feat(parity): stackiq's capability matrix against five competitors - #1072
Merged
Merged
Conversation
173 rows in 12 areas against five competitor columns, competitor cells from the intelligence database. Stackiq's own column is not read yet.
134 rated rows and 39 pending across 12 areas. Every own rating carries a path and a line, a reachedOn and, on sibling rows, the owning repo.
Contributor
Quality Report — ConductionNL/stackiq @
|
| Check | PHP | Vue | Security | License | Tests |
|---|---|---|---|---|---|
| lint | ✅ | ||||
| phpcs | ✅ | ||||
| phpmd | ✅ | ||||
| psalm | ✅ | ||||
| phpstan | ✅ | ||||
| phpmetrics | ✅ | ||||
| eslint | ✅ | ||||
| stylelint | ✅ | ||||
| build | ✅ | ||||
| check-manifest | ✅ | ||||
| check-vue-demi | ✅ | ||||
| test-l10n | ✅ | ||||
| format | ✅ | ||||
| check-schema-l10n | ✅ | ||||
| check-l10n-js | ✅ | ||||
| composer | ✅ | ✅ 130/130 | |||
| npm | ✅ | ✅ 807/807 | |||
| app:check-code | ⏭️ | ||||
| info.xml | ✅ | ||||
| REUSE | ❌ | ||||
| lockfile sync | ✅ | ||||
| PHPUnit | ⏭️ not run for this diff — no file in this diff matches the code globs, and none carries a source extension — the heavy tier has nothing to decide about it. | ||||
| Newman | ⏭️ | ||||
| Playwright | ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test. |
||||
| Hydra gates | ❌ |
Quality workflow — 2026-09-25 18:44 UTC
Download the full PDF report from the workflow artifacts.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
openspec/parity/capabilities.json, stackiq's capability matrix. Data file only, no page wired. Read from development atc9760e07454e8ae6d4e87d52ce31daa5c04492c8.Two security-shaped findings (code reading, needs a live check)
moduleread rule includes{group: public, match: {registeredBy: Supplier, status: Active}}next to the publication-date rule (lib/Settings/softwarecatalogus_register.json:2501). If OpenRegister applies the rules as an OR, any active module a supplier registered is public, whatever itspublicationDate.POST /api/archimate/test-round-tripis@NoAdminRequiredand@NoCSRFRequired, and it writes to the live register. It imports a test model into the live AMEF register. It can also never pass: it compares animported_countnothing sets against the literal string'calculated_in_export_service'.Live-defect candidates (code reading)
ArchiMateService::cancelArchiMateImport(), which does not exist. The resulting\Erroris not caught by the surroundingcatch (\Exception).x-openregister-notificationsrule filters on statusActief, while the enum isActive/Expired/In negotiation.conceptwhile the values are Draft / Active / Inactive. Its accept button also writesactief.FederationService::fetchPeerCatalog()passes aurlthat OpenCatalogi'sgetDirectoryignores.openapi.jsonhas 0 paths.email, which thecontactPersonschema no longer has.Backends no page reaches, and pages nothing opens
connectionandusageschemas have no page at all. So no stackiq page can register a koppeling or create the usage a contract requires.src/views/FacetedCatalogIndexView.vue:108has no row click). SuiteDetail cannot be opened from Suites, nor KwetsbaarheidDetail from Vulnerabilities.Settings.vueandStackiqSettingsPageare built but never mounted.src/:api/aanbod,api/aangeboden-gebruik,api/koppelingen-gebruik,api/gebruik,api/intake,api/preferences,api/dashboard,api/setup. Moderation and eol-sync are reached, from admin settings.reachedOnsays "external frontend, not in this repo" or "API only". The pending rows that depend on that frontend name it in their question.Judgement calls
Category. Stackiq does two jobs in one product. It is the back office and API of the successor to the VNG GEMMA Softwarecatalogus: suppliers publish what they offer, and municipalities record what they use and how it connects, all plotted on GEMMA. It is also a portfolio view for one organisation: contracts, lifecycle, licences, vulnerabilities and compliance. So it competes first with the VNG catalogue, second with application portfolio and EA tools, and third with CMDB and IT asset tools. The paragraph sits in the file's
categoryfield, so correct it there.Columns. Five competitors:
The other 66 linked competitors stay out. They are developer portals, enterprise-priced asset and licence tools, duplicate EA tools, discovery and hardware tools, or noise such as Atlas Governance, Kong, Gravitee, Apigee and Sensus BPM. The reasons are in
columnsWhy.Areas. 12 areas of 9 to 20 rows. The operations area (discovery, tickets, change, SLA) exists on purpose. It records what a catalogue does not do, and most of its rows honestly rate
no.What the research held (tagging checked in both directions)
stackiq,softwarecatalog,softwarecatalogus). Only a command reference, a scorecard line and a SOURCES line about the GEMMA import. The richest requirement source is the product's ownissues.md: 160 VNG issues with acceptance criteria.competitor_appslinks 71 competitors tosoftwarecatalog. The 153 taggedcompetitor_featuresare 12 competitors × 12 to 15 rows, all from one docs pass on 2026-07-23. Of the 250canonical_features, 144 are uncategorised release-note slugs and about 29 are stackiq's own specs tagged back in.procest; those come from a GLPI source reading on 2026-09-14, and they are cited here for general features.gemma_*tables hold 254 components and 422 services and were used for vocabulary only.Every competitor is graded
docs-only, withreadOn2026-07-23 and a system-levelunknownReason. Nobody drove any of them.Rows and split
173 rows: 134 rated, 39 pending.
no.On sibling rows,
built.ownernames the repo that holds the logic: 20 openregister, 2 decidiq, 2 integriq, 2 opencatalogi and 1 portaliq.Claimed differentiators nobody has checked
These 18 rows rate stackiq
yeswhile every competitor readsunknown. They are the next pass's work:Verify
python3 parity_verify.py openspec/parity/capabilities.json(hydra development):With
--strictit exits 1, and the only finding is the unknown census. The strict-profile counts are all zero: system-without-grade 0, grade-not-in-enum 0, cell-without-evidence 0, own-rating-without-evidence 0, unknown-without-reason 0.Not run
A JSON file under
openspec/cannot affect stackiq's suites, so I did not run PHPUnit,check:strict, lint or Playwright.