Connector configuration schema parity table
Originally generated for Sprint 20260503-011 (B-CONNCFG-005) and refreshed by Sprint 20260504-001 (CONN-OVERLAY-001 — see docs-archive/implplan/SPRINT_20260504_001_*.md). Tracks which SourceDefinitions entries have a connector-owned configuration schema, which expose live runtime overlay (DB-persisted config takes effect without restart), and which have orphan status (no connector library backs them).
Legend:
- Schema: Y =
IAdvisorySourceConfigurationContributorregistered in DI. - Overlay: Y = connector wires
AddAdvisorySourceRuntimeOverlay<T,O>+AddAdvisorySourceCacheInvalidator<T>AND its connector class consumesIOptionsMonitor<TOptions>so PUT changes apply on the next fetch without service restart. - Connector lib: Y = there is a
StellaOps.Concelier.Connector.{X}(orDistro.{X}/Vndr.{X}) library with a runnable fetch pipeline.
Primary feeds
| SourceId | Schema | Overlay | Connector lib | Notes |
|---|---|---|---|---|
| nvd | Y | Y | Y | Canary for runtime cache propagation. |
| osv | Y | Y | Y | Aggregator drives ecosystem aliases below. |
| ghsa | Y | Y | Y | Optional: apiToken (Secret) for higher GitHub REST API rate limits. |
| cve | Y | Y | Y | Auth-triplet OR seed directory. |
| epss | Y | Y | Y | Air-gap branch via bundlePath. |
| kev | Y | Y | Y | Single-feed minimal. |
Vendors
| SourceId | Schema | Overlay | Connector lib | Notes |
|---|---|---|---|---|
| redhat | Y | Y | Y (Distro.RedHat) | RHSA/RedHat advisories. Distro.RedHat plugin reports SourceName=redhat. |
| microsoft | Y | Y | Y (Vndr.Msrc) | Azure client-credential triplet. |
| oracle | Y | Y | Y | Calendar + advisory URIs as StringList. |
| adobe | Y | Y | Y | Index + additional-index URIs. |
| apple | Y | Y | Y | Includes allow/block lists for trust filtering. |
| chromium | Y | Y | Y | Single Atom feed. |
| cisco | Y | Y | Y | OAuth client credentials. |
| vmware | Y | Y | Y | Index URI + pacing. |
| intel | Y | Y | Y | Hardware PSIRT connector. |
| amd | Y | Y | Y | Hardware PSIRT connector; production status tracked separately. |
| siemens | Y | Y | Y | ProductCERT CSAF connector. |
| N | N | N | Too broad for one connector; split Android/Pixel if needed and rely on gcp/chromium for existing cloud/browser coverage. | |
| fortinet | Y | Y | Y | Fortinet PSIRT RSS/CSAF endpoint overrides. |
| juniper | N | N | N | Unsupported until stable official all-Juniper JSA feed/API exists; Mist-only RSS would need a separate scoped source. |
| paloalto | Y | Y | Y | Palo Alto RSS/JSON/CSAF endpoint overrides. |
Distributions
| SourceId | Schema | Overlay | Connector lib | Notes |
|---|---|---|---|---|
| alpine | Y | Y | Y | secdb releases + repository scoping. |
| amazon | Y | Y | Y | Amazon Linux ALAS RSS/detail feed overrides (feedUris, baseUri). |
| debian | Y | Y | Y | Salsa list + tracker base. |
| ubuntu | Y | Y | Y | USN notices feed. |
| suse | Y | Y | Y | Changes endpoint + advisory base. |
| rhel | N | N | Y (Distro.RedHat, alias) | Folded into redhat schema. |
| centos | N | N | N | Unsupported/deprecated; legacy CentOS Linux can only use Red Hat history with reduced confidence and explicit RHEL-major mapping. |
| fedora | Y | Y | Y | Fedora Bodhi endpoint overrides (updatesEndpoint, detailBaseUri). |
| arch | Y | Y | Y | Arch Security Advisories connector; UI+CLI configuration wired. |
| gentoo | Y | Y | Y | GLSA connector; UI+CLI configuration wired. |
| astra | Y | Y | Y | Astra Linux connector; UI+CLI configuration wired. |
Ecosystems / package managers
| SourceId | Schema | Overlay | Connector lib | Notes |
|---|---|---|---|---|
| npm | Y | Y | Y | OSV alias scope. |
| pypi | Y | Y | Y | OSV alias scope. |
| go | Y | Y | Y | OSV alias scope. |
| rubygems | Y | Y | Y | OSV alias scope. |
| crates | Y | Y | Y | OSV alias scope. |
| maven | Y | Y | Y | OSV alias scope. |
| hex | Y | Y | Y | OSV alias scope. |
| packagist | Y | Y | Y | OSV alias scope. |
| nuget | N | N | N | GHSA package-ecosystem filter; covered by ghsa. |
| rustsec | Y | Y | Y | OSV alias scope. |
| pypa | Y | Y | Y | OSV alias scope. |
| govuln | Y | Y | Y | OSV alias scope. |
| bundler-audit | Y | Y | Y | OSV alias scope. |
CERTs
| SourceId | Schema | Overlay | Connector lib | Notes |
|---|---|---|---|---|
| cert-fr | Y | Y | Y | French CERT. |
| cert-de | Y | Y | Y (CertBund) | Alias cert-bund. |
| cert-cc | Y | Y | Y | TimeWindowCursorOptions flattened. |
| cert-in | Y | Y | Y | Indian CERT. |
| cccs | Y | Y | Y | Multi-language feeds as StringList. |
| auscert | Y | Y | Y (Acsc) | Alias acsc. |
| jpcert | Y | Y | Y (Jvn) | Alias jvn. |
| krcert | Y | Y | Y (Kisa) | Alias kisa. |
| us-cert | Y | Y | Y (Ics.Cisa) | Required GovDelivery code. |
| fstec-bdu | Y | Y | Y (Ru.Bdu) | FilePath cache directory. |
| nkcki | Y | Y | Y (Ru.Nkcki) | FilePath cache directory. |
| cert-eu | Y | Y | Y (NationalCert) | CERT-EU RSS advisory feed. |
