feat(policies): predefined compliance packs — CIS, HIPAA, PCI, NIST and more, out of the box
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
Hướng nghiên cứu
Bắt đầu với manifest của pack và phần công việc liên quan đến policy-packs và interoperability-packs, sau đó kiểm tra bộ policy Terraform hiện có và các tag compliance-framework. Chạy flow tirith --pack cis -input-path plan.json và các fixture của tirith test. Được xem là hoàn tất khi CIS hoạt động end-to-end với metadata framework/severity, có một tuyên bố trung thực về phạm vi bao phủ và các fixture mẫu được kích hoạt.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Ship thousands of predefined checks grouped by compliance framework, so tirith --pack cis -input-path plan.json covers a benchmark without the user writing anything. Terraform first, then
the other document kinds (CloudFormation, ARM, Kubernetes).
Source. A large verified translation set already exists internally (~2,700 policies translated
from public check libraries, each verified to pass a compliant and fail a violating document), and
the upstream checks carry compliance-framework tags — so framework packs are largely a regrouping
of that set, not new authoring. CIS ships first (the richest and best-structured tag set); PCI and
NIST follow; HIPAA and GDPR need an explicit mapping pass, since upstream tagging is sparser there.
Mechanics. Delivered through the pack manifest ("policy packs" issue) with meta.compliance
tags and meta.severity so --fail-on-severity gates them; deduplicated by
(resource type, attribute path) across source libraries (see the interoperability-packs issue);
coverage claims exclude never-firing stubs — a framework pack must state how many of the
benchmark's requirements it actually gates, not how many rows it contains.
Acceptance. tirith --pack cis -input-path plan.json runs a CIS pack end to end with per-policy
framework/severity metadata in every output format; each pack publishes an honest coverage
statement (requirements gated / requirements total); tirith test fixtures prove a sample of each
pack fires.
- Ngôn ngữ chính
- Python
- Star
- 167
- Fork
- 47
- Merge trung bình
- 1 ngày 21 giờ
- Pull request đã merge (30 ngày)
- 7
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của StackGuardian/tirith
-
test(evaluators): edge cases for the numeric comparison evaluatorsCó thể đã có người làm @shrinidhi1402 đã nhận 5 ngày trước. Đang mởgood first issue hacktoberfest tests
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
StackGuardian/tirith#381 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
research
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 78/100
StackGuardian/tirith#356 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
documentation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
StackGuardian/tirith#302 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
StackGuardian/tirith#299 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
fix(providers): dotted keys are addressable from terraform_plan but not from json/kubernetesĐang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
StackGuardian/tirith#295 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của StackGuardian/tirith
Issue tương tự
-
Link Checker ReportĐang mởautomated issue report
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
RapidAI/RapidOCRDocs#119 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
btclib-org/btclib-node#1833 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
IRIS reader: no-data velocity bins (DB_VEL, DB_VELC) returned as 0.0 m/s instead of NaNCó thể đã có người làm @syedhamidali đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 80/100
elodin-sys/elodin#890 ·
Maintainer thường phản hồi trong vòng 1 ngày