Commit 3b24b70d69

3b24b70d6909abc3462876e7ad3b3058cbee2f11

parent: cf0e01f5e6

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-08 03:52 UTC

Release v1.0.0

Bump version to 1.0.0, add CHANGELOG, and document the stability commitment.

Layout: unified · split

CHANGELOG.md added +31
@@ -0,0 +1,31 @@
1# Changelog
2
3All notable changes to this project are documented here. The format is based on
4[Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres
5to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
6
7## [1.0.0] - 2026-08-07
8
9First stable release. The bundled catalogs, the coverage / Statement of
10Applicability / JSON output schemas, and the `--fail-under` gate are committed
11under semantic versioning. Reads
12[audit-report](https://github.com/audit-labs/audit-report)'s v1 JSON contract.
13
14## [0.1.0] - 2026-08-06
15
16### Added
17
18- Control-first coverage and blind-spot analysis over a corpus of audit-report
19 JSON, producing a true coverage percentage and an unaddressed-control (blind-spot)
20 list from the framework's full control catalog.
21- Bundled catalogs: SOC 2 (61 controls across all five Trust Services categories),
22 ISO 27001:2022 Annex A (93), NIST SP 800-53 Moderate baseline (177).
23- Statement of Applicability generation from a scope file (exclusions + reasons),
24 with `exclude_families` to drop a whole category/theme/family from the denominator.
25- Trend mode (`--baseline`) and crosswalk mode (`--crosswalk`, greedy minimal
26 evidence set); md/html/json output.
27- `--fail-under N` coverage gate for CI.
28- PyPI trusted-publishing release workflow.
29
30[1.0.0]: https://github.com/audit-labs/control-coverage/releases/tag/v1.0.0
31[0.1.0]: https://github.com/audit-labs/control-coverage/releases/tag/v0.1.0
README.md +7
@@ -169,6 +169,13 @@ audit-tools ──► CSV package ──► evidence-seal (seal + verify)
169 trend over time, evidence crosswalk 169 trend over time, evidence crosswalk
170``` 170```
171 171
172## Stability
173
174`control-coverage` is stable as of **v1.0.0** and follows [semantic versioning](https://semver.org).
175It reads [audit-report](https://github.com/audit-labs/audit-report)'s v1 JSON
176contract; the bundled catalogs, the coverage / Statement of Applicability / JSON
177output schemas, and the `--fail-under` gate are committed within the 1.x line.
178
172## Development 179## Development
173 180
174```bash 181```bash
control_coverage/__init__.py +1 −1
@@ -1,3 +1,3 @@
1"""control-coverage — control-first coverage and blind-spot analysis over an evidence corpus.""" 1"""control-coverage — control-first coverage and blind-spot analysis over an evidence corpus."""
2 2
3__version__ = "0.1.0" 3__version__ = "1.0.0"
pyproject.toml +1 −1
@@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta"
4 4
5[project] 5[project]
6name = "control-coverage" 6name = "control-coverage"
7version = "0.1.0" 7version = "1.0.0"
8description = "Control-first coverage and blind-spot analysis over an evidence corpus, with a Statement of Applicability." 8description = "Control-first coverage and blind-spot analysis over an evidence corpus, with a Statement of Applicability."
9readme = "README.md" 9readme = "README.md"
10requires-python = ">=3.10" 10requires-python = ">=3.10"