{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security/2"}],"enrichment":{"capability":"Compliance-trestle manages, validates, and transforms OSCAL (NIST's compliance standard format) documents, splitting large structures into editable pieces while enforcing schema compliance and supporting markdown-to-OSCAL conversion.","skillfed_tags":["compliance-automation","oscal","governance"],"use_cases":["Manage control descriptions and implementation details in git, linking system changes to affected compliance controls.","Convert compliance documentation from spreadsheets or markdown into standardized OSCAL format for tool interoperability.","Enforce consistent formatting and content in compliance markdown documents via template-based governance.","Build compliance CI/CD pipelines that validate and version OSCAL artifacts alongside infrastructure code.","Split large OSCAL catalogs into smaller, reviewable pieces for team collaboration and peer review."],"what_it_does":"Compliance-trestle is a Python toolkit for managing OSCAL (NIST's machine-readable compliance standard) documents in a developer-friendly way. It breaks large OSCAL structures into smaller, editable pieces that fit into normal git workflows\u2014allowing teams to version, review, and collaborate on compliance artifacts via pull requests. The package validates schemas, transforms documents from other formats into OSCAL, and provides governance tooling for markdown and drawio files used in compliance authoring.\n\nThe package is built around a CI/CD-friendly pipeline that sits on top of compliance artifacts in git, making compliance state transparent across stakeholders. It supports JSON and YAML formats (not XML), includes detached signing and verification for artifacts, and exposes an underlying object model for developers to interact with OSCAL programmatically. Version 5 is actively developed and supports OSCAL 1.2.1 with pydantic v2; version 4 is in maintenance mode until December 31, 2026.","worth_installing":"Yes, if you work with NIST compliance frameworks or need to manage OSCAL documents at scale. The package is actively maintained, has no known vulnerabilities, supports current Python versions, and provides genuine value for teams bringing compliance into DevOps workflows. Install with confidence if your compliance tooling stack requires OSCAL interchange; skip it if you don't work with OSCAL or compliance automation."},"id":"compliance-trestle","links":{"html":"https://skillfed.io/packages/compliance-trestle","md":"https://skillfed.io/packages/compliance-trestle.md","pypi":"https://pypi.org/project/compliance-trestle/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-08-07","license_spdx":"Apache-2.0","license_treatment":"permissive","name":"compliance-trestle","python_support":"supports_current","summary":"Tools to manage & autogenerate python objects representing the OSCAL layers/models"},"popularity":{"monthly_downloads":193632,"position":9849,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"5.0.0"}
