarations
- Project license text:
LICENSE - Third-party attributions:
NOTICE.md - Full dependency inventory:
docs/legal/THIRD-PARTY-DEPENDENCIES.md - Vendored license texts:
third-party-licenses/
StellaOps is licensed under BUSL-1.1 with an Additional Use Grant (see LICENSE). The Change License is Apache License 2.0 effective on the Change Date stated in LICENSE.
License Compatibility with BUSL-1.1
| License | SPDX | Compatible | Notes |
|---|---|---|---|
| MIT | MIT | Yes | Permissive, no restrictions |
| Apache-2.0 | Apache-2.0 | Yes | Permissive, patent grant |
| BSD-2-Clause | BSD-2-Clause | Yes | Permissive |
| BSD-3-Clause | BSD-3-Clause | Yes | Permissive |
| ISC | ISC | Yes | Functionally equivalent to MIT |
| 0BSD | 0BSD | Yes | Public domain equivalent |
| PostgreSQL | PostgreSQL | Yes | Permissive, similar to MIT/BSD |
| MPL-2.0 | MPL-2.0 | Yes | File-level copyleft; keep MPL files isolated |
| LGPL-2.1+ | LGPL-2.1-or-later | Yes | Dynamic linking only; relinking rights preserved |
| OASIS specification notice | LicenseRef-OASIS-Specification-Notice | Yes | Specification/schema asset notice preserved; no modified OASIS deliverables distributed |
| Commercial | LicenseRef-* | N/A | Customer-provided, not distributed |
1. Vendored/Bundled Components
Components included directly in the StellaOps source tree.
| Component | Version | License | SPDX | Location | Notes |
|---|---|---|---|---|---|
| tree-sitter | - | MIT | MIT | Native bindings | Parser generator for reachability analysis |
| tree-sitter-ruby | - | MIT | MIT | Native bindings | Ruby language parser |
| AlexMAS.GostCryptography | fork | MIT | MIT | src/__Libraries/StellaOps.Cryptography.Plugin.CryptoPro/third_party/ | GOST R 34.10/34.11 implementation |
| OASIS CSAF 2.0 JSON Schema Set | 2.0 | OASIS specification notice | LicenseRef-OASIS-Specification-Notice | docs/contracts/schemas/eu/csaf/2.0/ | Local official CSAF 2.0 validation for Stella product advisories |
| FIRST CVSS JSON Schemas | v2.0/v3.0/v3.1 | BSD-3-Clause | BSD-3-Clause | docs/contracts/schemas/eu/csaf/2.0/transitive/first-cvss/ | Transitive CVSS scoring schema refs for CSAF validation |
| golang.org/x/tools | v0.16.0 | BSD-3-Clause | BSD-3-Clause | tools/stella-callgraph-go/vendor/golang.org/x/tools/ | go/ssa + go/callgraph/{cha,rta} + go/packages for the Go SSA call-graph extractor (stella-callgraph-go); linked into the binary only, build/runtime not shipped at /app |
| golang.org/x/mod | v0.14.0 | BSD-3-Clause | BSD-3-Clause | tools/stella-callgraph-go/vendor/golang.org/x/mod/ | Indirect dependency of golang.org/x/tools (semver parsing) |
Go toolchain (golang:1.21-bookworm) | 1.21 | BSD-3-Clause | BSD-3-Clause | Build-stage SDK only (multi-stage Dockerfile) | Compiles the static stella-callgraph-go binary; never shipped in a runtime image |
| CryptoPro CSP | N/A | Commercial | LicenseRef-CryptoPro | Integration only | Not distributed; customer-provided |
License Files
Full license texts are available in /third-party-licenses/:
tree-sitter-MIT.txttree-sitter-ruby-MIT.txtAlexMAS.GostCryptography-MIT.txtOASIS-CSAF-2.0-Notice.txtFIRST-CVSS-JSON-Schemas-BSD-3-Clause.txtMicrosoft.ML.OnnxRuntime-MIT.txtall-MiniLM-L6-v2-Apache-2.0.txtgolang-x-tools-BSD-3-Clause.txtgolang-x-mod-BSD-3-Clause.txt
1.1 Regulator-vendored evidence packages
Regulator- or vendor-published evidence packages (eIDAS QTSP/QSCD/TSL/LOTL fixtures, EBA DORA DPM/XBRL taxonomies, EBA RoI XSD packages, RFC 3161 TSA fixtures) follow a separate intake lane defined in regulatory-asset-intake.md. Each vendored package has:
- An entry in
docs/contracts/schemas/eu/eu-schema-taxonomy-assets-v1.yaml(the machine-readable inventory). - A
REG-<YYYYMMDD>-<short-id>.mddecision record underdocs/legal/decisions/that captures all five intake gates (engineering candidacy, schema-governance review, legal review, optional vendor compliance, vendoring + sprint update). - Bytes-on-disk under
docs/contracts/schemas/eu/<regime>/<vendor>/<version>/matching the recorded SHA-256. - A
NOTICE.mdattribution and (for vendored license text) a file underthird-party-licenses/.
Currently approved regulator-vendored assets: the OASIS CSAF 2.0 Schema Set + FIRST CVSS schemas listed in §1.
Approved-with-notice; vendored verbatim (intake complete):
- EBA DORA RoI Reporting Framework 4.0 errata5 (
taxo_package_4.0_errata5.zip). Source: European Banking Authority, framework 4.0 (taxonomy architecture v2.0). Gate 3 cleared 2026-05-02 (REG-20260502-eba-dora-roi-4-0-errata5); re-affirmed 2026-05-30 by the counsel reply (dora-eba-taxonomy-counsel-thread-schema-intake-reply.md, Path A — vendor-and-redistribute, RoI only). Distribution licence:LicenseRef-EBA-Legal-Notice-Reproduction-With-Source-Acknowledgement. BUSL-1.1 compatibility:compatible-with-notice(EBA bytes carved out of the BUSL grant). Vendored atdocs/contracts/schemas/eu/dora/roi/eba-reporting-framework-4.0/taxo_package_4.0_errata5/. Outer SHA-256sha256:2cf8a0fe6aadee36a5bf07403d7bd63a43cab96f98fad8251c31938e8242e2fb(18,213,535 bytes); re-verified by controlled curl fetch 2026-05-30 (byte-identical). Conditions met: preserve source acknowledgement; no implied EBA endorsement; no use of EBA name/abbreviation/logo beyond source identification; verbatim/unmodified; download fromeba.europa.euwith recorded SHA-256. Third-party-component scan GATE (counsel control #6) — PASS (2026-05-30): the package bundles only EBA-copyrighted files (1,633<!--(C) EBA-->markings; zero non-EBA copyright notices; zero embedded license/notice files; zero physically-bundled third-party schemas). XBRL International, EuroFiling, and W3C namespaces are referenced by external URL only (resolved by the XBRL processor catalog), not redistributed — so no separate third-party clearance is required. Full scan evidence in the package README. NOTICE.md attribution mounted; EBA Legal Notice text captured verbatim underthird-party-licenses/.
Currently not vendored (engineering paths shipped fail-closed; a correct asset-scope decision is required before any official taxonomy claim can flip on):
- EBA DORA incident-reporting machine-validation package. The earlier Framework 4.3 candidate is
ABANDONED-wrong-asset: counsel provisionally cleared the Framework 4.3 licensing posture, but engineering re-verified that Framework 4.3 is not the DORA major-incident package. A future correct DORA-IR package must get a new asset record, final notice review, hash pin, and third-party-component scan before vendoring. SeeREG-20260502-eba-dora-incident-framework-4-3. - eIDAS qualified provider pack (TSA tokens, OCSP/CRL, archive timestamps, signing/TSA cert chains, qualified TSL/LOTL snapshots). Gate 3 vendor-independent half cleared 2026-05-02; default engineering fallback is
reference-only-no-vendoringwith a fail-closed runtime-loader path. Final determination is pending Gate 4 (QTSP vendor selection); TLv6 / ETSI TS 119 612 v2.4.1 compatibility is binding on any pack chosen after 2026-04-28; eIDAS Articles 33/34/40 claim-control wording is binding on runtime output paths regardless of vendor outcome. SeeREG-20260502-eidas-qualified-provider-packandSPRINT_20260502_005_Cryptography_eidas_qtsp_vendor_intake.md.
See regulatory-asset-intake.md§6 for the live blocker list and the originating sprints.
2. NuGet Dependencies (Runtime)
Primary runtime dependencies for .NET 10 modules. Extracted via dotnet list package --include-transitive.
2.1 Core Framework & ASP.NET
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| Microsoft.AspNetCore.* | 10.0.x | MIT | MIT | Yes |
| Microsoft.EntityFrameworkCore | 10.0.0 | MIT | MIT | Yes |
| Microsoft.EntityFrameworkCore.Relational | 10.0.0 | MIT | MIT | Yes |
| Microsoft.Extensions.* | 10.0.x | MIT | MIT | Yes |
| Microsoft.Extensions.Configuration.Binder | 10.0.1 | MIT | MIT | Yes |
| Microsoft.Extensions.Hosting.WindowsServices | 10.0.1 | MIT | MIT | Yes |
| Microsoft.IdentityModel.* | 8.x | MIT | MIT | Yes |
| System.IdentityModel.Tokens.Jwt | 8.0.1 | MIT | MIT | Yes |
2.2 Serialization & Data
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| Newtonsoft.Json | 13.0.3 | MIT | MIT | Yes |
| YamlDotNet | 16.3.0 | MIT | MIT | Yes |
| protobuf-net | 3.2.45 | Apache-2.0 | Apache-2.0 | Yes |
| Google.Protobuf | 3.31.1 | BSD-3-Clause | BSD-3-Clause | Yes |
| Json.More.Net | 2.1.1 | MIT | MIT | Yes |
| JsonPointer.Net | 5.3.1 | MIT | MIT | Yes |
| JsonSchema.Net | 8.0.4 | MIT | MIT | Yes |
| AngleSharp | 1.2.0 | MIT | MIT | Yes |
JsonSchema.Net is used for local JSON Schema parsing and validation in offline contract checks, including the Notify ENISA SRP operator-supplied schema source. It is consumed as a NuGet dependency only; no source, schema package, or license text is vendored by Stella Ops.
YamlDotNet 16.3.0 is also the parser used by the first-party src/Tools/StellaOps.OpenApi.DocGen OpenAPI-to-markdown generator selected by Sprint OAPI-059-003. No external markdown generator package is vendored for that tool.
