End-to-End Demo: Ubuntu Component Definitions

August 12, 2026 · View on GitHub

Repository to demo oscal based component definitions and agile authoring using compliance-trestle and github actions

The demo overview.

  1. Input: It was initialized with OSCAL catalog.json, profile.json, Ubuntu yml from ComplianceAsCode, and control selections specified in spread sheets.

  2. Processing: Changes to any of the input files will cause regeneration of the software and validation component definitions.

  3. Output: Updated component-definition.json files in component-definition repo

  4. Next action: Updated component-definition.json files pushed to ssp repo

Demo for this repo:

  • Show changes to spread sheet (delete control, re-add control) are incorporated into component-definition.json files

We are a Cloud Native Computing Foundation sandbox project.

The Linux Foundation® (TLF) has registered trademarks and uses trademarks. For a list of TLF trademarks, see Trademark Usage.

OSCAL Compass is an independent open source project. It is not affiliated with, endorsed by, or sponsored by the National Institute of Standards and Technology (NIST) or any other government agency.

OSCAL Compass was originally contributed by IBM.