Public Access
2.2 KiB
2.2 KiB
Charybdis - TODO List
Last Updated: 2026-05-06 Status: Phase 0 done. Phase 1 (Security Core) in progress — assessment & gates remaining.
Aligned with VISION.md roadmap.
Phase 1: Security Core (In Progress)
Goal: Native vulnerability management and scan ingestion. Replace DefectDojo for finding lifecycle management. Architecture: Core features (reconciliation, dedup, dry-run) in
src/. Parsers extensible viaScannerParsertrait. Plugins contribute parsers viacontributed_parsers().
Remaining
- CycloneDX VEX parser (vulnerability data from SBOMs)
Plugin::contributed_parsers()default impl on base trait- Publish events: FindingCreated, FindingResolved, FindingReopened (for downstream plugins)
- Assessment workflow (triage, accept risk, remediate)
- Rules engine for auto-assessment
- Security gates (severity thresholds per product)
- License tracking and policy engine
Phase 2: Compliance & Integrations
Goal: Compliance frameworks and integration plugins.
- Compliance framework mappings (NIS2, SOC2, DORA)
- VEX document support (CSAF, OpenVEX)
- Export/reporting (PDF, Excel)
- Notification plugins (Slack, Teams, email)
- Issue tracker plugins (Jira, GitHub, GitLab)
- Redis event bus backend (production)
Phase 3: Scaffolder & Ecosystem
Goal: Service scaffolding and community growth.
- Service scaffolder (Git-native templates, not Nunjucks)
- Event-driven provisioning on scaffold
- Plugin SDK documentation
- Helm chart & 1-click deploy
- Community plugin registry
Infrastructure & Quality
- Performance benchmarks (criterion)
- Dependency-Track plugin implementation (follow DefectDojo pattern)
Non-Goals (per VISION.md)
These will not be implemented:
REST API— gRPC only. Teams can add REST via grpc-gateway or Envoy.GraphQL API— Same. gRPC is the single API surface.Hot-swappable plugins— Plugins are compile-time integrated for type safety.Scanner execution— Charybdis ingests results, it doesn't run scanners.SIEM features— Not an incident response tool.