2.3 Database & Caching
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| Npgsql | 10.0.0 | PostgreSQL | PostgreSQL | Yes |
| Npgsql.EntityFrameworkCore.PostgreSQL | 10.0.0 | PostgreSQL | PostgreSQL | Yes |
| Dapper | 2.1.35 | Apache-2.0 | Apache-2.0 | Yes |
| StackExchange.Redis | 2.8.37 | MIT | MIT | Yes |
2.4 Cryptography & Security
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| BouncyCastle.Cryptography | 2.6.2 | MIT | MIT | Yes |
| BCrypt.Net-Next | 4.0.3 | MIT | MIT | Yes |
| Pkcs11Interop | 5.1.2 | Apache-2.0 | Apache-2.0 | Yes |
| Blake3 | 1.1.0 | Apache-2.0 OR CC0-1.0 | Apache-2.0 | Yes |
| System.Security.Cryptography.Pkcs | 7.0.2 | MIT | MIT | Yes |
| System.Security.Cryptography.ProtectedData | 9.0.0 | MIT | MIT | Yes |
| Novell.Directory.Ldap.NETStandard | 4.0.0 | MIT | MIT | Yes |
Novell.Directory.Ldap.NETStandardis the fully-managed LDAP/AD client used by the Authority LDAP identity-provider plugin. It replacedSystem.DirectoryServices.Protocols, whose nativelibldapP/Invoke breaks on hosts where the OpenLDAP soname differs from the one the runtime probes (e.g. Ubuntu 24.04 shipslibldap.so.2while the runtime looks forlibldap-2.5.so.0) — independent of CPU architecture. The managed client has no native dependency, so it is portable across x64/arm64 and air-gapped images.
2.5 Cloud Providers
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| AWSSDK.Core | 4.0.1.3 | Apache-2.0 | Apache-2.0 | Yes |
| AWSSDK.S3 | 4.0.16 | Apache-2.0 | Apache-2.0 | Yes |
| AWSSDK.KeyManagementService | 4.0.6 | Apache-2.0 | Apache-2.0 | Yes |
| Google.Cloud.Kms.V1 | 3.19.0 | Apache-2.0 | Apache-2.0 | Yes |
| Google.Api.Gax | 4.11.0 | Apache-2.0 | Apache-2.0 | Yes |
2.6 gRPC & Networking
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| Grpc.Net.Client | 2.71.0 | Apache-2.0 | Apache-2.0 | Yes |
| Grpc.Core.Api | 2.71.0 | Apache-2.0 | Apache-2.0 | Yes |
| Grpc.Auth | 2.71.0 | Apache-2.0 | Apache-2.0 | Yes |
2.7 Observability & Logging
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| Serilog | 3.1.1 | Apache-2.0 | Apache-2.0 | Yes |
| Serilog.AspNetCore | 8.0.1 | Apache-2.0 | Apache-2.0 | Yes |
| Serilog.Extensions.Hosting | 8.0.0 | Apache-2.0 | Apache-2.0 | Yes |
| Serilog.Sinks.Console | 5.0.1 | Apache-2.0 | Apache-2.0 | Yes |
| Serilog.Sinks.File | 5.0.0 | Apache-2.0 | Apache-2.0 | Yes |
2.8 SBOM & Security Scanning
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| CycloneDX.Core | 10.0.2 | Apache-2.0 | Apache-2.0 | Yes |
| NuGet.Versioning | 6.13.2 | Apache-2.0 | Apache-2.0 | Yes |
| Semver | 2.3.0 | MIT | MIT | Yes |
2.9 Code Analysis & Build
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| Microsoft.CodeAnalysis.Common | 4.14.0 | MIT | MIT | Yes |
| Microsoft.CodeAnalysis.CSharp | 4.14.0 | MIT | MIT | Yes |
| Microsoft.CodeAnalysis.Workspaces.MSBuild | 4.14.0 | MIT | MIT | Yes |
| Microsoft.Build | 17.7.2 | MIT | MIT | Yes |
| Microsoft.Build.Locator | 1.10.2 | MIT | MIT | Yes |
| Esprima | 3.0.5 | BSD-3-Clause | BSD-3-Clause | Yes |
| Mono.Cecil | 0.11.6 | MIT | MIT | Yes |
2.10 Binary Analysis
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| Iced | 1.21.0 | MIT | MIT | Yes |
| Gee.External.Capstone | 2.3.0 | BSD-3-Clause | BSD-3-Clause | Yes |
| PdfPig | 0.1.12 | Apache-2.0 | Apache-2.0 | Yes |
2.11 Compression & Archives
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| SharpCompress | 0.41.0 | MIT | MIT | Yes |
| ZstdSharp.Port | 0.8.7 | MIT | MIT | Yes |
2.12 Authentication & Authorization
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| Microsoft.AspNetCore.Authentication.JwtBearer | 10.0.0 | MIT | MIT | Yes |
| OpenIddict.Abstractions | 6.4.0 | Apache-2.0 | Apache-2.0 | Yes |
2.13 Resilience & Scheduling
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| Microsoft.Extensions.Http.Resilience | 10.1.0 | MIT | MIT | Yes |
| Polly | 8.5.2 | BSD-3-Clause | BSD-3-Clause | Yes |
| Polly.Core | 8.5.2 | BSD-3-Clause | BSD-3-Clause | Yes |
| Polly.Extensions | 8.4.2 | BSD-3-Clause | BSD-3-Clause | Yes |
| Polly.Extensions.Http | 3.0.0 | BSD-3-Clause | BSD-3-Clause | Yes |
| Cronos | 0.9.0 | MIT | MIT | Yes |
Microsoft.Extensions.Http.Resilience 10.x (MIT) wraps every outgoing integration connector HTTP call with the standard retry / circuit-breaker / timeout pipeline (see src/Integrations/StellaOps.Integrations.WebService/IntegrationHttpClientServiceCollectionExtensions.cs). Polly v8 (Polly.Core, BSD-3-Clause) is pulled in transitively. Both licenses are on the BUSL-1.1 allowlist; no vendored license texts are required for these packages because they are consumed via NuGet rather than vendored source.
2.14 Utilities
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| Humanizer.Core | 2.14.1 | MIT | MIT | Yes |
| System.CommandLine | 2.0.0-beta5 | MIT | MIT | Yes |
| NetEscapades.Configuration.Yaml | 3.1.0 | MIT | MIT | Yes |
| Pipelines.Sockets.Unofficial | 2.2.8 | MIT | MIT | Yes |
2.15 Manifest & Config Parsers
| Package | Version | License | SPDX | Compatible | Consuming Module |
|---|---|---|---|---|---|
| Tomlyn | 0.19.0 | BSD-2-Clause | BSD-2-Clause | Yes | StellaOps.Scanner.Analyzers.Lang.Rust (Cargo.toml manifest reader) |
2.16 AI/ML Runtime
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| Microsoft.ML.OnnxRuntime | 1.20.1 | MIT | MIT | Yes |
3. NuGet Dependencies (Development/Test)
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| xunit | 2.x | Apache-2.0 | Apache-2.0 | Yes |
| xunit.runner.visualstudio | 2.x | Apache-2.0 | Apache-2.0 | Yes |
| Moq | 4.x | BSD-3-Clause | BSD-3-Clause | Yes |
| AwesomeAssertions | 9.4.0 | Apache-2.0 | Apache-2.0 | Yes |
| Microsoft.AspNetCore.Mvc.Testing | 10.0.x | MIT | MIT | Yes |
| Testcontainers | 3.x | MIT | MIT | Yes |
| Testcontainers.PostgreSql | 3.x | MIT | MIT | Yes |
| coverlet.collector | 6.x | MIT | MIT | Yes |
| BenchmarkDotNet | 0.13.x | MIT | MIT | Yes |
AwesomeAssertions note (sprint
SPRINT_20260503_005): drop-in community fork of FluentAssertions 6.x kept under Apache-2.0. We migrated away fromFluentAssertionsbecause v7.0+ (Jan 2025) was re-licensed under the Xceed Community License, which requires a paid subscription for commercial (BUSL-1.1) use. Pinned to9.4.0insrc/Directory.Packages.props; nupkg SHA25680B5A9F84B2F8E78CE7244A496893D73F910848562046FD57D41094D419660D2; license verified via nuspec at~/.nuget/packages/awesomeassertions/9.4.0/AwesomeAssertions.nuspec(<license type="expression">Apache-2.0</license>).
4. npm Dependencies (Angular Frontend)
4.1 Runtime Dependencies
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| @angular/animations | ^17.3.0 | MIT | MIT | Yes |
| @angular/cdk | ^17.3.10 | MIT | MIT | Yes |
| @angular/common | ^17.3.0 | MIT | MIT | Yes |
| @angular/compiler | ^17.3.0 | MIT | MIT | Yes |
| @angular/core | ^17.3.0 | MIT | MIT | Yes |
| @angular/forms | ^17.3.0 | MIT | MIT | Yes |
| @angular/material | ^17.3.10 | MIT | MIT | Yes |
| @angular/platform-browser | ^17.3.0 | MIT | MIT | Yes |
| @angular/platform-browser-dynamic | ^17.3.0 | MIT | MIT | Yes |
| @angular/router | ^17.3.0 | MIT | MIT | Yes |
| monaco-editor | 0.52.0 | MIT | MIT | Yes |
| rxjs | ~7.8.0 | Apache-2.0 | Apache-2.0 | Yes |
| tslib | ^2.3.0 | 0BSD | 0BSD | Yes |
| yaml | ^2.4.2 | ISC | ISC | Yes |
| zone.js | ~0.14.3 | MIT | MIT | Yes |
4.2 Development Dependencies
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| @angular-devkit/build-angular | ^17.3.17 | MIT | MIT | Yes |
| @angular/cli | ^17.3.17 | MIT | MIT | Yes |
| @angular/compiler-cli | ^17.3.0 | MIT | MIT | Yes |
| @axe-core/playwright | 4.8.4 | MPL-2.0 | MPL-2.0 | Yes |
| @playwright/test | ^1.47.2 | Apache-2.0 | Apache-2.0 | Yes |
| @storybook/angular | 8.1.0 | MIT | MIT | Yes |
| @storybook/addon-* | 8.1.0 | MIT | MIT | Yes |
| jasmine-core | ~5.1.0 | MIT | MIT | Yes |
| karma | ~6.4.0 | MIT | MIT | Yes |
| karma-chrome-launcher | ~3.2.0 | MIT | MIT | Yes |
| karma-coverage | ~2.2.0 | MIT | MIT | Yes |
| karma-jasmine | ~5.1.0 | MIT | MIT | Yes |
| storybook | ^8.1.0 | MIT | MIT | Yes |
| typescript | ~5.4.2 | Apache-2.0 | Apache-2.0 | Yes |
4.3 DevPortal (Astro) Dependencies
| Package | Version | License | SPDX | Compatible |
|---|---|---|---|---|
| astro | 5.16.0 | MIT | MIT | Yes |
| @astrojs/mdx | 4.3.12 | MIT | MIT | Yes |
| @astrojs/starlight | 0.36.2 | MIT | MIT | Yes |
| rapidoc | 9.3.8 | MIT | MIT | Yes |
| linkinator | 6.1.2 | Apache-2.0 | Apache-2.0 | Yes |
5. Infrastructure Dependencies
Components required for deployment but not bundled with StellaOps source.
