Skip to content

Releases: usnistgov/oscal-content

OSCAL Content 1.5.0 Release

Choose a tag to compare

@iMichaela iMichaela released this 13 May 16:29

Summary

The oscal-content v1.5.0 release is a minor release which provides a new set of NIST publications in OSCAL and upgrades previously published OSCAL content to the version v1.2.2.

The release provides:

All published OSCAL artifacts have been upgraded to OSCAL v1.2.2.
In addition to the links provided above, all released artifacts are packaged and made available in the section "Assets" , below.

Detailed Commit Log

Below is a detailed commit log generated by running the following command against the release branch:

git log origin/release-1.4..origin/release-1.5 --pretty=oneline --abbrev-commit

78650f0 Publishing auto-converted artifacts
4789970 Fixes id-ref typo.
108232d Fixes param id typo.
4e4f54c Adds SP800-172 rev3 and SP800-172A rev3 in OSCAL.
837de4b Corrects a short-name in 800-171.
81e152a Corrects the version of the OSCAL 800-171 catalog.
75e0be4 Fix empty statements
ce7a06c Fixes resource duplicate key in IFA ssp example.
6576803 Updates resources in IFA ssp example.
6a4db90 Bug fixes for withdrawn categories and subcategories in CSF 2.0
6717459 Adds a schema-only validation target.
fec4382 Updates all examples to OSCAL v1.2.2 and fixes minor typos.
1116be2 Updates metadata of the SP800-218: SSDF and one remark.
8d2353f Updates the metadata of the sp800-171 in preparation of the release 1.5.0
b3d0b27 Updates metadata for CSF v2.0
c9bad6e Removes experimentally the remark added in a5ed555 and which unreasonably triggers a JSON convers
ion error in Actions but not locally
223b0b4 Inserted a missing remark in the 800-53 v5.2 catalog.
5143de7 Upgraded OSCAL version to v1.2.2 for the SP 800-53 rev4 artifacts.
c1ffed5 Upgraded the OSCAL version to v1.2.2 for all SP 800-53 v5.2.0 artifacts
195714f Updated the basic examples to eliminate deprecated values and to generate valid resolved catalog.
049aeb1 Updated OSCAL submodule to tag v1.2.2
fa5092c Updated OSCAL submodule to v1.2.1
99d1dd0 Corrected the profile example to resolve to a valid catalog and updated the oscal-cli command in
Makefile.
f6f2656 Corrected empty labels (CPRT errors) on A.03.01.10.ODP[02] and A.03.01.08.ODP[04].
f498d84 Undated wrong uuid for publisher
267ebcf Updating the OSCAL submodule to the v1.2.0 which has all submodules updated including the relocated ones.

OSCAL Content 1.4.0 Release

Choose a tag to compare

@iMichaela iMichaela released this 27 Aug 02:52

Summary

The oscal-content v1.4.0 release is a minor release which provides a new set of NIST publications in OSCAL and updates SP 800-53 to the latest version.

The release provides:

All released artifacts are also provided below user the section "Assets".

Detailed Commit Log

Below is a detailed commit log generated by running the following command against the release branch:

