Product registry
Every record in Vellaci connects back to a product: versions, SBOMs, components, vulnerabilities, incidents, CRA cases, evidence.
Versions
Versions are immutable release facts (version label, release date, support status, commit, branch). They are created manually, from GitHub/GitLab releases or tags, from CI uploads, or through the API.
Exposure context
Three optional fields feed the vulnerability priority model: criticality, internet exposed and customer exposure band. They never change legal severity — they change the order in which your team works.
Release security gate
Each version carries a gate status (pass / warn / blocked / approved). Findings: open critical or known-exploited vulnerabilities, unreviewed highs, missing SBOM, missing security owner, incomplete support information. The organisation policy decides whether blocking findings only warn or require an explicit, audited approval. The gate never blocks anything outside Vellaci.
Bulk operations
Select products to assign owners, change lifecycle or criticality and apply tags. Dangerous transitions ask for confirmation; every change is audited per record. CSV export respects the current filter.
Last updated . This page describes the current release.