Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

feat(policies): predefined compliance packs — CIS, HIPAA, PCI, NIST and more, out of the box

Aperta
#331 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
35/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
python, terraform
Ambito
devops, security

Direzione di ricerca

Inizia dal manifest del pack e dal lavoro correlato su policy-packs e interoperability-packs, quindi esamina il set di policy Terraform esistente e i tag compliance-framework. Esegui il flusso tirith --pack cis -input-path plan.json e i fixture di tirith test. Il lavoro è completo quando CIS funziona end-to-end con metadati di framework/severity, è presente una dichiarazione onesta sulla copertura e i fixture di esempio si attivano.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

enhancement

Ship thousands of predefined checks grouped by compliance framework, so tirith --pack cis -input-path plan.json covers a benchmark without the user writing anything. Terraform first, then
the other document kinds (CloudFormation, ARM, Kubernetes).

Source. A large verified translation set already exists internally (~2,700 policies translated
from public check libraries, each verified to pass a compliant and fail a violating document), and
the upstream checks carry compliance-framework tags — so framework packs are largely a regrouping
of that set, not new authoring. CIS ships first (the richest and best-structured tag set); PCI and
NIST follow; HIPAA and GDPR need an explicit mapping pass, since upstream tagging is sparser there.

Mechanics. Delivered through the pack manifest ("policy packs" issue) with meta.compliance
tags and meta.severity so --fail-on-severity gates them; deduplicated by
(resource type, attribute path) across source libraries (see the interoperability-packs issue);
coverage claims exclude never-firing stubs — a framework pack must state how many of the
benchmark's requirements it actually gates, not how many rows it contains.

Acceptance. tirith --pack cis -input-path plan.json runs a CIS pack end to end with per-policy
framework/severity metadata in every output format; each pack publishes an honest coverage
statement (requirements gated / requirements total); tirith test fixtures prove a sample of each
pack fires.

Lingua principale
Python
Stelle
167
Fork
47
Merge medio
1g 21h
PR unite (30g)
7

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di StackGuardian/tirith

Tutte le issue di StackGuardian/tirith

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.