dcs-conformance
Belnap-folded conformance for the modern compliance stack.
Binary tools answer pass/fail. When two of them disagree — GitHub says
yes, AWS says no, an auditor says "partial" — they have no state for it.
dcs does.
Install
pip install dcs-conformance
Optional extras:
pip install 'dcs-conformance[aws]' # boto3 connector
pip install 'dcs-conformance[oscap]' # OpenSCAP ARF parsing
pip install 'dcs-conformance[crypto]' # Ed25519 signing
Quickstart
dcs keygen # generate dcs/key.hex (Ed25519, gitignored)
dcs self # fold local tests x external sources
Every run writes three files:
- self-.json primary signed bundle
- self-.oscal.json OSCAL 1.1.2 Assessment Results
- self-.intoto.json in-toto v1 Statement in a DSSE envelope
Verify
dcs verify-intoto dcs/evidence/self-<ts>.intoto.json
# OK: 1 valid signature(s)
Or against an externally supplied public key:
dcs verify-intoto envelope.json --pubkey $(cat dcs/key.pub.hex)
The Belnap fold
Each requirement gets attestations from multiple sources. They fold via meet over Belnap FOUR:
| sources | folded |
|---|---|
| local=T, github=T | T |
| local=T, aws=F | B |
| local=T, github=U | T |
| all=F | F |
CONFLICT is a first-class state. A binary tool would have printed one of the inputs and dropped the disagreement.
Connectors
Sovereign plugins. Missing tool or missing env var yields U; the verdict narrows but never breaks.
- github README, workflows, default branch
- aws S3 encryption, CloudTrail multi-region, IAM password policy
- oscap OpenSCAP ARF XML
- kube_bench CIS Kubernetes Benchmark
- kyverno Kyverno PolicyReport CRDs
- prowler Prowler OCSF findings
Interoperability
- OSCAL consumed by compliance-trestle, trestle-cli, FedRAMP tooling
- in-toto consumed by cosign, Rekor, policy-controller
- Ed25519 verifiable with only key.pub.hex
License
Apache-2.0
Metadata
Release files for dcs-conformance 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| dcs_conformance-1.0.0.tar.gz | 129.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| dcs_conformance-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 285.9 kB
Release files / dcs_conformance-1.0.0.tar.gz
| Download URL | dcs_conformance-1.0.0.tar.gz |
|---|---|
| Size | 129.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e24438d237e00ab596ec6fdc5d0be3ef5b1fd11cc23781218499ec33e2af8b24
|
|
BLAKE2b-256 checksum How to use checksums |
5a44cdd0e279b9fa036d4c8b24ff10c1844be6af079dfbf60c430761d737f4cf
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.14
|
Release files / dcs_conformance-1.0.0-py3-none-any.whl
| Download URL | dcs_conformance-1.0.0-py3-none-any.whl |
|---|---|
| Size | 156.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e0a4c47035dbd4b66569e1203b7808f083834d1694307f6ac26abc37067bc6b7
|
|
BLAKE2b-256 checksum How to use checksums |
a8e0714c27fa2dbff4b51bf6e4dc033c8e439cebcad2197405aeaeaa7454d90d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.14
|