audit-labs/audit-report

Turn audit-tools evidence packages into control-mapped, auditor-ready reports. audit compliance evidence reporting https://audit-labs.dev/audit-report/

Commit 073020727e

073020727e5ddc574f63690de8e559a5e43d2794

parent: e4d13ff9dc

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-08 03:52 UTC

Release v1.0.0

Bump version to 1.0.0, add CHANGELOG, and document the stability commitment.

Layout: unified · split

CHANGELOG.md added +28
@@ -0,0 +1,28 @@
1# Changelog
2
3All notable changes to this project are documented here. The format is based on
4[Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres
5to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
6
7## [1.0.0] - 2026-08-07
8
9First stable release. The JSON report schema — findings carrying their `controls`
10and `pass` / `fail` / `not_applicable` status — is now a committed contract that
11[control-coverage](https://github.com/audit-labs/control-coverage) consumes
12directly; it will not change in a breaking way without a major-version bump.
13
14## [0.1.0] - 2026-08-06
15
16### Added
17
18- Control-mapped reports from an audit-tools evidence package: declarative YAML
19 rulesets map pass/fail results to SOC 2, ISO 27001, and NIST SP 800-53 controls.
20- Output as Markdown, self-contained HTML, or JSON; `--fail-on {low,medium,high,none}`
21 gate for CI.
22- Bundled rulesets for GitHub, GitLab, and AWS evidence.
23- Trend mode to diff two evidence packages.
24- Tool and ruleset provenance stamped into every report.
25- PyPI trusted-publishing release workflow.
26
27[1.0.0]: https://github.com/audit-labs/audit-report/releases/tag/v1.0.0
28[0.1.0]: https://github.com/audit-labs/audit-report/releases/tag/v0.1.0
README.md +8
@@ -167,6 +167,14 @@ The `--fail-on` exit code (`1` = a finding/regression met the threshold, `2` =
167167usage error) lets a workflow separate "the audit found a problem" from "the job
168168is misconfigured".
169169
170## Stability
171
172`audit-report` is stable as of **v1.0.0** and follows [semantic versioning](https://semver.org).
173The JSON report schema — findings carrying their `controls` and
174`pass` / `fail` / `not_applicable` status — is a committed contract that
175[control-coverage](https://github.com/audit-labs/control-coverage) consumes
176directly; it will not break without a major-version bump.
177
170178## Development
171179
172180```bash
audit_report/__init__.py +1 −1
@@ -1,3 +1,3 @@
11"""audit-report — turn audit-tools evidence packages into control-mapped reports."""
22
3__version__ = "0.1.0"
3__version__ = "1.0.0"
pyproject.toml +1 −1
@@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta"
44
55[project]
66name = "audit-report"
7version = "0.1.0"
7version = "1.0.0"
88description = "Turn audit-tools evidence packages into control-mapped, auditor-ready reports."
99readme = "README.md"
1010requires-python = ">=3.10"