Skip to content

Feature: Support signed connected and air-gapped intelligence bundles #301

Description

@JustNZ

Release

Release 1 — Living CVE intelligence

Goal

Use the same verified intelligence artifact for connected and fully offline installations.

Scope

  • Define a versioned bundle manifest covering CVE/NVD, KEV, EPSS, schema version, timestamps, and checksums.
  • Sign bundles and verify them before activation.
  • Support scheduled connected download plus CLI and admin-UI offline import.
  • Retain active and previous bundle versions for rollback.
  • Expose freshness, signature, source coverage, import history, and failure health.

Acceptance criteria

  • Tampered, expired, unknown-key, and replayed bundles are rejected safely.
  • Failed imports leave the last verified bundle active.
  • Online and offline imports produce identical normalized records.
  • Feed age can be enforced by organization policy.
  • The offline procedure requires no runtime internet access.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions