Adds TAG SC artifacts for Cloud Native Security Controls Catalog#221
Open
Adds TAG SC artifacts for Cloud Native Security Controls Catalog#221
Conversation
✅ Deploy Preview for contribute-cncf-io ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
f029367 to
4d021a8
Compare
* 29a4246 feat: WIP commit to add controls catalog to tag-sc publications (Jennifer Power) * a5dd1b9 feat: control catalog refinement for CNSCC initiative (#1) (Hannah Braswell) * e8f4e93 feat: updates the conversion utility to new gemara module location (Jennifer Power) * 24d6d58 docs(tag-sc): adds README.md with contributing information security controls (Jennifer Power) * 3b237de docs(tag-sc): updates README.md structure and tools list (Jennifer Power) * 5e9fc8f docs: updates the controls catalog markdown generation and template (Jennifer Power) * 38e26be fix: add updates to control catalogs for storage family (#3) (Hannah Braswell) * 861cd2a feat: adds controls from CNSWP 2.0 (Jennifer Power) * a8cf748 chore: updates go dependencies for controls catalog (Jennifer Power) Co-authored-by: Hannah Braswell <hbraswel@redhat.com> Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>
Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>
Missing space and broken link Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>
Signed-off-by: Hannah Braswell <hbraswel@redhat.com> feat: adds linkage between CNSC 15, 16, and 19 Signed-off-by: Hannah Braswell <hbraswel@redhat.com> fix: adds template rendering of see-also Signed-off-by: Hannah Braswell <hbraswel@redhat.com> Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>
Add cnsc-nist-800-53-mapping.yaml (Gemara MappingDocument) and generate the NIST SP 800-53 crosswalk markdown. Replace families.yaml with groups.yaml and align the converter with Gemara v1.0.0-rc.1. Made-with: Cursor Signed-off-by: Hannah Braswell <hbraswel@redhat.com> Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>
4d021a8 to
1e5e940
Compare
… catalog cross-references Made-with: Cursor Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>
eddie-knight
approved these changes
Apr 3, 2026
eddie-knight
left a comment
There was a problem hiding this comment.
This is structurally sound, and visually impactful. I especially like the way that this gives credit to the source document (v1 / v2) and organizes mapping relationships in a standalone artifact with active links from the main catalog view.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR adds artifacts created in support of the TAG Security and Compliance Cloud Native Security Controls Catalogs Initiative - cncf/toc#1910.
What's Included
tags/security-and-compliance/publicationscalledcontrol-catalogto house the artifacts and toolinggo-gemaraSDK) to validate the artifact schemas and convert to theindex.mdwhich is renderedindex.mdSnippet
Footnotes
Yes, I can answer maintainer questions about the content of this PR, without using AI. ↩