Public Access
initial-commit
This commit is contained in:
@@ -0,0 +1,67 @@
|
||||
# Charybdis - TODO List
|
||||
|
||||
**Last Updated**: 2026-05-06
|
||||
**Status**: Phase 0 done. Phase 1 (Security Core) in progress — assessment & gates remaining.
|
||||
|
||||
> Aligned with [VISION.md](VISION.md) roadmap.
|
||||
|
||||
---
|
||||
|
||||
## Phase 1: Security Core (In Progress)
|
||||
|
||||
> **Goal**: Native vulnerability management and scan ingestion. Replace DefectDojo for finding lifecycle management.
|
||||
> **Architecture**: Core features (reconciliation, dedup, dry-run) in `src/`. Parsers extensible via `ScannerParser` trait. Plugins contribute parsers via `contributed_parsers()`.
|
||||
|
||||
### Remaining
|
||||
|
||||
- [ ] CycloneDX VEX parser (vulnerability data from SBOMs)
|
||||
- [ ] `Plugin::contributed_parsers()` default impl on base trait
|
||||
- [ ] Publish events: FindingCreated, FindingResolved, FindingReopened (for downstream plugins)
|
||||
- [ ] Assessment workflow (triage, accept risk, remediate)
|
||||
- [ ] Rules engine for auto-assessment
|
||||
- [ ] Security gates (severity thresholds per product)
|
||||
- [ ] License tracking and policy engine
|
||||
|
||||
---
|
||||
|
||||
## Phase 2: Compliance & Integrations
|
||||
|
||||
> **Goal**: Compliance frameworks and integration plugins.
|
||||
|
||||
- [ ] Compliance framework mappings (NIS2, SOC2, DORA)
|
||||
- [ ] VEX document support (CSAF, OpenVEX)
|
||||
- [ ] Export/reporting (PDF, Excel)
|
||||
- [ ] Notification plugins (Slack, Teams, email)
|
||||
- [ ] Issue tracker plugins (Jira, GitHub, GitLab)
|
||||
- [ ] Redis event bus backend (production)
|
||||
|
||||
---
|
||||
|
||||
## Phase 3: Scaffolder & Ecosystem
|
||||
|
||||
> **Goal**: Service scaffolding and community growth.
|
||||
|
||||
- [ ] Service scaffolder (Git-native templates, not Nunjucks)
|
||||
- [ ] Event-driven provisioning on scaffold
|
||||
- [ ] Plugin SDK documentation
|
||||
- [ ] Helm chart & 1-click deploy
|
||||
- [ ] Community plugin registry
|
||||
|
||||
---
|
||||
|
||||
## Infrastructure & Quality
|
||||
|
||||
- [ ] Performance benchmarks (criterion)
|
||||
- [ ] Dependency-Track plugin implementation (follow DefectDojo pattern)
|
||||
|
||||
---
|
||||
|
||||
## Non-Goals (per VISION.md)
|
||||
|
||||
These will **not** be implemented:
|
||||
|
||||
- ~~REST API~~ — gRPC only. Teams can add REST via grpc-gateway or Envoy.
|
||||
- ~~GraphQL API~~ — Same. gRPC is the single API surface.
|
||||
- ~~Hot-swappable plugins~~ — Plugins are compile-time integrated for type safety.
|
||||
- ~~Scanner execution~~ — Charybdis ingests results, it doesn't run scanners.
|
||||
- ~~SIEM features~~ — Not an incident response tool.
|
||||
Reference in New Issue
Block a user