Context
complyctl has two report conversion paths with different delegation
strategies:
-
SARIF (internal/output/sarif.go): delegates entirely to
gemaraconv.ToSARIF() from go-gemara. When go-gemara adds
evidence support to SARIF conversion, complyctl benefits
automatically with no code changes.
-
OSCAL (internal/output/oscal.go): uses a local
implementation that manually constructs oscalTypes.Finding
objects. There is an existing FIXME(jpower432) at line 18:
"This would probably make more sense in go-gemara/gemaraconv".
The local OSCAL formatter currently creates findings with only
Title, Description, Target, and Remarks -- it does not include
observations with relevant_evidence, which is an OSCAL
Assessment Results field that maps naturally to Gemara's
#EvidenceMapping.
Proposed Work
Once gemaraproj/go-gemara#127
lands (adding evidence support to OSCAL/SARIF conversions in
gemaraconv), migrate complyctl's local OSCAL formatter to
delegate to gemaraconv -- mirroring the pattern already used
for SARIF output. This would:
- Remove the local OSCAL conversion code in
internal/output/oscal.go (resolving the FIXME)
- Automatically gain
relevant_evidence support from the
upstream conversion
- Ensure both OSCAL and SARIF outputs stay aligned with Gemara
schema evolution without complyctl-side maintenance
Blocked By
- gemaraproj/go-gemara#127 --
upstream must add gemaraconv.ToOSCAL() (or equivalent) with
relevant_evidence mapping before this migration can proceed
Related
Context
complyctl has two report conversion paths with different delegation
strategies:
SARIF (
internal/output/sarif.go): delegates entirely togemaraconv.ToSARIF()from go-gemara. When go-gemara addsevidence support to SARIF conversion, complyctl benefits
automatically with no code changes.
OSCAL (
internal/output/oscal.go): uses a localimplementation that manually constructs
oscalTypes.Findingobjects. There is an existing
FIXME(jpower432)at line 18:"This would probably make more sense in go-gemara/gemaraconv".
The local OSCAL formatter currently creates findings with only
Title, Description, Target, and Remarks -- it does not include
observationswithrelevant_evidence, which is an OSCALAssessment Results field that maps naturally to Gemara's
#EvidenceMapping.Proposed Work
Once gemaraproj/go-gemara#127
lands (adding evidence support to OSCAL/SARIF conversions in
gemaraconv), migrate complyctl's local OSCAL formatter todelegate to
gemaraconv-- mirroring the pattern already usedfor SARIF output. This would:
internal/output/oscal.go(resolving the FIXME)relevant_evidencesupport from theupstream conversion
schema evolution without complyctl-side maintenance
Blocked By
upstream must add
gemaraconv.ToOSCAL()(or equivalent) withrelevant_evidencemapping before this migration can proceedRelated
internal/output/oscal.go:18