git log origin/release-1.3..origin/release-1.4 --pretty=oneline --abbrev-commit

5a09662 Bump actions/checkout from 4.2.2 to 5.0.0
676a520 Bump actions/cache from 4.2.3 to 4.2.4
d5181e8 Bump stefanzweifel/git-auto-commit-action from 5.0.0 to 5.2.0
5651059 Bump actions/upload-artifact from 4.3.1 to 4.6.2
4309e9a Bump actions/add-to-project from 0.6.0 to 1.0.2
9089a52 Added labels to groups in 800-53 and updated resolved profile example.
3668484 Added the profile example used in the tutorial.
91be7fd More metadata updates in the OSCAL examples.
d483a9b More updates to the CI/CD pipeline.
f8efbd2 More updates to the CI/CD pipeline, content-artrifact due to ubuntu install error.
de3450a Update CI/CD pipeline, content-artrifact due to ubuntu install error.
ed03607 Updated metadata for all profiles - uuids, last-modified, file version, oscal version and the 800-53 version to v5.2.0
f1a8368 Fixed typo in SA-24a.
babba42 SP 800-53 v5.2.0 updated metadata.
01b826f SP 800-53 v5.2.0 update completed.
057aa62 Initial 800-53 updates for v5.2.0 - work in progress.
ad42a94 Updated readme file and names of few ifa artifacts to eliminate redundancy. Fixed 800-218 incomplete text in resources.
6e6ba1e Resolved ifa_ssp conflicts and name update.
2cccdef Updated OSCAL version to 1.1.3 and changed system's name.
1db77fe OSCAL version update to few IFA OSCAL examples.
c9da07a Bump actions/checkout from 4.1.2 to 4.2.2
96fe9ff Bump actions/cache from 4.0.1 to 4.2.3
b44dd77 Added the SSDF in OSCAL and updated metadata of other NIST artifacts.
978ac94 Eliminated all backmatter duplications and completed the references.
bb610b4 additional manual fixes of references duplication due to capordino error and missing text in references due to CPRT error
d0ff760 partial manual fix of references duplication due to capordino error and missing text in references due to CPRT error
3c542b0 Adding CSF v2.0, SP800-171 and upgrading SP800-53 to OSCAL v1.1.3
b0e9ac3 Fixed path and file name to the imported SSP, enhanced metadeta and back-matter.
8b1fb00 Fixed path to imported assessment plan and enhanced metadeta.
6e337e5 Fixed imported SSP and updated metadata.
ddf288f Fixed bug #280.
1976931 adding CSF v2.0 in OSCAL
48919ba chore: fix spelling errors #275
0755303 Revert "chore: fix spelling errors #2032"
1831081 chore: fix spelling errors #2032
0ed4960 Bump actions/cache from 4.0.0 to 4.0.1
75f1c12 Bump actions/checkout from 4.1.1 to 4.1.2
0f38d6a Bump actions/add-to-project from 0.5.0 to 0.6.0
88bb8de Upgraded ubuntu to 22.04 in issue-triage.yml
dcf08a7 Upgraded ubuntu to 22.04

OSCAL Content 1.3.0 Release

Choose a tag to compare

@iMichaela iMichaela released this 13 Feb 23:59

Summary

The oscal-content v1.3.0 release is a minor release which fixes community-identified errors in the OSCAL representation of the NIST SP 800-53 Rev 5.1.1 catalog and provides additional OSCAL examples.

The release provides:

Key Take-aways for Ready Changes

The minor release provides:

  • prop/@name="label" with non-padded IDs for backwards compatibility in 800-53 catalog and prop/@name="label" with zero-padded IDs for all controls.
  • brings all existing OSCAL content to OSCAL 1.1.2
  • publishes the OSCAL content examples used during the workshop of the 4th OSCAL Conference (May, 2023).
  • updates the CI/CD pipeline to add additional validation with oscal-cli

Detailed Commit Log

Below is a detailed commit log generated by running the following command against the release branch:

git log origin/release-1.2.1..origin/release-1.3 --pretty=oneline --abbrev-commit

941c978 Publishing auto-converted artifacts [skip ci]
dbd2677 adjust makefile
cc62356 Update Makefile
d3f627a get latest oscal cli version
c17709d Update Makefile
7fc367b Update Makefile
f5869e3 install and validate oscal-cli in the make file
297a3dd Bump actions/upload-artifact from 4.3.0 to 4.3.1
0895563 Bump actions/upload-artifact from 3.1.3 to 4.3.0
f38e0f7 Bump actions/cache from 3.3.2 to 4.0.0
f0b990e updated metadata/OSCAL version to 1.1.2 and validated
c9a996b Update ifa_ssp-example.xml
9d0ee68 remove extra spaces
ca05d91 Update ifa_ssp-example.xml
bf0cdec change names
5dfd659 update file-names & oscal versions
341b28d add new content
f6d9319 Replacing the alt-idenfier props with zero-padded labels.
715faf5 corrected oscal version
397e692 Addressing SC-12 error - issue 72
562c2a0 Restore labels in the SP800-53 Rev 5.1.1 OSCAL catalog to their pre 1.2.1 version

OSCAL Content v1.2.1 Release

Choose a tag to compare

@iMichaela iMichaela released this 16 Dec 19:50

Summary

The oscal-content v1.2.1 release is a patch release which mainly fixes community-identified errors in the OSCAL representation of the NIST SP 800-53 Rev 5.1.1 catalog.