| cert-at | Y | Y | Y (NationalCert) | CERT.at warning feed. |
| cert-be | Y | Y | Y (NationalCert) | Belgian CCB advisories RSS. |
| cert-ch | N | N | N | Unsupported; warning pages exist, but no current official machine-readable advisory feed was found. |
| cert-pl | Y | Y | Y (NationalCert) | CERT Polska RSS; disabled by default. |
| cert-ua | Y | Y | Y (NationalCert) | CERT-UA article RSS; disabled by default. |
Cloud / containers / hardware / threat-intel
| SourceId | Schema | Overlay | Connector lib | Notes |
|---|---|---|---|---|
| aws | Y | Y | Y (Cloud.Aws) | Public RSS fetcher; UI+CLI configuration wired. |
| azure | N | N | N | Canonical alias covered by microsoft/MSRC. |
| gcp | Y | Y | Y | Public Atom fetcher; UI+CLI configuration wired. |
| chainguard | N | N | N | OSV-backed source bucket; no direct connector library. |
| wolfi | N | N | N | OSV-backed source bucket; no direct connector library. |
| kaspersky-ics | Y | Y | Y | ICS feeds. |
| mitre-attack | N | N | N | Removed in Sprint 20260513_008; no active source row. |
| mitre-d3fend | N | N | N | Removed in Sprint 20260513_008; no active source row. |
| exploitdb | Y | Y | Y | Metadata-only connector reads official CSV rows; exploit bodies are not fetched. |
| metasploit | Y | Y | Y | Metadata-only connector reads module metadata JSON; module source files are not fetched. |
Mirror & VEX stubs
| SourceId | Schema | Overlay | Connector lib | Notes |
|---|---|---|---|---|
| stella-mirror | Y | Y | Y (StellaOpsMirror) | Mirror config has its own special-case path in ConfiguredAdvisorySourceService; the connector class still consumes IOptionsMonitor<StellaOpsMirrorConnectorOptions> for runtime overlay parity. |
| csaf | N | N | N | Stub catalog entry. Sprint 012 unifies Excititor providers; remove or repurpose. |
| csaf-tc | N | N | N | Stub catalog entry — same as above. |
| vex | N | N | N | Stub catalog entry — same as above. |
Summary
ARM was removed from the active catalog/project set in Sprint 20260601_001 because the legacy connector failed closed and no approved machine-readable feed exists. It should not be counted as a current orphan.
poc-github and docker-official were also removed from the active catalog in Sprint 20260601_001. poc-github is uncurated and safety/legal ambiguous; docker-official was only Docker Hub/Official Images metadata, not an official CVE/VEX advisory feed.
Live counts are served by /api/v1/advisory-sources/catalog. This matrix keeps the connector-level parity decision: a row with no direct connector can still be parent-covered (osv, ghsa, redhat, microsoft), intentionally unsupported, a future implementation candidate, or a cleanup candidate.
Non-tunable fields (per-connector exclusions)
The runtime overlay only projects fields that are operator-tunable. The following internal pacing / feature-flag knobs remain compile-time constants or IOptions<T> defaults and are intentionally NOT exposed via IAdvisorySourceConfigurationContributor schemas:
- All connectors:
HttpClientNameconstants (DI registration key, never operator-mutable). NvdOptions: pagination batch size (resultsPerPageliteral2000inBuildRequestUri) is a deterministic API constraint, not a tunable.CiscoOptions: OAuth token cache window (internal back-off), andMaxPagesPerFetch/MaxAdvisoriesPerFetchare exposed (operator pacing knobs).AcscOptions:ForceRelay/EnableRelayFallback/PreferRelayByDefaultare operator feature flags and ARE exposed; the per-feedAcscFeedOptionscollection is defined inline (not runtime-overlay-tunable; future sprint may extend the schema).EpssOptions:AirgapModeandBundlePathare exposed; theHttpTimeout/RequestTimeoutinternal-pacing primitives stay defaulted unless operator opts in.- Distro / vendor connectors (
AlpineOptions,DebianOptions, etc.):RequestDelay/FailureBackoff/MaxDocumentsPerFetchare internal pacing constants, optionally exposed at the connector author’s discretion.
Per-connector decisions are documented in each connector’s *ConfigurationContributor.cs descriptor (the descriptor is the source of truth — anything not listed there is not operator-tunable, by definition).
Follow-up sprint candidates
Architecture-conformance test (deferred from Sprint 20260504-001 risk register): add a small reflection-driven test next to
DeterminismCallSiteConformanceTeststhat asserts every connector library’s primaryIFeedConnectorimplementation acceptsIOptionsMonitor<TOptions>(or equivalent runtime-aware path), notIOptions<TOptions>. Prevents regression of the runtime-overlay sweep.No-direct-connector triage: for each row with no direct connector, decide:
- Remove from
SourceDefinitions(no connector planned). - Open a connector-authoring sprint.
- Mark as deprecated alias (e.g.,
rhel→redhat).
- Remove from
Excititor unification (sprint 012): the three stub entries (
csaf,csaf-tc,vex) are resolved by the federated catalog model.
