Metadata-Version: 2.4
Name: dcs-conformance
Version: 1.0.0
Summary: Belnap-folded conformance: OSCAL + in-toto bundles from any source
Author-email: Danny <danny@dannylabs.example>
License-Expression: Apache-2.0
Project-URL: Homepage, https://github.com/Danny-TMIG/enterprise-aiops
Project-URL: Repository, https://github.com/Danny-TMIG/enterprise-aiops
Project-URL: Issues, https://github.com/Danny-TMIG/enterprise-aiops/issues
Keywords: compliance,conformance,oscal,in-toto,sigstore,belnap,paraconsistent,audit,soc2,fedramp
Classifier: Development Status :: 4 - Beta
Classifier: Intended Audience :: Developers
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Topic :: Software Development :: Quality Assurance
Classifier: Topic :: Security
Requires-Python: >=3.11
Description-Content-Type: text/markdown
License-File: LICENSE
Provides-Extra: aws
Requires-Dist: boto3>=1.28; extra == "aws"
Provides-Extra: oscap
Requires-Dist: xmltodict>=0.13; extra == "oscap"
Provides-Extra: crypto
Requires-Dist: cryptography>=41; extra == "crypto"
Provides-Extra: dev
Requires-Dist: ruff>=0.6; extra == "dev"
Requires-Dist: mypy>=1.10; extra == "dev"
Requires-Dist: pytest>=7.4; extra == "dev"
Requires-Dist: pytest-cov>=5; extra == "dev"
Requires-Dist: cryptography>=41; extra == "dev"
Requires-Dist: boto3>=1.28; extra == "dev"
Dynamic: license-file

# dcs-conformance

Belnap-folded conformance for the modern compliance stack.

Binary tools answer pass/fail. When two of them disagree — GitHub says
yes, AWS says no, an auditor says "partial" — they have no state for it.
`dcs` does.

## Install

    pip install dcs-conformance

Optional extras:

    pip install 'dcs-conformance[aws]'      # boto3 connector
    pip install 'dcs-conformance[oscap]'    # OpenSCAP ARF parsing
    pip install 'dcs-conformance[crypto]'   # Ed25519 signing

## Quickstart

    dcs keygen          # generate dcs/key.hex (Ed25519, gitignored)
    dcs self            # fold local tests x external sources

Every run writes three files:

- self-<ts>.json         primary signed bundle
- self-<ts>.oscal.json   OSCAL 1.1.2 Assessment Results
- self-<ts>.intoto.json  in-toto v1 Statement in a DSSE envelope

## Verify

    dcs verify-intoto dcs/evidence/self-<ts>.intoto.json
    # OK: 1 valid signature(s)

Or against an externally supplied public key:

    dcs verify-intoto envelope.json --pubkey $(cat dcs/key.pub.hex)

## The Belnap fold

Each requirement gets attestations from multiple sources. They fold
via meet over Belnap FOUR:

| sources              | folded |
|----------------------|--------|
| local=T, github=T    | T      |
| local=T, aws=F       | B      |
| local=T, github=U    | T      |
| all=F                | F      |

CONFLICT is a first-class state. A binary tool would have printed one
of the inputs and dropped the disagreement.

## Connectors

Sovereign plugins. Missing tool or missing env var yields U; the
verdict narrows but never breaks.

- github      README, workflows, default branch
- aws         S3 encryption, CloudTrail multi-region, IAM password policy
- oscap       OpenSCAP ARF XML
- kube_bench  CIS Kubernetes Benchmark
- kyverno     Kyverno PolicyReport CRDs
- prowler     Prowler OCSF findings

## Interoperability

- OSCAL       consumed by compliance-trestle, trestle-cli, FedRAMP tooling
- in-toto     consumed by cosign, Rekor, policy-controller
- Ed25519     verifiable with only key.pub.hex

## License

Apache-2.0