Key Take-aways for Ready Changes

The patch addresses bugs in 800-53 catalog (issues 224 226 227 for OSCAL content patch 1.2.1 (#228)
* addressed issue 226: error in IA-13(03)
* addresses issue 227 by removing extra related links in IA-13(01)(02)(03)
* addresses issue 229 by using consistent structure for the IA-13 ODP params
* updated metadata and backmatter to include a link to the CPRT SP800-53v5.1.1 resource
* addresses issue 224 by replacing labels with alt-identifies and adding leading zeros to accurately reflect the SP800-53 v5.1.1 release.
* updated root uuid, last-modified, revision history and back-matter.
* added leading zero to PM-7, PM-8 and PM-9 which were missing.
* fix the errors identified during the Schematron validation
* updated one more time the last modified and the uuid
* Updating Schematron rules in view of ongoing changes. (#230)
---------
Co-authored-by members of: oscal@nist.gov

Detailed Commit Log

b517381 Publishing auto-converted artifacts [skip ci]
6a8faec Merge release 1.2.1
e0a8319 Addresses bugs in 800-53 catalog (issues 224 226 227 for OSCAL content patch 1.2.1 (#228)
a1fead9 Adjust home repository to oscal-content
acc0d51 Feature 800 53 updates (#221)

OSCAL Content 1.2.0 Release

Choose a tag to compare

@Compton-US Compton-US released this 05 Dec 22:50

Summary

oscal-content 1.2.0 release is a minor release with minor enhancements to the NIST SP 800-53 catalog and alignment with the NIST SP 800-53 v5.1.1 CPRT release.

Key Take-aways for Ready Changes

Key take-away for this release are as follows:

Resolved profiles by adding and by aligning the catalog and the profiles with the NIST SP 800-53 v5.1.1 release.

  1. Enhances NIST SP 800-53 catalog with links added to the assessment objectives to link them with the control statements they belong to.
  2. Updated NIST SP 800-53 content to align with the NIST SP 800-53 v5.1.1 CPRT release.
  3. Updated profiles and resolved profiles to align with the NIST SP 800-53 v5.1.1 CPRT released data.

Appendix

Detailed Commit Log

Note for NIST developers: the output below is from executing the following command against the release branch (main) on a developer workstation: git log origin/release-1.0..origin/main --pretty=oneline --abbrev-commit.

1763607 (HEAD -> main, origin/release-1.2, origin/main, origin/HEAD, release-1.2) Publishing auto-converted artifacts [skip ci]
002431b Update GitHub Action HOME_REPO to point to oscal-content (#223)
da0e372 Feature 800 53 updates (#221) (#222)

OSCAL Content 1.1.0 Release

Choose a tag to compare

@wendellpiez wendellpiez released this 09 Nov 22:39

This content release aligns the OSCAL content in this repository with the OSCAL 1.1.1 release. The assets include OSCAL content examples and NIST SP800-53 rev 5.1 with the enhancements listed below.

The release contains:

This release of OSCAL content includes bug fixes and minor enhancements, including metadata and tagging reflecting richer control semantics, such as organizational vs system-level controls as indicated in SP800-53 Rev 5.1 Appendix C.

NOTE: The content in this release has been with the release and all content has an oscal-version of 1.1.1, it is still backwards compatible with older schemas unless otherwise noted. Review Architecture Decision Record 8 for more details.

OSCAL Content 1.0.0 Release

Choose a tag to compare

@david-waltermire david-waltermire released this 10 Jun 17:36

This content release aligns the OSCAL content in this repository with the OSCAL 1.0.0 release.

Given the MAJOR.MINOR.PATCH version "1.0.0":

  • The MAJOR.MINOR version "1.0" indicates that this content release is compatible with the OSCAL 1.0.x releases. See the OSCAL versioning for more information on how OSCAL is versioned.
  • The PATCH version "0" indicates that this release is the initial content release for the OSCAL "1.0.x".