Skip to main content

dcs-conformance

Belnap-folded conformance for the modern compliance stack.

Binary tools answer pass/fail. When two of them disagree — GitHub says yes, AWS says no, an auditor says "partial" — they have no state for it. dcs does.

Install

pip install dcs-conformance

Optional extras:

pip install 'dcs-conformance[aws]'      # boto3 connector
pip install 'dcs-conformance[oscap]'    # OpenSCAP ARF parsing
pip install 'dcs-conformance[crypto]'   # Ed25519 signing

Quickstart

dcs keygen          # generate dcs/key.hex (Ed25519, gitignored)
dcs self            # fold local tests x external sources

Every run writes three files:

  • self-.json primary signed bundle
  • self-.oscal.json OSCAL 1.1.2 Assessment Results
  • self-.intoto.json in-toto v1 Statement in a DSSE envelope

Verify

dcs verify-intoto dcs/evidence/self-<ts>.intoto.json
# OK: 1 valid signature(s)

Or against an externally supplied public key:

dcs verify-intoto envelope.json --pubkey $(cat dcs/key.pub.hex)

The Belnap fold

Each requirement gets attestations from multiple sources. They fold via meet over Belnap FOUR:

sources folded
local=T, github=T T
local=T, aws=F B
local=T, github=U T
all=F F

CONFLICT is a first-class state. A binary tool would have printed one of the inputs and dropped the disagreement.

Connectors

Sovereign plugins. Missing tool or missing env var yields U; the verdict narrows but never breaks.

  • github README, workflows, default branch
  • aws S3 encryption, CloudTrail multi-region, IAM password policy
  • oscap OpenSCAP ARF XML
  • kube_bench CIS Kubernetes Benchmark
  • kyverno Kyverno PolicyReport CRDs
  • prowler Prowler OCSF findings

Interoperability

  • OSCAL consumed by compliance-trestle, trestle-cli, FedRAMP tooling
  • in-toto consumed by cosign, Rekor, policy-controller
  • Ed25519 verifiable with only key.pub.hex

License

Apache-2.0

Metadata

Release files for dcs-conformance 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dcs-conformance 1.0.0
File Size Uploaded
dcs_conformance-1.0.0.tar.gz 129.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dcs-conformance 1.0.0
File Interpreter ABI Platform
dcs_conformance-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 285.9 kB

Release files / dcs_conformance-1.0.0.tar.gz

Download URL dcs_conformance-1.0.0.tar.gz
Size 129.0 kB
Tags Source
SHA-256 checksum
How to use checksums
e24438d237e00ab596ec6fdc5d0be3ef5b1fd11cc23781218499ec33e2af8b24
BLAKE2b-256 checksum
How to use checksums
5a44cdd0e279b9fa036d4c8b24ff10c1844be6af079dfbf60c430761d737f4cf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.14

Release files / dcs_conformance-1.0.0-py3-none-any.whl

Download URL dcs_conformance-1.0.0-py3-none-any.whl
Size 156.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e0a4c47035dbd4b66569e1203b7808f083834d1694307f6ac26abc37067bc6b7
BLAKE2b-256 checksum
How to use checksums
a8e0714c27fa2dbff4b51bf6e4dc033c8e439cebcad2197405aeaeaa7454d90d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.14

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page