Commit 073020727e
073020727e5ddc574f63690de8e559a5e43d2794
parent: e4d13ff9dc
Verified · cmc
cmc <hello@cleberg.net> · 2026-08-08 03:52 UTC
Release v1.0.0
Bump version to 1.0.0, add CHANGELOG, and document the stability commitment.
Layout: unified · split
CHANGELOG.md
added
+28
| @@ -0,0 +1,28 @@ |
| 1 | # Changelog |
| 2 | |
| 3 | All notable changes to this project are documented here. The format is based on |
| 4 | [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres |
| 5 | to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). |
| 6 | |
| 7 | ## [1.0.0] - 2026-08-07 |
| 8 | |
| 9 | First stable release. The JSON report schema — findings carrying their `controls` |
| 10 | and `pass` / `fail` / `not_applicable` status — is now a committed contract that |
| 11 | [control-coverage](https://github.com/audit-labs/control-coverage) consumes |
| 12 | directly; it will not change in a breaking way without a major-version bump. |
| 13 | |
| 14 | ## [0.1.0] - 2026-08-06 |
| 15 | |
| 16 | ### Added |
| 17 | |
| 18 | - Control-mapped reports from an audit-tools evidence package: declarative YAML |
| 19 | rulesets map pass/fail results to SOC 2, ISO 27001, and NIST SP 800-53 controls. |
| 20 | - Output as Markdown, self-contained HTML, or JSON; `--fail-on {low,medium,high,none}` |
| 21 | gate for CI. |
| 22 | - Bundled rulesets for GitHub, GitLab, and AWS evidence. |
| 23 | - Trend mode to diff two evidence packages. |
| 24 | - Tool and ruleset provenance stamped into every report. |
| 25 | - PyPI trusted-publishing release workflow. |
| 26 | |
| 27 | [1.0.0]: https://github.com/audit-labs/audit-report/releases/tag/v1.0.0 |
| 28 | [0.1.0]: https://github.com/audit-labs/audit-report/releases/tag/v0.1.0 |
README.md
+8
| @@ -167,6 +167,14 @@ The `--fail-on` exit code (`1` = a finding/regression met the threshold, `2` = |
| 167 | 167 | usage error) lets a workflow separate "the audit found a problem" from "the job |
| 168 | 168 | is misconfigured". |
| 169 | 169 | |
| 170 | ## Stability |
| 171 | |
| 172 | `audit-report` is stable as of **v1.0.0** and follows [semantic versioning](https://semver.org). |
| 173 | The JSON report schema — findings carrying their `controls` and |
| 174 | `pass` / `fail` / `not_applicable` status — is a committed contract that |
| 175 | [control-coverage](https://github.com/audit-labs/control-coverage) consumes |
| 176 | directly; it will not break without a major-version bump. |
| 177 | |
| 170 | 178 | ## Development |
| 171 | 179 | |
| 172 | 180 | ```bash |
audit_report/__init__.py
+1 −1
| @@ -1,3 +1,3 @@ |
| 1 | 1 | """audit-report — turn audit-tools evidence packages into control-mapped reports.""" |
| 2 | 2 | |
| 3 | | __version__ = "0.1.0" |
| 3 | __version__ = "1.0.0" |
pyproject.toml
+1 −1
| @@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta" |
| 4 | 4 | |
| 5 | 5 | [project] |
| 6 | 6 | name = "audit-report" |
| 7 | | version = "0.1.0" |
| 7 | version = "1.0.0" |
| 8 | 8 | description = "Turn audit-tools evidence packages into control-mapped, auditor-ready reports." |
| 9 | 9 | readme = "README.md" |
| 10 | 10 | requires-python = ">=3.10" |