Skip to content

v0.8.0

Choose a tag to compare

@OpenComplaiCTO OpenComplaiCTO released this 24 Sep 06:52
· 8 commits to main since this release

Opencomplai v0.8.0 lets a system be assessed against several frameworks side by side.

List the frameworks in the manifest:

"compliance_targets": ["EU_AI_ACT", "NIST_AI_RMF"]

opencomplai gaps and opencomplai check --with-gaps then produce one report per framework. The EU AI Act is evaluated natively. NIST AI RMF 1.0 is derived from the same evidence through the crosswalk. Runs with a single EU AI Act or NIST AI RMF target produce the same output as before.

Added:

  • framework_reports on the scan-status artifact, with one report per target. It sits next to gap_report and nist_rmf_report, which are still written.
  • framework_inputs in the manifest, for each framework other than the EU AI Act:
    • excluded marks a requirement as not applicable and records why;
    • attested records a provider attestation.
  • Opt-in CI gating for frameworks other than the EU AI Act. Use gate: {frameworks, fail_on} in opencomplai.yaml, or check --gate NIST_AI_RMF and --gate-fail-on missing|partial.
    • A Missing row in a gated framework turns PASS into CONTROL_FAIL (exit 1).
    • Without a gate, exit codes are unchanged.
  • --target can be repeated on gaps and check, and controls status has a --framework option. recommend and report work across frameworks.
  • POST /v1/manifests/validate accepts compliance_targets and framework_inputs.
  • The SDK exports evaluate_targets, resolve_targets, FRAMEWORKS, FrameworkPack, FrameworkReport and GapReport.
  • Docs: a new Frameworks section, and a guide to adding framework packs.

Changed:

  • gaps without --target follows the manifest. A manifest whose compliance_target is NIST_AI_RMF now gets the NIST AI RMF table.
  • validate-manifest rejects an unknown framework key (exit 2).
  • A malformed opencomplai.yaml makes check exit 2.

Breaking for SDK callers: bridge_to_manifest_fields() no longer returns the intended_purpose key, which was deprecated in 0.7.1. Read checker_verdict instead.

Fixed:

  • Rule rationales list matched keywords in a stable order.
  • scan exits 2 on a malformed opencomplai.yaml instead of showing a traceback.

Full notes: CHANGELOG.md