Block a user
STORY · Externalize findings/SBOM/CVE as API + MCP to platform services
STORY · RBAC for onboarding + scanner data (breakpilot-platform RBAC)
STORY · Next.js onboarding app in breakpilot-platform (replace Dioxus)
STORY · Nightly agent regression against the demo targets
Epic · Certifai → breakpilot-platform integration (post-#183)
STORY · Demo target fixtures — curated representative targets
docs(plc): PLC Runtime Landscape reference + support watch-list
ONB · Bitbake/Yocto detection (our classifier) + Yocto-native SPDX/cve-check ingest (no tramiton dep)
Re-scope: own the Yocto path here, not in tramiton (decision 2026-07-17)
Verified against tramiton v0.4.1 (the tag pinned in compliance-agent/Cargo.toml): its providers are `platformio,…
ONB · CODESYS-on-Yocto customer: end-to-end SBOM/SAST/DAST/pentest coverage tracker
Current-state audit (2026-07-17) — frame is in place, engine is not
Traced the Yocto/firmware path in code. The scaffolding exists but nothing behind it processes a real Yocto artifact,…
docs(plc): soft-PLC architecture + CODESYS/Yocto lifecycle diagram
sharang
created branch docs/plc-runtimes in sharang/compliance-scanner-agent
2026-07-16 21:59:47 +00:00
docs(plc): PLC Runtime Landscape reference + support watch-list
sharang
pushed to docs/plc-soft-plc-architecture at sharang/compliance-scanner-agent
2026-07-16 21:52:50 +00:00
sharang
created branch docs/plc-soft-plc-architecture in sharang/compliance-scanner-agent
2026-07-16 21:52:50 +00:00
docs(plc): soft-PLC architecture + CODESYS/Yocto lifecycle diagram
Epic: Dynamic PLC testing via ephemeral soft-PLC (deploy control logic → ICS + DAST)
Licensing decision + procurement open questions (from cost review)
Decision — evaluate on the free tier only (for now)
We are not selling this as a SaaS yet, so all dynamic-PLC work…