Eclipse SCINTX (Supply Chain Intelligence Exchange)

Scope

Eclipse SCINTX (Supply Chain Intelligence Exchange) defines a vendor-neutral interchange layer between package registries (and CI/feed bridges) and security providers that normalizes provider output into a common verdict model, applies consumer policy, and emits a signed CloudEvents lifecycle.

In scope:

  • An interoperability model for package-security assessment: submission API, normalized finding/verdict vocabulary, provider interface, and policy decision model.
  • Normative artifacts: OpenAPI description, JSON Schemas, and documentation of the HTTP lifecycle (submit → process → poll / webhook → optional adjudication).
  • A reference gateway implementation (orchestration, durable store, optional cache, worker dispatch, signed webhooks).
  • Reference and example provider adapters and policy engines (extension model).
  • HTTP integration patterns for registries, CI, and external feed bridges (e.g. package-feeds → POST /v1/submissions).

Out of scope:

  • Operating a public package registry.
  • In-process registry pollers (prefer external feeds posting submissions).
  • Replacing or competing with security scanners — the project integrates scanners.
     
Releases
Name Date
Reviews
Name Date
Creation Review 2026-09-09