StackGuardian / StackGuardian/tirith

feat(policies): interoperability packs — import existing public checks as Tirith policies

Open
#327 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
Python
Stars
165
Forks
42
Avg merge
1d 3h
Merged PRs (30d)
11

Description

A large, verified translation set already exists internally: ~2,700 policies drawn from several
widely-used public check libraries, each with a fidelity record (exact/approximate + what differs)
and a verified failing case. Publish them as importable packs by framework/provider, plus generated
mapping tables (upstream check id → tirith policy). One measured caveat: a large share of checks
restate a (resource type, attribute path) pair another library already asserts, so packs should
deduplicate by (type, path), not by source. Scope: published packs and the mappings — not a
runtime emulator of any other tool.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the existing verified translation set and its fidelity records, then determine how published packs and generated upstream-check-to-Tirith mapping tables are organized. Define completion as importable framework/provider packs that preserve verified failing cases and deduplicate by (resource type, attribute path), without implementing a runtime emulator.

Written by the indexing model from the issue text.

Assessment

Domain
security, tooling
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.