$npx skillfedfor your agent

compliance-trestle

Tools to manage & autogenerate python objects representing the OSCAL layers/models

With conditionsPyPI SecurityReleased Aug 2026193.6K downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — compliance_trestle-5.0.0-py3-none-any.whl
v5.0.0 · released 2026-08-07 · Python >=3.10 · 19 runtime deps: attrs, cmarkgfm, cryptography, defusedxml, furl, ilcli, importlib-resources, jinja2

Yes, if you work with NIST compliance frameworks or need to manage OSCAL documents at scale. The package is actively maintained, has no known vulnerabilities, supports current Python versions, and provides genuine value for teams bringing compliance into DevOps workflows. Install with confidence if your compliance tooling stack requires OSCAL interchange; skip it if you don't work with OSCAL or compliance automation.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later; designed for use in git-based workflows with compliance artifacts.
  • Low friction installation via pip; actively maintained with releases every few days.
  • Requires Python 3.10 or later and pulls in 19 runtime dependencies including cryptography, pydantic, and YAML/JSON handling libraries—typical for a compliance tooling suite.

License · maintenance · safety

Apache-2.0 (permissive) — Apache-2.0 (permissive): you can use, modify, and distribute this package freely in commercial and private projects, provided you include the license notice and state material changes.

last release 2026-08-07 (7 days) · last repo commit 2026-08-14 · 269 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 193,632 downloads/mo, #9,849 on PyPI

Verify before relying

pip install compliance-trestle

from trestle.core.models import OscalBaseModel
# Load and manipulate OSCAL documents via the object model
  • Whether the package's 19 runtime dependencies introduce supply-chain risk in regulated environments.
  • Performance characteristics when working with very large OSCAL catalogs or profiles.
  • Extent of support for OSCAL 1.2.1 features beyond what v4 (maintenance mode) provides.
Same gist for agents: .md · .json

What it is and what it does

Compliance-trestle is a Python toolkit for managing OSCAL (NIST's machine-readable compliance standard) documents in a developer-friendly way. It breaks large OSCAL structures into smaller, editable pieces that fit into normal git workflows—allowing teams to version, review, and collaborate on compliance artifacts via pull requests. The package validates schemas, transforms documents from other formats into OSCAL, and provides governance tooling for markdown and drawio files used in compliance authoring.

The package is built around a CI/CD-friendly pipeline that sits on top of compliance artifacts in git, making compliance state transparent across stakeholders. It supports JSON and YAML formats (not XML), includes detached signing and verification for artifacts, and exposes an underlying object model for developers to interact with OSCAL programmatically. Version 5 is actively developed and supports OSCAL 1.2.1 with pydantic v2; version 4 is in maintenance mode until December 31, 2026.

Use it for

  • Manage control descriptions and implementation details in git, linking system changes to affected compliance controls.
  • Convert compliance documentation from spreadsheets or markdown into standardized OSCAL format for tool interoperability.
  • Enforce consistent formatting and content in compliance markdown documents via template-based governance.
  • Build compliance CI/CD pipelines that validate and version OSCAL artifacts alongside infrastructure code.
  • Split large OSCAL catalogs into smaller, reviewable pieces for team collaboration and peer review.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you work with NIST compliance frameworks or need to manage OSCAL documents at scale.

The package is actively maintained, has no known vulnerabilities, supports current Python versions, and provides genuine value for teams bringing compliance into DevOps workflows. Install with confidence if your compliance tooling stack requires OSCAL interchange; skip it if you don't work with OSCAL or compliance automation.

Install

compliance-trestle on PyPI

Before you install

Low friction installation via pip; actively maintained with releases every few days. Requires Python 3.10 or later and pulls in 19 runtime dependencies including cryptography, pydantic, and YAML/JSON handling libraries—typical for a compliance tooling suite.

Requires Python 3.10 or later; designed for use in git-based workflows with compliance artifacts.

License in practice

Apache-2.0 (permissive): you can use, modify, and distribute this package freely in commercial and private projects, provided you include the license notice and state material changes.

Quickstart

pip install compliance-trestle

from trestle.core.models import OscalBaseModel
# Load and manipulate OSCAL documents via the object model

Verify before relying

  • Whether the package's 19 runtime dependencies introduce supply-chain risk in regulated environments.
  • Performance characteristics when working with very large OSCAL catalogs or profiles.
  • Extent of support for OSCAL 1.2.1 features beyond what v4 (maintenance mode) provides.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
19 packages
attrscmarkgfmcryptographydefusedxmlfurlilcliimportlib-resourcesjinja2openpyxlorjsonparamikopydanticpython-dotenvpython-frontmatterpywin32requestsrfc8785ruamel-yamlsecuresystemslib
MaintenanceActively maintained 7 days since the last release
Last repo commit
First released
Downloads193,632 / month, #9,849 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: Information TechnologyLicense :: OSI Approved :: Apache Software LicenseOperating System :: MicrosoftOperating System :: POSIXProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12

Evidence: compliance_trestle-5.0.0-py3-none-any.whl

Tags

Capabilities
OSCAL document managementcompliance automation toolsNIST compliance frameworkcompliance artifact validationmarkdown to OSCAL conversioncompliance CI/CD pipelinecontrol documentation governance
Topics
compliance-automationoscalgovernance
PyPI keywords
ComplianceOSCALSecurity

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “OSCAL document management”

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also agent_governance_toolkit · agent-governance-toolkit-core · cdk-nag · prowler · terraform-compliance · stix2-validator · docling-slim · agent-governance-toolkit-cli · doclang · solc-select