Compact vulnerability DB segregation and replacement notice
Status: published and live-verified on 2026-07-16 after explicit operator direction to fully finish the remaining sprint work.
Corrected release 2026-07-15-corrected-gate-v1 was prepared on 2026-07-15 and published at:
https://mirrors.stella-ops.org/vuln-db/latest/- immutable path
https://mirrors.stella-ops.org/vuln-db/releases/2026-07-15-corrected-gate-v1/ - erratum
https://mirrors.stella-ops.org/vuln-db/ERRATUM.md - supersession record
https://mirrors.stella-ops.org/vuln-db/supersession.json
The immutable release digests are:
| Artifact | Bytes | SHA-256 |
|---|---|---|
vuln-db.sqlite | 107,761,664 | c4a46ae3c9c2972832f047940ffca85c2c230771bb347c354bb40f9d04b60f08 |
vuln-db.manifest.json | 24,320 | a7cd2c99b093ee3e21ecf843f9df3a0ed30e40d6c8c32d4db8d63f9384f1b188 |
vuln-db-sharealike.sqlite | 1,921,024 | d79fb7d5b8df94c0ab170f980a5f810dc7a0bb692969423a0b24fc2d465c84ae |
vuln-db-sharealike.manifest.json | 4,145 | 424debecbcfcd0c2cea2297275a47c4252a7f1848b6ec3a7b0b51e64f8be223d |
The core manifest reports EPSS, KEV, and reachability-sink capabilities present. The core has zero share-alike, commercial-restriction, no-derivatives, or no-redistribution source rows. The companion contains 176 CC-BY-SA Ubuntu advisories, 11,521 affected rows, and 176 record attributions. Both sidecar size/digest claims match the files, and the core sidecar pins the companion digest.
Why replacement is required
Compact vulnerability databases exported before the 2026-07-04 publication freeze used one undifferentiated vuln-db.sqlite. They predate the source-license segregation gate and the authoritative per-artifact capability/license manifests. The locally preserved releases also contain Ubuntu-attributed title text in that undifferentiated database. They must therefore be superseded by, not silently overwritten with, the current two-artifact export:
vuln-db.sqlite: license-cleared core facts;vuln-db-sharealike.sqlite: optional share-alike companion with per-record attribution;- one authoritative
*.manifest.jsonsidecar per artifact, plus the signed manifest evidence used by the publishing workflow.
This is a distribution and provenance correction. It does not assert that every vulnerability match in the older databases was incorrect.
Preserved pre-freeze inventory
The table is the local operator-drop inventory verified on 2026-07-14. The remote mirror was reconciled read-only on 2026-07-16 before publication: it contained only a flat 2026-07-01-v6 drop, whose three hashes exactly matched the preserved local copy. No additional remote versions were present.
| Version | Generated (UTC) | SQLite SHA-256 | Bundle SHA-256 | Classification |
|---|---|---|---|---|
2026-06-26-v4 | 2026-06-26 11:36 | 5bc2fb1b46731f1e629cb44cafe4f155d73011c4e47de0c6300ea5d08ce0bba4 | 4f3c57fa7a1a6f89df59c9b8e38e994eb50dd9898e49f887f5c3fbf212660124 | Supersede and correct: legacy undifferentiated artifact; 117 Ubuntu-attributed titled records. |
2026-06-30-v5 | 2026-06-30 06:02 | 5f357e7168b320db63c2db431c5c9627c32259182c702a552bc5276ed7e0ef92 | Not present in the preserved local drop | Supersede and correct: legacy undifferentiated artifact; 126 Ubuntu-attributed titled records. |
2026-07-01-v6 | 2026-07-01 11:30 | 4ddcd1d18ee4ccfcb82663d410d265769aa229d297714ec3d357df75a2ff621f | 2315a0758e600aa3360dbb66fde5485fec5826e39e613b26e44c9af4d19fa432 | Supersede and correct: legacy undifferentiated artifact; 126 Ubuntu-attributed titled records. |
2026-07-03 | 2026-07-03 13:56 | b3d79728bfe6898d9b47841765b2472a2ebf4325702387d7e6c747c3f740f51a | b04af9e1cfa66cb7d40004a6dc3e3f1dcb51c5e9e1a27a6d65ad9cf90dc3e55e | Supersede and correct: legacy undifferentiated artifact; 127 Ubuntu-attributed titled records. |
The corresponding preserved manifest.json SHA-256 values are, in version order: 147163c738856d0e084e6a65b9a7f08f3d8037c38a5a3403f17cd7dc9cbae6b4, 77771de4a948cfc962f3291e86be354ceb89d7deb0ac81339413fb4ca161afa6, adae5e03bcfc26a514d9698c5955404559ec941bcdc7f8461089b496780376d8, and cc24be5785bc9e429301cd644d2dce4d8b442930272bd168b2c5ca04a80b2f46.
Air-gapped operator replacement
- Preserve the installed database and its SHA-256 as audit evidence. Do not delete the old version until the replacement is verified.
- Obtain the replacement core database, its per-artifact manifest, signature evidence, and (when required by local policy) the share-alike companion from the corrected release.
- Verify the downloaded digest against the signed manifest using the normal offline trust roots.
- Inspect the manifest and confirm that
has_epss,has_kev, andhas_reachability_sinkstruthfully match the intended deployment. A reachability-enabled install must not accept an artifact whose manifest reports no sinks. - Replace the core database atomically at the configured
--vuln-dbpath. Store the companion as a separate artifact; never merge it into the core database. - Run one ordinary
stella sbom checkand, when reachability is enabled, onestella sbom check --reachability. The latter must fail loudly when the installed database lacks the declared reachability capability. - Record the old and new digests, verification result, replacement time, and operator identity in the installation change record.
Mirror erratum text
Publish this notice with the replacement checksums. The values below identify the validated local candidate; if the publisher creates a new immutable version, replace them with that output’s values:
Compact vulnerability DB releases dated 2026-06-26 through 2026-07-03 are superseded. Those releases used the legacy undifferentiated artifact format and did not carry the current per-artifact license/capability manifest. Replace them with
2026-07-15-corrected-gate-v1using core SHA-256c4a46ae3c9c2972832f047940ffca85c2c230771bb347c354bb40f9d04b60f08and, if required, companion SHA-256d79fb7d5b8df94c0ab170f980a5f810dc7a0bb692969423a0b24fc2d465c84ae. Existing files remain available only for audit continuity and must not be used as the mirrorlatesttarget.
No additional affected mirror versions were discovered. Old flat files remain byte-for-byte immutable; a versioned 2026-07-01-v6 audit copy was added, while supersession is expressed by the erratum, supersession.json, and the latest pointer.
Release gate — completed 2026-07-16
Publication occurred only after all of the following were verified:
- the remote mirror inventory is reconciled with the preserved local inventory;
- the fresh export contains separate core and companion artifacts with authoritative sidecars;
- the core leak query is clean and the manifest capability checks pass;
- replacement digests and erratum placeholders above are filled from the immutable output;
- the operator explicitly directed the remaining sprint work to be fully finished.
Post-publication verification returned HTTP 200 for the mirror index, erratum, supersession record, core manifest, and both immutable release paths. The public core response has content length 107,761,664, the manifest reports EPSS/KEV/reachability sinks present with go,rust, and server-side SHA-256 verification matches the four artifact/sidecar values above. The legacy flat manifest, SQLite, and bundle remain unchanged at adae5e03..., 4ddcd1d1..., and 2315a075... respectively.
