slug: anaconda provider: Anaconda generated_by: planning/capability-mapping/scripts/classify_capabilities.py model: claude-opus-5 frame: - Software & Technology min_confidence: 0.7 capability_model: source: https://github.com/vincentmakes/turbo-ea-capabilities license: CC-BY-4.0 attribution: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 notice: NOTICE edge_count: 4 edges: - tag: CVEs spec_file: anaconda-cves-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.82 evidence: '"Get all the CVE''s associated with this channel"; "Get artifact CVE details"; schemas CVEsBySeverity, CVEPackage, CVE_status' reason: The operations enumerate CVEs by channel, subchannel and artifact, expose severity breakdowns, affected package files and CVE notification history — vulnerability identification and tracking across hosted packages, which is Vulnerability Management. - tag: Users spec_file: anaconda-users-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: openapi description "User role management endpoints"; PUT /users/{user_id} "Admin Only! Edit the individual user role by user id"; POST /users/{user_id}/tokens "Create a new user token by admin user"; schemas AuthRolePermissions, UserScopeToken reason: Explicitly user role and API-token/credential administration with scoped permissions — identity and access management for the platform. - tag: Account spec_file: anaconda-account-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: '"This allows a non-user to create an user"; "Create a new user token"; "Get the user permission level" with schemas UserTokenPermissionResourceItem, UserPermission' reason: Operations cover user account registration/unregistration, account edit/delete, and issuance, scoping and update of user API tokens with permissions — i.e. identity and credential/access administration for the repository platform. Some chance a grader would treat it as developer credential management instead, so 0.75. - tag: Groups spec_file: anaconda-groups-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.72 evidence: PUT /channels/{channel_name}/groups/{group_id} — "Update group channel permission"; schemas ChannelGroupPermissions, Group, GroupRequest reason: Operations create groups and grant/revoke their permissions on repository channels and subchannels — group-based access control, i.e. identity & access management plumbing rather than any line-of-business capability.