Skip to main content

audit-packs-mapping

PyPI version Python License GitHub Repository

Audit-Packs Banner

audit-packs-mapping is the compliance framework mapping, posture calculation, and OSCAL export engine for the audit-packs ecosystem.

⚠️ IMPORTANT: This is a sub-package of the audit-packs compliance mapping toolkit. It is NOT designed to be run as a standalone CLI tool. If you are looking for the main CLI and GitHub Action scanner execution engine, please install and refer to audit-packs.


📦 Installation

Install this package via pip if you are programmatically resolving rules to controls or outputting OSCAL artifacts:

pip install audit-packs-mapping

🛠️ API Surface & Modules

Module Key API Exports Description
audit_packs_mapping.packs load_pack(), iter_controls(), map_findings() Loads YAML pack definitions and maps raw scanner rule IDs to controls. Resolves crosswalk references.
audit_packs_mapping.coverage compute_coverage() Calculates posture metrics (pass, fail, manual review) for active frameworks.
audit_packs_mapping.oscal to_assessment_results() Serializes mapped findings into standard NIST Open Security Controls Assessment Language (OSCAL) JSON.

🏗️ Supported Compliance Frameworks

Framework mappings are maintained as YAML files under packs/ at the repository root (or inside the Docker image at /app/packs). Packs are not bundled inside the wheel; the CLI resolves them at runtime: first --packs-dir / PACKS_DIR env var, then <workspace>/packs, then /app/packs, then falls back to the workspace root so downstream mapping gracefully skips unresolved controls.

  • NIST SP 800-53 Rev 5: The canonical pack (maps Checkov/Semgrep rules to NIST).
  • Crosswalk Frameworks: SOC 2, HIPAA, GDPR, ISO/IEC 27001, PCI-DSS, FedRAMP, and Custom Org-Policy (resolve crosswalk rules to underlying NIST controls).

📦 Ecosystem Architecture

audit-packs is built as a modular ecosystem consisting of five Python packages:

Package PyPI Link Role Standalone?
audit-packs pypi Main CLI & Action entrypoint Yes
audit-packs-core pypi Primitives, diff parsing, normalization No
audit-packs-mapping pypi Compliance pack loader & OSCAL exporter No
audit-packs-evidence pypi Evidence collectors & heuristic agents No
audit-packs-ai pypi LLM consensus & confidence scoring No

🔗 Related Resources

📄 License

This library is licensed under the Apache-2.0 License. See the LICENSE file in the main repository for details.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

audit_packs_mapping-0.8.0.tar.gz (8.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

audit_packs_mapping-0.8.0-py3-none-any.whl (8.1 kB view details)

Uploaded Python 3

File details

Details for the file audit_packs_mapping-0.8.0.tar.gz.

File metadata

  • Download URL: audit_packs_mapping-0.8.0.tar.gz
  • Upload date:
  • Size: 8.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for audit_packs_mapping-0.8.0.tar.gz
Algorithm Hash digest
SHA256 acf1d278e3e42f26146a997ac6fd260c77963ae7940e574ca9df85a083e8106c
MD5 2cc709c1599f9d9add786b787b2a0a4a
BLAKE2b-256 a429829cacfce7ac6f657d23a0729ade0fa1caf80e05d84966157fca820082e5

See more details on using hashes here.

File details

Details for the file audit_packs_mapping-0.8.0-py3-none-any.whl.

File metadata

File hashes

Hashes for audit_packs_mapping-0.8.0-py3-none-any.whl
Algorithm Hash digest
SHA256 78e39e513ec960292fc3c1311cb73d61da5eefc2b2570f2c53ede39e0b01172b
MD5 be24d281299ebf2a92d60f8bf4d4428d
BLAKE2b-256 84e89ef596a3cc4e2e6b72eb173026a7793760f21dd3a23fda02045a384c1a33

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page