| Component | Version | License | SPDX | Distribution | Notes |
|---|---|---|---|---|---|
| PostgreSQL | ≥16 | PostgreSQL | PostgreSQL | Separate | Required database |
| RabbitMQ | ≥3.12 | MPL-2.0 | MPL-2.0 | Separate | Optional message broker |
| OpenBao | 2.4.1 (dev/test default tag) | MPL-2.0 | MPL-2.0 | NOT distributed — dev/test tooling only (external image openbao/openbao, pulled at dev/test time) | DEV/TEST-ONLY secret broker (Linux Foundation; community fork of HashiCorp Vault). The opt-in openbao compose profile (devops/compose/docker-compose.openbao.yml) runs an ephemeral OpenBao for local development and automated tests; it is never part of a release bundle and is not a supported production backend (operator decision 2026-07-04 — Option A of the OpenBao positioning memo; ADR-031 §D5 as amended). The supported external secret backend is an operator-run HashiCorp Vault (or an operator-run OpenBao). API-compatible with Vault (KV v2 + token/login), so Stella Ops reuses the existing Vault HTTP client — no new NuGet dependency, no source vendoring, no redistribution. Because Stella Ops does not distribute the image, MPL-2.0 distribution obligations do not attach; the former courtesy license copy third-party-licenses/OpenBao-MPL-2.0.txt was removed with this decision (component not redistributed, and the copy’s provenance was non-canonical). Upstream: https://openbao.org / https://github.com/openbao/openbao. |
| Valkey | ≥7.2 | BSD-3-Clause | BSD-3-Clause | Separate | Optional cache (Redis fork) for StellaOps and Rekor |
| Rekor v2 (rekor-tiles) | v2 (tiles) | Apache-2.0 | Apache-2.0 | Separate | Optional transparency log (POSIX tiles backend) |
| Docker | ≥24 | Apache-2.0 | Apache-2.0 | Tooling / bundled image package | Container runtime and CLI tooling for deployment execution and the standalone agent-core image |
| Docker Compose | 2.40.3 | Apache-2.0 | Apache-2.0 | Tooling / bundled image package | CLI plugin used by the local agent-target deployment lab and bundled in the standalone agent-core image for ComposeHost execution |
| Docker Buildx | 0.30.x (Ubuntu noble universe docker-buildx package) | Apache-2.0 | Apache-2.0 | Tooling / bundled image package | Docker CLI plugin bundled in the standalone agent-core image for the built-in build.docker execution plugin (Sprint 20260529.066 S066-001). Upstream: https://github.com/docker/buildx. |
| Anchore Grype | latest resolved at benchmark runtime | Apache-2.0 | Apache-2.0 | External benchmark image (anchore/grype) | Optional Stella/Trivy/Grype benchmark scanner used by tools/benchmarks/stella-vs-trivy; pulled and resolved at run time, not vendored or redistributed in the Stella Ops source tree. Upstream: https://github.com/anchore/grype. |
| ansible-core | distro package | GPLv3 | GPL-3.0-or-later | Tooling / bundled image package | Runtime package in the standalone agent-core image for deploy.ansible. Stella Ops’ wrapper plugin remains BUSL-1.1 and invokes ansible-playbook as a separate process; no Ansible code is vendored, linked, patched, or derived. Redistributors of agent images containing ansible-core must satisfy GPLv3 obligations for that package. |
| rsync | distro package | GPLv3 with OpenSSL/xxhash dynamic-linking exception | GPL-3.0-or-later | Tooling / bundled image package | Runtime package in the standalone agent-core image for Ansible synchronize tasks in operator-owned playbooks, including playbook-fidelity acceptance. Stella Ops invokes rsync as separate runtime tooling and does not vendor, link, patch, or derive from rsync code. Redistributors of agent images containing rsync must satisfy GPLv3 obligations for that package. |
| Alpine/OpenSSL QA fixture image | latest | Mixed package licenses | - | External image | Linux deployment E2E fixture pulled from the configured registry source; not distributed |
Local RFC 3161 TSA image (OpenSSL ts) | OpenSSL 3.x on Alpine base | Apache-2.0 (OpenSSL 3.x) | Apache-2.0 | Bundled image (built in-repo) | Self-hosted, air-gapped Timestamp Authority for EvidenceLocker bundle sealing (ADR-036 / SPRINT_20260704_009 SER-1). Image is built in-repo from an OpenSSL base using the openssl ts timestamping facility + a minimal HTTP handler — no unvetted third-party TSA binary is vendored. OpenSSL 3.x is Apache-2.0 (permissive, BUSL-1.1 compatible). No cloud/managed TSA is used (offline-first invariant). Upstream: https://www.openssl.org. |
| Microsoft Windows Nano Server image | ltsc2022 | Microsoft container image terms | LicenseRef-Microsoft-Container | External image | Windows deployment E2E fixture pulled from MCR; not distributed |
