StellaOps.Vulnerabilities
The vulnerability knowledge hub: one microservice, one database (stellaops_vuln), holding tenant-free raw + normalized vulnerability / VEX / distro knowledge for the platform. It consolidates Concelier (incl. Feedser + Excititor) + VexHub per ADR-039.
- architecture.md — the module dossier: what is built in
src/Vulnerabilities/, the data model and its identity rules, the reconciliation protocol, the served surface, the corpus artifact, and the reference boundaries. - connectors-architecture.md — connector tiers, removals, plugin contract.
- vulnerability-data-plane-v2-design.md — target design, ERD, capacity budget, desk-check scenarios, build/cutover plan.
Which dossier describes production today? This one. The hub has owned live vulnerability-plane traffic since the completed SPRINT_20260722_008 G1 cutover on 2026-08-04. The old schemas and services are stopped/dropped and the VexHub/VexLens trees are retired. Remaining src/Concelier/ source is compile-only transition debt for named consumers; it is not a live authority.
Program sprints: docs/implplan/SPRINT_20260722_*.
