OSCAL Compass
unknown · United StatesScores
1 product on the map — 1 open.
Openness
5 high confidence- license
- Apache-2.0(OSI)
- source
- public
- core features withheld
- no
Trestle is published under Apache-2.0 by the OSCAL Compass community project, with no company selling a fuller edition of it.
- https://cdn.jsdelivr.net/gh/oscal-compass/compliance-trestle@develop/LICENSE recorded 2026-09-26
Apache License, Version 2.0, full text
- https://cdn.jsdelivr.net/gh/oscal-compass/compliance-trestle@develop/README.md recorded 2026-09-27
README points to the OSCAL Compass community meetings and a CNCF OSCAL Compass end-to-end demo; external contributions welcome
- https://ungh.cc/repos/oscal-compass/compliance-trestle/files/develop recorded 2026-09-26
Full file listing of oscal-compass/compliance-trestle develop, 1,546 paths; no ee/, enterprise/, commercial/ or proprietary/ directory
Adoption
2 high confidencePyPI downloads of compliance-trestle, the product's own package, measure its use.
- https://pypistats.org/api/packages/compliance-trestle/recent recorded 2026-09-26
last_month downloads = 63,201 for compliance-trestle
Capability
3 high confidenceIts output is OSCAL, a published standard that auditors and their tools can validate independently, which puts it above tools that emit their own report formats. The content is still the operator's assertion, and signing is a beta feature, so it sits two steps below NVIDIA's hardware attestation.
- https://cdn.jsdelivr.net/gh/oscal-compass/compliance-trestle@develop/docs/predicates/oscal-signing/v1.md recorded 2026-09-26
"Trestle uses this predicate type in the in-toto Statement created by trestle sign"
- https://cdn.jsdelivr.net/gh/oscal-compass/compliance-trestle@develop/README.md recorded 2026-09-27
"Trestle is an ensemble of tools that enable the creation, validation, and governance of documentation artifacts for compliance needs. It leverages NIST's OSCAL as a standard data format"
- https://cdn.jsdelivr.net/gh/oscal-compass/compliance-trestle@develop/trestle/core/commands/sign.py recorded 2026-09-26
"Sign a JSON file as a detached DSSE provenance envelope"; the command is gated as a beta feature