Eclipse SCINTX (Supply Chain Intelligence Exchange) defines a vendor-neutral interchange layer between package registries (and CI/feed bridges) and security providers that normalizes provider output into a common verdict model, applies consumer policy, and emits a signed CloudEvents lifecycle.
In scope:
- An interoperability model for package-security assessment: submission API, normalized finding/verdict vocabulary, provider interface, and policy decision model.
- Normative artifacts: OpenAPI description, JSON Schemas, and documentation of the HTTP lifecycle (submit → process → poll / webhook → optional adjudication).
- A reference gateway implementation (orchestration, durable store, optional cache, worker dispatch, signed webhooks).
- Reference and example provider adapters and policy engines (extension model).
- HTTP integration patterns for registries, CI, and external feed bridges (e.g. package-feeds → POST /v1/submissions).
Out of scope:
- Operating a public package registry.
- In-process registry pollers (prefer external feeds posting submissions).
- Replacing or competing with security scanners — the project integrates scanners.
| Name | Date |
|---|
| Name | Date |
|---|---|
| Creation Review | 2026-09-09 |