Skip to content

v1.0.0: SWAO General Availability

Choose a tag to compare

@MyLaserEyes MyLaserEyes released this 05 Sep 20:52
· 49 commits to main since this release

First public stable release of SWAO Community Edition.

What is SWAO?

SWAO (Sovereign Workload Assessment and Onboarding) is an open-source CLI tool that assesses cloud workloads for sovereign readiness and cloud-native maturity. It analyses source code, infrastructure definitions, and runtime signals to produce actionable migration plans and compliance evidence.

Included in this release

Assessment engine

  • 14 automated assessment passes: static analysis (AST, IaC, dependencies), LLM-assisted classification (7R migration label, compliance verdicts, cloud-native maturity, portability scoring), dynamic analysis (Playwright-driven UI traces), security scanning (credential detection, entropy analysis, SAST integration).
  • Coverage score reporting: Assessment Coverage, Cloud-Native Score, and Portability Score computed per application and aggregated across a portfolio.
  • 11 community frameworks: GDPR, AI 10 Pillars, BSI C5, BSI IT-Grundschutz 2023, HIPAA/NIST SP 800-66r2, LLM Selection, NCA CCC 2024, NCA ECC 2024, PCI-DSS v4, SAMA CSF v1.
  • Landing zone catalogue assessment against AWS, Azure, GCP, StackIT, and AWS sovereign landing zones.

Outputs

  • Workload Sovereignty Profile (WSP) - structured YAML assessment record per application run.
  • HTML publication with interactive coverage tiles, migration rationale prose, severity breakdown chart, and per-finding tables.
  • Text, YAML, and JSON report formats for CI integration.
  • SBOM generation (CycloneDX) included.

CLI and TUI

  • swao assess - run a full assessment against an application workspace.
  • swao report - generate reports from an existing WSP.
  • swao publish - produce the HTML publication from a WSP.
  • swao health-check - verify environment readiness (LLM provider, Playwright, community frameworks, licence).
  • swao init - scaffold a new SWAO workspace interactively.
  • Interactive TUI menu (swao menu) for guided operation.

Platform

  • Binaries available for Windows (x64), Linux (x64), macOS (x64), macOS (Apple Silicon).
  • Docker image: ghcr.io/accenture/swao:1.0.0.
  • Node.js >= 20 required if running from source.

Known Limitations

  • LZ Stakeholder Challenge findings are not yet shown in the HTML publication. The CLI text report (swao report-lz) reads the YAML files correctly; the HTML block is scheduled for the next release.
  • Authenticode (Windows code signing) is not yet applied to the Windows binary. The unsigned PE may trigger AV heuristics on some systems. See docs/releases/v1.0.0-vt-baseline.md for the current detection profile. Code signing is planned for v1.1.0.
  • MCP server WSP read coverage (Enterprise): ingested input file listing, assessment run history, WSP verdict summary, saved report retrieval, and per-provider LZ fit score matrix are in active development and will be available in the next minor release.