feat(policies): predefined compliance packs — CIS, HIPAA, PCI, NIST and more, out of the box
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 35/100
调研方向
先从 pack manifest 以及相关的 policy-packs 和 interoperability-packs 工作开始,然后检查现有的 Terraform policy set 和 compliance-framework 标签。运行 tirith --pack cis -input-path plan.json 流程和 tirith test fixtures。完成的标准是 CIS 能够携带 framework/severity 元数据端到端运行,有一份诚实的覆盖范围说明,并且示例 fixtures 能够触发。
由索引模型根据 Issue 内容生成。
描述
Ship thousands of predefined checks grouped by compliance framework, so tirith --pack cis -input-path plan.json covers a benchmark without the user writing anything. Terraform first, then
the other document kinds (CloudFormation, ARM, Kubernetes).
Source. A large verified translation set already exists internally (~2,700 policies translated
from public check libraries, each verified to pass a compliant and fail a violating document), and
the upstream checks carry compliance-framework tags — so framework packs are largely a regrouping
of that set, not new authoring. CIS ships first (the richest and best-structured tag set); PCI and
NIST follow; HIPAA and GDPR need an explicit mapping pass, since upstream tagging is sparser there.
Mechanics. Delivered through the pack manifest ("policy packs" issue) with meta.compliance
tags and meta.severity so --fail-on-severity gates them; deduplicated by
(resource type, attribute path) across source libraries (see the interoperability-packs issue);
coverage claims exclude never-firing stubs — a framework pack must state how many of the
benchmark's requirements it actually gates, not how many rows it contains.
Acceptance. tirith --pack cis -input-path plan.json runs a CIS pack end to end with per-policy
framework/severity metadata in every output format; each pack publishes an honest coverage
statement (requirements gated / requirements total); tirith test fixtures prove a sample of each
pack fires.
- 主要语言
- Python
- 星标
- 167
- 派生
- 47
- 平均合并
- 1 天 21 小时
- 30 天内合并 PR
- 7
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
StackGuardian/tirith 的其他 Issue
-
test(evaluators): edge cases for the numeric comparison evaluators可能已有人在做 @sricharanreddycheruku 于 1 天前认领。 未关闭good first issue hacktoberfest tests
难度 2/5 1-3 小时 新手友好度 84/100
StackGuardian/tirith#381 · 3 条评论 ·
维护者通常 1 天内回复
-
research
难度 1/5 1-3 小时 新手友好度 78/100
StackGuardian/tirith#356 ·
维护者通常 1 天内回复
-
documentation
难度 2/5 1-3 小时 新手友好度 76/100
StackGuardian/tirith#302 ·
维护者通常 1 天内回复
-
enhancement
难度 2/5 1-3 小时 新手友好度 74/100
StackGuardian/tirith#299 ·
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 85/100
StackGuardian/tirith#295 ·
维护者通常 1 天内回复
查看 StackGuardian/tirith 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 70/100
NVIDIA/earth2studio#1241 ·
维护者通常 3 天内回复
-
docs(types): update the collection binding note now that typed collections shipped in pycubrid 1.9.0未关闭documentation priority: low size: S
难度 2/5 1-3 小时 新手友好度 75/100
cubrid-lab/sqlalchemy-cubrid#768 ·
维护者通常 1 天内回复
-
bug help wanted
难度 2/5 1-3 小时 新手友好度 75/100
维护者通常 1 天内回复
-
documentation
难度 1/5 1 小时以内 新手友好度 65/100
ansys/pydpf-core#3547 ·
维护者通常 1 天内回复
-
good first issue
难度 2/5 1-3 小时 新手友好度 78/100
OktoLabsAI/okto-pulse#114 ·
维护者通常 1 天内回复