| NGINX | 1.27-alpine | BSD-2-Clause | BSD-2-Clause | Separate | Optional local QA fixture image for Harbor and GitHub App onboarding success-path checks |
| OCI Registry | - | Varies | - | External | Harbor (Apache-2.0), Docker Hub, etc. |
CNCF Distribution registry (registry:2) | 2.8.x | Apache-2.0 | Apache-2.0 | External image (docker.io/library/registry) | OCI Distribution registry. Used as (a) hosted test registries (devops/compose/docker-compose.integrations.yml, docker-compose.testing.yml, StellaOps.Infrastructure.Registry.Testing) and (b) a CI Docker Hub pull-through cache in proxy mode (devops/ci-local/docker-compose.registry-cache.yml). Pulled at deploy/test time; not bundled or redistributed by Stella Ops. Upstream: https://github.com/distribution/distribution |
| Kubernetes | ≥1.28 | Apache-2.0 | Apache-2.0 | Orchestration | Optional |
| all-MiniLM-L6-v2 embedding model | - | Apache-2.0 | Apache-2.0 | Optional runtime asset | Local semantic embedding model for AdvisoryAI (VectorEncoderType=onnx) |
Cilium Tetragon (vendored as stellaops/tetragon) | v1.4.0 | Apache-2.0 | Apache-2.0 | Vendored OCI image at lab registry | Optional Linux eBPF sensor input (Sprint 20260513_022). Upstream quay.io/cilium/tetragon@sha256:500eca691c0be96dc7943c2da43d9d3ea1fdcaabfa0406a63742914d3c438123; Stella sha256:5e1e9017ab5927e513bead1ede1861cef2c19b7144162422a8ea894b4c4b1b0b. LICENSE at third-party-licenses/tetragon-apache-2.0.txt (sha256 f096c31ac0fb2e66df5b7ec20049741ae15accd50c8cd4d100b4db6c9353f6aa) — vendored 2026-05-13 from https://raw.githubusercontent.com/cilium/tetragon/v1.4.0/LICENSE per CLAUDE.md §2.8(2) user-initiated authorization. Wrapper Dockerfile at devops/airgap/tetragon/Dockerfile. |
| Mailpit | latest | MIT | MIT | Separate dev-only image | Developer SMTP catch-all + web UI for Notify email channels (devops/compose/docker-compose.dev.yml). NOT shipped or recommended for production — production uses customer-supplied SMTP relay. Source: https://github.com/axllent/mailpit |
| Grafana OSS | 10.4.2 | AGPL-3.0-only | AGPL-3.0-only | Separate external image (grafana/grafana-oss:10.4.2) | Optional observability dashboards (weighted-canary board devops/observability/grafana/canary.json, wired in devops/compose/docker-compose.telemetry.yml). Runs as a separate, unmodified service container reached over HTTP — see the AGPL aggregation analysis in §5.1 below. Stella Ops does not bundle, statically/dynamically link, or distribute a modified Grafana; the image is pulled at deploy time from docker.io/grafana. Sibling Grafana-Labs tools already in the stack (Loki, Tempo, Promtail) are AGPL-3.0 likewise and covered by the same analysis. |
5.1 AGPL-3.0 components and the “separate service / mere aggregation” determination
Grafana OSS (and the sibling Grafana-Labs agents Loki, Tempo, and Promtail) are licensed AGPL-3.0, which appears in the blocked_licenses allowlist in §8.4. That blocklist governs code that is linked into, derived from, or distributed as part of the Stella Ops product (BUSL-1.1). It does not govern an unmodified upstream service that Stella Ops merely deploys alongside and talks to over a network boundary.
Deployment model (the only way these components are used):
- The component runs in its own container, from the unmodified upstream image (
grafana/grafana-oss:10.4.2, pinned, notlatest), pulled at deploy time from the upstream registry. - Stella Ops and Grafana communicate only over HTTP / the Prometheus HTTP query API — there is no in-process linking, no shared address space, no embedding of Grafana source or binaries into a Stella Ops artifact.
- Stella Ops ships only configuration and data consumed by Grafana (provisioning YAML + the
canary.jsondashboard), which are interface data, not derivative works of Grafana. - Stella Ops does not distribute Grafana, modified or otherwise. Operators obtain Grafana directly from upstream; the compose file references it by image tag.
Conclusion: under the AGPL-3.0 §0/§13 definitions, this is aggregation of separate programs, not the creation of a “covered work” or a “modified version.” AGPL-3.0’s network-use copyleft (§13) attaches to modifying the AGPL program and making the modified version available to network users; neither occurs here. Therefore Grafana OSS as deployed is compatible with BUSL-1.1 distribution of Stella Ops under the mere-aggregation/separate-service posture. This determination is scoped to the unmodified-separate-container deployment model only. If Stella Ops ever (a) forks/patches Grafana, (b) embeds Grafana code, or © redistributes a Grafana image as part of a Stella Ops artifact, this determination is void and the §8.4 block re-applies — open a new legal review before doing any of those.
