audit-packs-core
audit-packs-core contains the foundational models, normalization logic, git diff parser, and source-to-sink data-flow primitives for the audit-packs ecosystem.
⚠️ IMPORTANT: This is a sub-package of the
audit-packscompliance mapping toolkit. It is NOT designed to be run as a standalone CLI tool. If you are looking for the main CLI and GitHub Action scanner execution engine, please install and refer to audit-packs.
📦 Installation
You can install this package via pip if you are writing custom extensions or building on top of the audit-packs data structures:
pip install audit-packs-core
🛠️ API Surface & Modules
| Module | Key API Exports | Description |
|---|---|---|
audit_packs_core.models |
Finding, ControlFinding, ControlStatus, AdjudicationResult |
Core compliance structures and type schemas. |
audit_packs_core.normalize |
sarif_to_findings(), extract_rule_confidences() |
Standardizes engine-specific SARIF JSON outputs into standard Finding instances. |
audit_packs_core.diff |
parse_unified_diff() |
Compares line numbers between refs to filter PR-changed lines. |
audit_packs_core.dataflow |
extract_data_flows(), flow_confidence() |
Tracks source-to-sink data flow dependencies (Python/YAML/HCL/JSON). |
audit_packs_core.trust |
TrustPolicy, repo_config_allowed() |
Repo-config trust gate: controls whether workspace-supplied AST rules, scanner plugins, and model configs are honored (requires AUDIT_ALLOW_REPO_CONFIG opt-in). |
audit_packs_core.redact |
redact_evidence(), mask_evidence(), add_masked_engine() |
Single chokepoint for redacting secrets from evidence strings before any output sink. |
📦 Ecosystem Architecture
audit-packs is built as a modular ecosystem consisting of five Python packages:
| Package | PyPI Link | Role | Standalone? |
|---|---|---|---|
audit-packs |
pypi | Main CLI & Action entrypoint | Yes |
audit-packs-core |
pypi | Primitives, diff parsing, normalization | No |
audit-packs-mapping |
pypi | Compliance pack loader & OSCAL exporter | No |
audit-packs-evidence |
pypi | Evidence collectors & heuristic agents | No |
audit-packs-ai |
pypi | LLM consensus & confidence scoring | No |
🔗 Related Resources
- Main GitHub Repository: https://github.com/prakharsingh/audit-packs
- Documentation & Setup: docs/SETUP.md
- Issue Tracker: https://github.com/prakharsingh/audit-packs/issues
📄 License
This library is licensed under the Apache-2.0 License. See the LICENSE file in the main repository for details.
Metadata
Release files for audit-packs-core 0.9.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| audit_packs_core-0.9.0.tar.gz | 14.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| audit_packs_core-0.9.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 29.4 kB
Release files / audit_packs_core-0.9.0.tar.gz
| Download URL | audit_packs_core-0.9.0.tar.gz |
|---|---|
| Size | 14.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
cbb4f9137cd7ca36ed48dc8c21e37c44bfa3c617ae024f507b665eb903af628a
|
|
BLAKE2b-256 checksum How to use checksums |
ad9f29e10df313771478d82ff165434f319d84188bc83e511c50168687dfee35
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Release files / audit_packs_core-0.9.0-py3-none-any.whl
| Download URL | audit_packs_core-0.9.0-py3-none-any.whl |
|---|---|
| Size | 15.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0e1a048f3a5dd09bf1d6c9ee6f283d6c971a6c7d29081e58f8b1356b1ce06cfe
|
|
BLAKE2b-256 checksum How to use checksums |
0ad47a179913d546b13a57571cf6134c56a1ccc8e9d17951b9e1cd86dd549def
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|