StellaOps.Vulnerabilities
The vulnerability knowledge hub: one microservice, one database (stellaops_vuln), holding tenant-free raw + normalized vulnerability / VEX / distro knowledge for the platform. It consolidates Concelier (incl. Feedser + Excititor) + VexHub per ADR-039.
- architecture.md — the module dossier: what is built in
src/Vulnerabilities/, the data model and its identity rules, the reconciliation protocol, the served surface, the corpus artifact, and the reference boundaries. - connectors-architecture.md — connector tiers, removals, plugin contract.
- vulnerability-data-plane-v2-design.md — target design, ERD, capacity budget, desk-check scenarios, build/cutover plan.
Which dossier describes production today? Not this one, yet. The hub is built but has not taken over: until the SPRINT_20260722_008 cutover, the live plane is still Concelier + VexHub, and docs/modules/concelier/architecture.mdis what an operator running the current stack should read. This module’s docs describe the successor. They swap roles at cutover, not before — which is also why the Concelier and VexHub dossiers are still full documents rather than stubs.
Program sprints: docs/implplan/SPRINT_20260722_*.
