Changelog
All notable changes to AARF are documented here. The format follows
Keep a Changelog, and AARF adheres to
Semantic Versioning as scoped by spec/AARF_V1.md §7.
1.0.0 — 2026-07-06
First public release.
Added
- LOCKED spec
spec/AARF_V1.md: 13 control families (CC1–CC9 + Availability,
Confidentiality, Processing Integrity, Privacy), theessential/standard/
advancedtier model, severity weights, and the readiness-scoring math. - Control catalog — 43 controls across all 13 families, each with objective,
requirement, evidence requirements, and mappings to SOC 2 / ISO 27001 / CIS v8
(by reference). - JSON Schemas for control files and self-assessments (
schema/). aarfCLI —validate,list,scope,assess,report; ESM + CJS
library with TypeScript types.- Coverage-aware scoring — coverage-gated
Confidence, impact-ranked gaps,
and anUnprovenresult when coverage is below 30%. - Checklists — a runnable audit checklist and an evidence-collection
checklist. - Docs — MkDocs site and getting-started guide.
- Apache-2.0 license,
NOTICE, andPROVENANCE.md.
Full Changelog: https://github.com/Pioneeraitech-governance/aarf/commits/v1.0.0
Full Changelog: https://github.com/Pioneeraitech-governance/aarf/commits/v1.0.0
Full Changelog: https://github.com/Pioneeraitech-governance/aarf/commits/v1.0.0