Skip to content

feat: add cybersecurity engineering package - #8

Merged
joey-huckabee merged 3 commits into
mainfrom
feat/package-5-cybersecurity
Sep 12, 2026
Merged

joey-huckabee merged 3 commits into
mainfrom
feat/package-5-cybersecurity

Conversation

@joey-huckabee

Copy link
Copy Markdown
Contributor

Summary

  • add authoritative source register and schema-validated OSCAL component definition with deterministic SCTM/human views
  • add architecture, threat model, cryptographic boundary, vulnerability/exception, incident, and inherited-responsibility documentation
  • add native amd64/arm64 report-only SCAP discovery over never-executed owner-preserving exports
  • record crypto linkage evidence and enforce official OSCAL schema validation in CI

Claims boundary

  • no system authorization, compliance, STIG certification, or FIPS claim
  • all initial control classifications remain pending independent review
  • SCAP findings remain report-only; scanner and evidence errors are blocking

Validation

  • official OSCAL 1.2.3 component schema validation
  • 19 unit tests
  • pre-commit (JSON/YAML, actionlint, shellcheck, hadolint, formatting)
  • private vulnerability reporting API returned enabled

@joey-huckabee
joey-huckabee merged commit 8a6e60c into main Sep 12, 2026
9 checks passed
@joey-huckabee
joey-huckabee deleted the feat/package-5-cybersecurity branch September 12, 2026 13:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant