Concelier Connectors

This index is the authoritative operator-facing inventory for the Concelier advisory source catalog and the linked Excititor VEX provider control plane.

Current control-plane counts

Operator entry points:

Bulk operator actions:

Related docs:

Readiness model

Advisory sources and VEX providers preserve operator intent separately from runtime readiness.

Advisory sources return:

Excititor VEX providers return:

Interpretation:

Canonical runtime note:

Advisory source inventory

Legend:

CategoryIDDisplay nameDefault enabledRequires authBuilt-in runnableStored config
CertauscertASD ACSC (Australia)truefalseyesUI+CLI
CertcccsCCCS (Canada)truefalseyesUI+CLI
Certcert-atCERT.at (Austria)truefalseyesUI+CLI
Certcert-beCERT.be (Belgium)truefalseyesUI+CLI
Certcert-ccCERT/CCtruefalseyesUI+CLI
Certcert-chNCSC-CH (Switzerland)truefalsenonone
Certcert-deCERT-Bund (Germany)truefalseyesUI+CLI
Certcert-euCERT-EUtruefalseyesUI+CLI
Certcert-frCERT-FRtruefalseyesUI+CLI
Certcert-inCERT-In (India)falsefalseyesUI+CLI
Certcert-plCERT.PL (Poland)falsefalseyesUI+CLI
Certcert-uaCERT-UA (Ukraine)falsefalseyesUI+CLI
Certfstec-bduFSTEC BDU (Russia)falsefalseyesUI+CLI
CertjpcertJPCERT/CC (Japan)truefalseyesUI+CLI
CertkrcertKrCERT/CC (South Korea)truefalseyesUI+CLI
CertnkckiNKCKI (Russia)falsefalseyesUI+CLI
Certus-certCISA (US-CERT)truefalseyesUI+CLI
ContainerchainguardChainguard Advisoriesfalsefalsenonone
DistributionalpineAlpine SecuritytruefalseyesUI+CLI
DistributionamazonAmazon Linux SecuritytruefalseyesUI+CLI
DistributionarchArch SecuritytruefalseyesUI+CLI
DistributionastraAstra Linux SecurityfalsefalseyesUI+CLI
DistributioncentosCentOS Securitytruefalsenonone
DistributiondebianDebian SecuritytruefalseyesUI+CLI
DistributionfedoraFedora SecuritytruefalseyesUI+CLI
DistributiongentooGentoo SecuritytruefalseyesUI+CLI
DistributionrhelRHEL Securitytruefalsenonone
DistributionsuseSUSE SecuritytruefalseyesUI+CLI
DistributionubuntuUbuntu SecuritytruefalseyesUI+CLI
DistributionwolfiWolfi Securityfalsefalsenonone
EcosystemcratesCrates.io Advisoriesfalsefalsenonone
EcosystemgoGo Advisoriesfalsefalsenonone
EcosystemhexHex.pm Advisoriesfalsefalsenonone
EcosystemmavenMaven Advisoriesfalsefalsenonone
Ecosystemnpmnpm Advisoriesfalsefalsenonone
EcosystemnugetNuGet Advisoriesfalsefalsenonone
EcosystempackagistPackagist Advisoriesfalsefalsenonone
EcosystempypiPyPI Advisoriesfalsefalsenonone
EcosystemrubygemsRubyGems Advisoriesfalsefalsenonone
ExploitexploitdbExploit-DBfalsefalseyesUI+CLI
ExploitmetasploitMetasploit ModulesfalsefalseyesUI+CLI
HardwareamdAMD SecurityfalsefalseyesUI+CLI
HardwareintelIntel PSIRTfalsefalseyesUI+CLI
Icskaspersky-icsKaspersky ICS-CERTfalsefalseyesUI+CLI
IcssiemensSiemens ProductCERTfalsefalseyesUI+CLI
Mirrorstella-mirrorStellaOps Mirror (downstream relay)falsefalseyesUI+CLI
PackageManagerbundler-auditRuby Advisory DBfalsefalsenonone
PackageManagergovulnGo Vuln DBfalsefalsenonone
PackageManagerpypaPyPA Advisory DBfalsefalsenonone
PackageManagerrustsecRustSec Advisory DBfalsefalsenonone
PrimarycveCVE.org (MITRE)truefalseyesUI+CLI
PrimaryghsaGitHub Security AdvisoriestruefalseyesUI+CLI
PrimarynvdNVD (NIST)truefalseyesUI+CLI
PrimaryosvOSV (Google)truefalseyesUI+CLI
ThreatepssEPSS (FIRST)truefalseyesUI+CLI
ThreatkevCISA KEVtruefalseyesUI+CLI
VendoradobeAdobe SecuritytruefalseyesUI+CLI
VendorappleApple SecuritytruefalseyesUI+CLI
VendorawsAWS Security BulletinstruefalseyesUI+CLI
VendorazureAzure Security Advisoriestruefalsenonone
VendorchromiumChromium SecuritytruefalseyesUI+CLI
VendorciscoCisco SecuritytruetrueyesUI+CLI
VendorfortinetFortinet PSIRTtruefalseyesUI+CLI
VendorgcpGCP Security BulletinstruefalseyesUI+CLI
VendorgoogleGoogle Securitytruefalsenonone
VendorjuniperJuniper Securitytruefalsenonone
VendormicrosoftMicrosoft SecuritytruetrueyesUI+CLI
VendororacleOracle SecuritytruefalseyesUI+CLI
VendorpaloaltoPalo Alto SecuritytruefalseyesUI+CLI
VendorredhatRed Hat SecuritytruefalseyesUI+CLI
VendorvmwareVMware SecuritytruefalseyesUI+CLI

Unsupported/source-decision notes:

Stored advisory configuration coverage

Every advisory source marked Built-in runnable = yes is configurable through the Web setup/source-management page and the persisted /api/v1/advisory-sources/{id}/configuration API. The CLI’s stella config sources tree manages enablement, connectivity, and status; it does not currently expose connector field editing. Some connectors expose only endpoint, timeout, public-feed, or fixture/offline snapshot overrides; auth fields appear only where the connector needs credentials.

The runnable and configurable advisory sources are:

Policy-sensitive or regional sources such as fstec-bdu, nkcki, astra, kaspersky-ics, cert-in, cert-pl, cert-ua, amd, siemens, exploitdb, metasploit, and stella-mirror remain disabled by default. They are still visible in the setup UI so an operator can explicitly enable, configure, check, and sync them when local policy permits it.

Rows with Built-in runnable = no are either parent-covered aliases or catalog-visible unsupported sources. Parent-covered aliases (npm, pypi, go, maven, nuget, rhel, azure, and similar rows) are folded into the parent row in the setup UI as “Also covering …” notes. Unsupported rows such as centos, cert-ch, google, juniper, chainguard, and wolfi remain visible as catalog truth but cannot be enabled until a real fetch job is added.

Verification state for this inventory

Control-plane evidence reverified in Sprint 20260422_004:

This page does not claim that all 79 advisory connectors were end-to-end re-ingested in this sprint. It records catalog truth, built-in host wiring, stored configuration coverage, and the specific control-plane verification completed during this implementation slice.