Repository navigation
v0.8.0
Opencomplai v0.8.0 lets a system be assessed against several frameworks side by side.
List the frameworks in the manifest:
"compliance_targets": ["EU_AI_ACT", "NIST_AI_RMF"]opencomplai gaps and opencomplai check --with-gaps then produce one report per framework. The EU AI Act is evaluated natively. NIST AI RMF 1.0 is derived from the same evidence through the crosswalk. Runs with a single EU AI Act or NIST AI RMF target produce the same output as before.
Added:
framework_reportson the scan-status artifact, with one report per target. It sits next togap_reportandnist_rmf_report, which are still written.framework_inputsin the manifest, for each framework other than the EU AI Act:excludedmarks a requirement as not applicable and records why;attestedrecords a provider attestation.
- Opt-in CI gating for frameworks other than the EU AI Act. Use
gate: {frameworks, fail_on}inopencomplai.yaml, orcheck --gate NIST_AI_RMFand--gate-fail-on missing|partial.- A Missing row in a gated framework turns
PASSintoCONTROL_FAIL(exit 1). - Without a gate, exit codes are unchanged.
- A Missing row in a gated framework turns
--targetcan be repeated ongapsandcheck, andcontrols statushas a--frameworkoption.recommendandreportwork across frameworks.POST /v1/manifests/validateacceptscompliance_targetsandframework_inputs.- The SDK exports
evaluate_targets,resolve_targets,FRAMEWORKS,FrameworkPack,FrameworkReportandGapReport. - Docs: a new Frameworks section, and a guide to adding framework packs.
Changed:
gapswithout--targetfollows the manifest. A manifest whosecompliance_targetisNIST_AI_RMFnow gets the NIST AI RMF table.validate-manifestrejects an unknown framework key (exit 2).- A malformed
opencomplai.yamlmakescheckexit 2.
Breaking for SDK callers: bridge_to_manifest_fields() no longer returns the intended_purpose key, which was deprecated in 0.7.1. Read checker_verdict instead.
Fixed:
- Rule rationales list matched keywords in a stable order.
scanexits 2 on a malformedopencomplai.yamlinstead of showing a traceback.
Full notes: CHANGELOG.md