Repository navigation
v1.0.0: SWAO General Availability
First public stable release of SWAO Community Edition.
What is SWAO?
SWAO (Sovereign Workload Assessment and Onboarding) is an open-source CLI tool that assesses cloud workloads for sovereign readiness and cloud-native maturity. It analyses source code, infrastructure definitions, and runtime signals to produce actionable migration plans and compliance evidence.
Included in this release
Assessment engine
- 14 automated assessment passes: static analysis (AST, IaC, dependencies), LLM-assisted classification (7R migration label, compliance verdicts, cloud-native maturity, portability scoring), dynamic analysis (Playwright-driven UI traces), security scanning (credential detection, entropy analysis, SAST integration).
- Coverage score reporting: Assessment Coverage, Cloud-Native Score, and Portability Score computed per application and aggregated across a portfolio.
- 11 community frameworks: GDPR, AI 10 Pillars, BSI C5, BSI IT-Grundschutz 2023, HIPAA/NIST SP 800-66r2, LLM Selection, NCA CCC 2024, NCA ECC 2024, PCI-DSS v4, SAMA CSF v1.
- Landing zone catalogue assessment against AWS, Azure, GCP, StackIT, and AWS sovereign landing zones.
Outputs
- Workload Sovereignty Profile (WSP) - structured YAML assessment record per application run.
- HTML publication with interactive coverage tiles, migration rationale prose, severity breakdown chart, and per-finding tables.
- Text, YAML, and JSON report formats for CI integration.
- SBOM generation (CycloneDX) included.
CLI and TUI
swao assess- run a full assessment against an application workspace.swao report- generate reports from an existing WSP.swao publish- produce the HTML publication from a WSP.swao health-check- verify environment readiness (LLM provider, Playwright, community frameworks, licence).swao init- scaffold a new SWAO workspace interactively.- Interactive TUI menu (
swao menu) for guided operation.
Platform
- Binaries available for Windows (x64), Linux (x64), macOS (x64), macOS (Apple Silicon).
- Docker image:
ghcr.io/accenture/swao:1.0.0. - Node.js >= 20 required if running from source.
Known Limitations
- LZ Stakeholder Challenge findings are not yet shown in the HTML publication. The CLI text report (
swao report-lz) reads the YAML files correctly; the HTML block is scheduled for the next release. - Authenticode (Windows code signing) is not yet applied to the Windows binary. The unsigned PE may trigger AV heuristics on some systems. See
docs/releases/v1.0.0-vt-baseline.mdfor the current detection profile. Code signing is planned for v1.1.0. - MCP server WSP read coverage (Enterprise): ingested input file listing, assessment run history, WSP verdict summary, saved report retrieval, and per-provider LZ fit score matrix are in active development and will be available in the next minor release.