GSoC 2026
OSCAL Document Signing and Verification in compliance-trestle
This project adds signing and verification for OSCAL JSON artifacts in compliance-trestle so generated documents can be verified in CI/CD and downstream workflows. The implementation will introduce deterministic RFC 8785 / JCS-style canonicalization for signing input, a detached JSON attestation workflow, and new trestle sign / trestle verify commands with clear failure handling. The MVP will be key-based, JSON-first, and detached so OSCAL artifacts remain unchanged, while signed metadata will capture provenance such as trestle version, signing time, OSCAL type, and optional git/build information. Deliverables include the signing and verification code, automated tests, documentation, and a tutorial.
Project details
Technologies
Not listed in the archive