Skip to content

refactor: migrate OSCAL formatter to gemaraconv for evidence and relevant_evidence support #851

Description

@marcusburghardt

Context

complyctl has two report conversion paths with different delegation
strategies:

  • SARIF (internal/output/sarif.go): delegates entirely to
    gemaraconv.ToSARIF() from go-gemara. When go-gemara adds
    evidence support to SARIF conversion, complyctl benefits
    automatically with no code changes.

  • OSCAL (internal/output/oscal.go): uses a local
    implementation
    that manually constructs oscalTypes.Finding
    objects. There is an existing FIXME(jpower432) at line 18:
    "This would probably make more sense in go-gemara/gemaraconv".

The local OSCAL formatter currently creates findings with only
Title, Description, Target, and Remarks -- it does not include
observations with relevant_evidence, which is an OSCAL
Assessment Results field that maps naturally to Gemara's
#EvidenceMapping.

Proposed Work

Once gemaraproj/go-gemara#127
lands (adding evidence support to OSCAL/SARIF conversions in
gemaraconv), migrate complyctl's local OSCAL formatter to
delegate to gemaraconv -- mirroring the pattern already used
for SARIF output. This would:

  1. Remove the local OSCAL conversion code in
    internal/output/oscal.go (resolving the FIXME)
  2. Automatically gain relevant_evidence support from the
    upstream conversion
  3. Ensure both OSCAL and SARIF outputs stay aligned with Gemara
    schema evolution without complyctl-side maintenance

Blocked By

  • gemaraproj/go-gemara#127 --
    upstream must add gemaraconv.ToOSCAL() (or equivalent) with
    relevant_evidence mapping before this migration can proceed

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Fields

    Priority

    High

    Effort

    Medium

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions