Skip to content

feat: add cds report compliance/evidence report command - #766

Open
RonaldHensbergen wants to merge 5 commits into
mainfrom
feat/734-compliance-evidence-report
Open

RonaldHensbergen wants to merge 5 commits into
mainfrom
feat/734-compliance-evidence-report

Conversation

@RonaldHensbergen

Copy link
Copy Markdown
Owner

Summary

Adds cds report <profile> which exports a single, exportable readiness-evidence snapshot for a rendered stack, resolving issue #734.

The report aggregates:

  • Modules: resolved id/source/version/dependsOn for every module instance in the plan.
  • Images: every image referenced by the rendered Compose output, whether digest-pinned, and linked signature/SBOM/provenance evidence looked up from tests/fixtures/signed-images.json (no new verification pipeline is duplicated — reuses cli/image_verification.py's existing fixture lookup via a new public lookup_image_evidence() wrapper).
  • Topology: each module's provided/consumed contracts and dependsOn edges.
  • Secret leak check: confirms none of the profile's declared secret values (spec.secrets.values) render literally into the Compose output instead of a ${CDS_*} placeholder.

Missing evidence degrades gracefully instead of failing the report:

  • Locally-built images → not-available, no diagnostic (expected dev state).
  • Published/digest-pinned images with no fixture match → not-available + W101 warning.
  • No fixture configured at all → not-available + W101 warning, distinct reason.
  • A leaked secret → E119 error, secretLeakCheck.status: fail, exit code 1.

Supports human-readable text (default) or --json, and --output/-o to save to a file. Diagnostics are always printed to stderr so --json stdout output stays parseable.

New docs: docs/compliance-report.md, including the required disclaimer that this is readiness evidence, not a legal compliance/conformity certification — cross-linked from docs/image-signing.md/docs/image-scanning.md.

Testing

  • New tests/test_report.py (13 tests): module/topology summary assembly, image evidence for available/local-build/no-match/no-fixture-configured cases, secret-leak pass/fail, and a regression test confirming non-declared CDS_* env vars (e.g. a database name) are excluded from the leak scan so they don't false-positive. Plus CLI-level smoke tests for text/--json/--output.
  • ruff check clean, markdownlint clean on the new doc.
  • Full suite: python scripts/run_tests_with_deprecation_gate.py → 977 tests, only the 3 pre-existing, unrelated ProductionPlaintextExposureWorkflowTest failures (reproduced identically on a clean main checkout — not caused by this change).

Fixes #734.

Adds `cds report <profile>` which exports a single, exportable
readiness-evidence snapshot for a rendered stack: resolved module list
(id/source/version/dependsOn), linked signature/SBOM/provenance
evidence per image (looked up from the signed-images fixture, with
graceful degradation and a W101 warning for locally-built or
unlinkable images instead of a hard failure), the contract/topology
graph, and a secret-leak check (E119) confirming no profile-declared
secret value renders literally into Compose output instead of a
${CDS_*} placeholder.

Supports human-readable text (default) or --json, and --output/-o to
save to a file. Diagnostics are always printed to stderr so --json
output stays parseable.

Fixes #734.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot and others added 4 commits September 27, 2026 12:06
Adds in-process tests for cli.main's report command (json/text output,
diagnostics-to-stderr, exit codes, --output) and for
build_compliance_report's validate/plan/render failure branches and
cli.report's edge cases, bringing new-code coverage to 100% on
cli/report.py and cli/image_verification.py's lookup_image_evidence.
Fixes a Sonar/Bandit false positive (S105/S107) by renaming a test
helper's 'secret_status' parameter to 'leak_status'.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- File #767 (GitOps), #768 (DB operator), #769 (cds maturity) for the
  three haven-parity-plan workstreams that had no issue yet.
- Create milestone 'Dutch Public-Sector Data & Security Alignment' and
  file #771 (Cyberbeveiligingswet/NIS2 scope), #772 (Common Ground/Haven
  reference profile), #773 (FDS data-provider alignment), #774 (NIS2-aligned
  cds security reporting).
- Cross-link the new issues from docs/roadmap.md and update
  docs/haven-parity-plan.md's status table and next steps accordingly.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Track ordering and dependencies for CRA-readiness issues (#729-#737)
on this branch.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
markdownlint's MD033/no-inline-html rule rejected the <span style=...>
color spans used to visually mark resolved/CRA-tagged rows. Convert
those rows to plain Markdown (strikethrough for resolved items) with
no styling loss to the table's information content.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@sonarqubecloud

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add exportable compliance/evidence report for rendered stacks

1 participant