Commit 073020727e
073020727e5ddc574f63690de8e559a5e43d2794
parent: e4d13ff9dc
Verified · cmc
cmc <hello@cleberg.net> · 2026-08-08 03:52 UTC
Release v1.0.0
Bump version to 1.0.0, add CHANGELOG, and document the stability commitment.
Layout: unified · split
CHANGELOG.md
added
+28
| @@ -0,0 +1,28 @@ |
| |
1 | # Changelog |
| |
2 | |
| |
3 | All notable changes to this project are documented here. The format is based on |
| |
4 | [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres |
| |
5 | to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). |
| |
6 | |
| |
7 | ## [1.0.0] - 2026-08-07 |
| |
8 | |
| |
9 | First stable release. The JSON report schema — findings carrying their `controls` |
| |
10 | and `pass` / `fail` / `not_applicable` status — is now a committed contract that |
| |
11 | [control-coverage](https://github.com/audit-labs/control-coverage) consumes |
| |
12 | directly; it will not change in a breaking way without a major-version bump. |
| |
13 | |
| |
14 | ## [0.1.0] - 2026-08-06 |
| |
15 | |
| |
16 | ### Added |
| |
17 | |
| |
18 | - Control-mapped reports from an audit-tools evidence package: declarative YAML |
| |
19 | rulesets map pass/fail results to SOC 2, ISO 27001, and NIST SP 800-53 controls. |
| |
20 | - Output as Markdown, self-contained HTML, or JSON; `--fail-on {low,medium,high,none}` |
| |
21 | gate for CI. |
| |
22 | - Bundled rulesets for GitHub, GitLab, and AWS evidence. |
| |
23 | - Trend mode to diff two evidence packages. |
| |
24 | - Tool and ruleset provenance stamped into every report. |
| |
25 | - PyPI trusted-publishing release workflow. |
| |
26 | |
| |
27 | [1.0.0]: https://github.com/audit-labs/audit-report/releases/tag/v1.0.0 |
| |
28 | [0.1.0]: https://github.com/audit-labs/audit-report/releases/tag/v0.1.0 |
README.md
+8
| @@ -167,6 +167,14 @@ The `--fail-on` exit code (`1` = a finding/regression met the threshold, `2` = |
| 167 | usage error) lets a workflow separate "the audit found a problem" from "the job |
167 | usage error) lets a workflow separate "the audit found a problem" from "the job |
| 168 | is misconfigured". |
168 | is misconfigured". |
| 169 | |
169 | |
| |
170 | ## Stability |
| |
171 | |
| |
172 | `audit-report` is stable as of **v1.0.0** and follows [semantic versioning](https://semver.org). |
| |
173 | The JSON report schema — findings carrying their `controls` and |
| |
174 | `pass` / `fail` / `not_applicable` status — is a committed contract that |
| |
175 | [control-coverage](https://github.com/audit-labs/control-coverage) consumes |
| |
176 | directly; it will not break without a major-version bump. |
| |
177 | |
| 170 | ## Development |
178 | ## Development |
| 171 | |
179 | |
| 172 | ```bash |
180 | ```bash |
audit_report/__init__.py
+1 −1
| @@ -1,3 +1,3 @@ |
| 1 | """audit-report — turn audit-tools evidence packages into control-mapped reports.""" |
1 | """audit-report — turn audit-tools evidence packages into control-mapped reports.""" |
| 2 | |
2 | |
| 3 | __version__ = "0.1.0" |
3 | __version__ = "1.0.0" |
pyproject.toml
+1 −1
| @@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta" |
| 4 | |
4 | |
| 5 | [project] |
5 | [project] |
| 6 | name = "audit-report" |
6 | name = "audit-report" |
| 7 | version = "0.1.0" |
7 | version = "1.0.0" |
| 8 | description = "Turn audit-tools evidence packages into control-mapped, auditor-ready reports." |
8 | description = "Turn audit-tools evidence packages into control-mapped, auditor-ready reports." |
| 9 | readme = "README.md" |
9 | readme = "README.md" |
| 10 | requires-python = ">=3.10" |
10 | requires-python = ">=3.10" |