6. Regional/Optional Components
Components with special licensing or distribution considerations.
6.1 Russian Federation (RootPack_RU)
| Component | License | Distribution | Notes |
|---|---|---|---|
| AlexMAS.GostCryptography | MIT | Vendored source | GOST algorithm implementation |
| CryptoPro CSP | Commercial | Customer-provided | PKCS#11 interface only |
| CryptoPro wrapper | BUSL-1.1 | StellaOps code | Integration bindings |
6.2 China (RootPack_CN) - Planned
| Component | License | Distribution | Notes |
|---|---|---|---|
| SM2/SM3 verification | MIT | NuGet (BouncyCastle.Cryptography 2.6.2) | Chinese national standards; software SM provider gated by SM_SOFT_ALLOWED |
| HSM integration | Commercial | Customer-provided | PKCS#11 interface only |
6.3 eIDAS (EU Qualified Signatures)
| Component | License | Distribution | Notes |
|---|---|---|---|
| BouncyCastle | MIT | NuGet | eIDAS-compatible algorithms |
| HSM integration | Commercial | Customer-provided | PKCS#11/CKM interface |
7. Known Restrictions & Requirements
7.0 EU Regulatory Schema And Taxonomy Assets
Sprint SPRINT_20260430_204_DOCS_eu_schema_taxonomy_assets.md added a local manifest at docs/contracts/schemas/eu/eu-schema-taxonomy-assets-v1.yaml. Approved local schema packages are recorded here; remaining unapproved external schema or taxonomy bodies stay blocked.
| Asset family | Local status | License/intake note |
|---|---|---|
| OASIS CSAF 2.0 schema set plus FIRST CVSS transitive refs | Present | Local copies are vendored under docs/contracts/schemas/eu/csaf/2.0/; hashes are recorded in the schema inventory and notices are preserved in /NOTICE.md plus /third-party-licenses/. |
EBA DORA RoI taxonomy package taxo_package_4.0_errata5.zip | Present | Vendored verbatim under docs/contracts/schemas/eu/dora/roi/eba-reporting-framework-4.0/taxo_package_4.0_errata5/; outer SHA-256 sha256:2cf8a0fe…e2fb recorded in the schema inventory; approved-with-notice (counsel Path A, RoI only). Third-party-component scan GATE PASS (2026-05-30): EBA-only content, no third-party redistribution. Notices in /NOTICE.md + /third-party-licenses/. |
| EBA DORA incident taxonomy package | ABANDONED-wrong-asset for Framework 4.3; no correct package vendored | Do not vendor Framework 4.3 for DORA incident reporting. If a correct DORA-IR machine-validation package appears, open a new REG record and follow docs/compliance/packs/dora/incident-taxonomy-completion-procedure.md. |
| ISO/IEC and IEC standards mapping sources | Metadata only | Licensed standard text is not vendored. IEC 62443 requirement-level claims remain blocked until licensed local review. |
7.1 Commercial Components (Not Distributed)
| Component | Vendor | Requirement |
|---|---|---|
| CryptoPro CSP | CryptoPro LLC | Customer must obtain license from crypto-pro.ru |
| Hardware Security Modules | Various | Customer-provided with PKCS#11 drivers |
7.2 Export Control Considerations
| Algorithm | Regulation | Notes |
|---|---|---|
| GOST R 34.10-2012 | Russian national | Recommended for RootPack_RU only |
| SM2/SM3/SM4 | Chinese national | Recommended for RootPack_CN only |
| Standard (ECDSA/RSA/EdDSA) | Mass-market exempt | No restrictions |
See docs/legal/crypto-compliance-review.md for detailed export control analysis.
7.3 Attribution Requirements
The following licenses require attribution in distributed software:
- MIT: Copyright notice in documentation/NOTICE file
- Apache-2.0: NOTICE file preservation, license in documentation
- BSD-3-Clause: Copyright notice in documentation
All required attributions are maintained in /NOTICE.md.
7.4 Third-Party Vulnerability Data In Produced Artifacts (compact vuln-db)
The compact vulnerability database artifacts produced by the single Concelier exporter (export:vuln-db-compact server job / stella vuln-db export CLI delegate) are composite third-party data artifacts, not BUSL-1.1-licensed software (SPRINT_20260703_006 EXPORT-E2/E3; counsel directive docs/legal/decisions/compact-vulndb-license-segregation-counsel-thread-reply.md, 2026-07-04):
| Artifact | License posture | Content |
|---|---|---|
vuln-db.sqlite | LicenseRef-StellaOps-Composite-Data-Notice (provisional — final LicenseRef pending legal-docs decision) | BUSL-distribution-clean core: records only from sources whose license_class is public-domain / permissive / government-open / Stella-owned with license known and prose / database-right risks cleared. Facts-only projections from cleared share-alike sources strip prose (titles) at export. |
vuln-db-sharealike.sqlite | CC-BY-SA-4.0 | Share-alike layer (currently: Ubuntu Security Notices, © Canonical Ltd.) with per-record attribution rows (record_attribution). |
vuln-db.manifest.json / vuln-db-sharealike.manifest.json | Sidecar metadata | Capability + license map (has_epss/has_kev/has_reachability_sinks/sink_langs, corpus digest, per-source rights fields, record counts). Mirrored inside each sqlite as export_manifest / license_sources / license_notices tables. |
Enforcement is the data-driven license gate (CompactVulnDbLicenseGate + CompactVulnDbLicenseMatrix, src/Concelier/__Libraries/StellaOps.Concelier.Exporter.VulnDbCompact/); the export fails on: unknown license routed to core, share-alike prose in core, substantial share-alike database extraction in core, NC/ND/no-redistribution content in any public artifact, missing attribution for redistributable CC content, or an encountered source with no configured routing. Unknown-licensed sources (including, pending EXPORT-E4 evidence: FIRST EPSS, CISA KEV, vuln.go.dev, RustSec) are excluded from every public artifact by default.
Notices: third-party-licenses/DATA-NOTICES.md (per-source data notices) and third-party-licenses/CC-BY-SA-4.0.txt (license text — placeholder until the exact legalcode is vendored; the companion artifact must not ship before that).
8. Automation & Verification
8.1 Generating Updated Dependency Lists
# NuGet dependencies
dotnet list src/<Project>/<Project>.csproj package --include-transitive
# npm dependencies (with licenses)
cd src/Web/StellaOps.Web && npx license-checker --json --production
# Full SBOM with license info
dotnet run --project src/Scanner/StellaOps.Scanner.Cli -- sbom generate \
--format cyclonedx-1.6 \
--include-licenses \
--output stellaops-sbom.json
8.2 CI License Audit
See .gitea/workflows/license-audit.yml for automated license validation.
8.3 Allowed Licenses (Allowlist)
# SPDX identifiers permitted in StellaOps
allowed_licenses:
# Permissive licenses (fully compatible)
- MIT
- Apache-2.0
- BSD-2-Clause
- BSD-3-Clause
- ISC
- 0BSD
- PostgreSQL
- Zlib
- BlueOak-1.0.0
- Python-2.0
- CC0-1.0
- Unlicense
# Weak copyleft (compatible with conditions)
- MPL-2.0 # File-level copyleft
- LGPL-2.1-or-later # Library linking allowed
- LGPL-3.0-or-later # Library linking allowed
# Data/documentation licenses (for non-code assets)
- CC-BY-3.0 # Attribution license (data only)
- CC-BY-4.0 # Attribution license (data only)
- LicenseRef-OASIS-Specification-Notice # Specification/schema assets only
8.4 Blocked Licenses
These licenses are NOT compatible with BUSL-1.1 when the component is linked into, derived from, or distributed as part of a StellaOps artifact:
blocked_licenses:
- GPL-2.0-only
- GPL-2.0-or-later
- GPL-3.0-only
- GPL-3.0-or-later
- AGPL-3.0-only # see §8.4.2 separate-service exception (Grafana/Loki/Tempo)
- AGPL-3.0-or-later # see §8.4.2 separate-service exception
- SSPL-1.0 # Server Side Public License - additional network restrictions
- BUSL-1.1 # Business Source License - time-delayed commercial restrictions
- Elastic-2.0 # Similar restrictions to SSPL
- Commons-Clause # Commercial use restrictions addon
- LicenseRef-Proprietary
- UNLICENSED
8.4.1 GPLv3 separate-process runtime tooling
The GPL block governs linked libraries, vendored code, patches, and derivative works. The deploy.ansible wrapper uses ansible-core only as runtime tooling by launching ansible-playbook as a separate process from the target-agent image. Operator-owned playbooks, including playbook-fidelity acceptance, may also invoke rsync through Ansible synchronize tasks. Stella Ops does not link against Ansible or rsync libraries, vendor their source, or modify their code. The BUSL-1.1 wrapper and the GPLv3 Ansible/rsync processes remain separate programs connected by the command-line interface. This determination is scoped to the unmodified separate-process model; any vendoring, patching, embedding, or library-linking use requires a new legal review and re-applies the blocked-license rule.
8.4.2 Separate-service / mere-aggregation exception
The block above governs bundling, linking, and derivative distribution. It does not govern an unmodified upstream service deployed in its own container and reached only over a network boundary (mere aggregation). AGPL-3.0 components used strictly under that model are permitted; the binding analysis, scope, and revocation conditions are in §5.1. Currently approved under this exception: Grafana OSS (and the sibling AGPL Grafana-Labs agents Loki, Tempo, Promtail) — separate containers, unmodified images, HTTP-only integration, not redistributed by Stella Ops. Any fork/patch/embed/redistribute of these components voids the exception and re-applies the block.
8.5 Conditional Licenses (Dev Dependencies Only)
The following licenses are used only in development dependencies and are not shipped to production:
| Package | License | Usage | Notes |
|---|---|---|---|
@img/sharp-libvips-* | LGPL-3.0-or-later | DevPortal build (Astro image optimization) | Not in production bundle |
axe-core | MPL-2.0 | Accessibility testing | Dev/test only |
spdx-exceptions | CC-BY-3.0 | License data file | Data, not code |
9. Document Maintenance
| Action | Trigger | Owner |
|---|---|---|
| Update NuGet deps | Major version bump | Engineering |
| Update npm deps | Major version bump | Frontend team |
| Review new packages | PR review checklist | Security Guild |
| Annual audit | January each year | Legal + Security |
10. References
Document maintained by: Security Guild Last full audit: 2026-01-20
