Scope
<p>Eclipse SCINTX (Supply Chain Intelligence Exchange) defines a vendor-neutral interchange layer between package registries (and CI/feed bridges) and security providers that normalizes provider output into a common verdict model, applies consumer policy, and emits a signed CloudEvents lifecycle.</p><p>In scope:</p><ul><li data-list-item-id="e7b2c5f711f6f6e1c4e52f55dced047f4">An interoperability model for package-security assessment: submission API, normalized finding/verdict vocabulary, provider interface, and policy decision model.</li><li data-list-item-id="eaeec392cf766eff4fe7f0625a5552bf2">Normative artifacts: OpenAPI description, JSON Schemas, and documentation of the HTTP lifecycle (submit → process → poll / webhook → optional adjudication).</li><li data-list-item-id="e95e3a1f628a16057c13f9f7d553cc740">A reference gateway implementation (orchestration, durable store, optional cache, worker dispatch, signed webhooks).</li><li data-list-item-id="ef6b82fd56c955d744be9a6bba2d96f3a">Reference and example provider adapters and policy engines (extension model).</li><li data-list-item-id="ed65fc89ce9c6dde797db520e1f56ccf4">HTTP integration patterns for registries, CI, and external feed bridges (e.g. package-feeds → POST /v1/submissions).</li></ul><p>Out of scope:</p><ul><li data-list-item-id="efe19af5e906de531f69e4c629923ecdc">Operating a public package registry.</li><li data-list-item-id="edbfb690f97fa72c66fdd89e06c380c09">In-process registry pollers (prefer external feeds posting submissions).</li><li data-list-item-id="ec32f7c2f282743e6cc4e552af085e4d2">Replacing or competing with security scanners — the project integrates scanners.<br> </li></ul>