diff --git a/README.md b/README.md index ff99ccd..18c298b 100644 --- a/README.md +++ b/README.md @@ -21,7 +21,7 @@ OpenSourceOM Core is the platform behind [opensourceom.org](https://opensourceom Traditional scanners flood you with CVEs and misconfigurations. OpenSourceOM connects the dots — showing which findings sit on paths from the internet to your sensitive data and privileged identities. -> **Status:** Early development (Phase 3). CSPM rules, identity blast radius, Kubernetes ingest, exports, a collector plugin SDK, and a Helm chart are available. CVE findings follow package and image inventory. Datastores can carry a sensitivity mark from a tag or label. A rules run writes an attack-path finding when a workload finding sits on a path to a datastore. `om scan aws` attaches recent CloudTrail management events, `om scan azure` attaches recent Activity Log events, and `om scan gcp` attaches recent Admin Activity audit logs, to the identity and resource on that path. That slice is [#74](https://github.com/OpenSourceOM/core/issues/74); Phase 3 closes when the issue is closed. Further rule packs stay open for contributors and do not gate the phase. See the [roadmap](./docs/ROADMAP.md). +> **Status:** Phase 3 has shipped. CSPM rules, identity blast radius, Kubernetes ingest, exports, a collector plugin SDK, and a Helm chart are available. CVE findings follow package and image inventory. Datastores can carry a sensitivity mark from a tag or label. A rules run writes an attack-path finding when a workload finding sits on a path to a datastore. `om scan aws` attaches recent CloudTrail management events, `om scan azure` attaches recent Activity Log events, and `om scan gcp` attaches recent Admin Activity audit logs, to the identity and resource on that path. Further rule packs stay open for contributors ([#10](https://github.com/OpenSourceOM/core/issues/10)). See the [roadmap](./docs/ROADMAP.md). ## Why this exists @@ -160,7 +160,7 @@ Full documentation: [opensourceom.org](https://opensourceom.org) (docs at [opens | **0** | Graph schema v0, AWS collector, ingest API, `om` CLI | | **1** | Attack path queries, CVE enrichment, web UI, Azure/GCP collectors | | **2** | CSPM rules, blast radius, K8s connector, exports | -| **3** *(now)* | Graph accuracy, crown-jewel datastores, attack-path findings, CloudTrail and Activity Log context. GCP Admin Activity logs ([#74](https://github.com/OpenSourceOM/core/issues/74)) close the phase. | +| **3** | Plugin SDK, Helm, embedded rule pack, demo graph, inventory-backed CVEs, crown-jewel datastores, attack-path findings, and cloud audit context (CloudTrail, Activity Log, Admin Activity). Shipped. | Details: [docs/ROADMAP.md](./docs/ROADMAP.md) diff --git a/docs/ARCHITECTURE.md b/docs/ARCHITECTURE.md index 57c409e..b21eac1 100644 --- a/docs/ARCHITECTURE.md +++ b/docs/ARCHITECTURE.md @@ -5,7 +5,7 @@ SPDX-License-Identifier: Apache-2.0 # Architecture -> **Status:** Phase 3. The ordered path is complete: the collector plugin SDK, Helm, the embedded rule pack, and cloud audit context from CloudTrail, Activity Log, and Admin Activity logs, alongside Phase 2 CSPM rules, blast radius, Kubernetes ingest, and exports. Further rule packs stay open for contributors. +> **Status:** Phase 3 has shipped. The collector plugin SDK, Helm, the embedded rule pack, and cloud audit context from CloudTrail, Activity Log, and Admin Activity logs are in the tree, alongside Phase 2 CSPM rules, blast radius, Kubernetes ingest, and exports. Further rule packs stay open for contributors. ## Overview @@ -70,9 +70,9 @@ See [ADR 001](./adr/001-graph-schema-v0.md), [ADR 002](./adr/002-phase1-findings - **Dev:** Docker Compose — Postgres + API (`docker compose up -d`); CLI can also target Postgres directly - **Prod:** Helm chart in `deploy/helm/opensourceom/` (API, optional Postgres, optional scheduled collectors) -## What's next (Phase 3) +## Phase 3 -Making the skeleton true, in order: +Shipped, in this order: - Self-hosted operability (console). Read routes honor the API secret, and the Helm chart schedules collectors when credentials are set. - CVE enrichment tied to workload inventory. `om enrich cve` writes a finding only when a workload package or image matches. @@ -80,7 +80,7 @@ Making the skeleton true, in order: - Attack path as the finding. A rules run writes one `attack_path` finding per existing finding on an internet-reachable workload that can reach a datastore, and stores the path as ordered node ids. - Cloud audit logs as graph context. `om scan aws` stores CloudTrail management events from the last 24 hours, `om scan azure` stores administrative Activity Log events from the same window, and `om scan gcp` stores Admin Activity audit logs from the same window, on the identity and resource they name when that resource is on an exposed path. `GET /v1/graph/query` returns those events in `audits` for each path that contains the resource. Entra ID sign-in logs, S3 data events such as `GetObject`, and GCP Data Access logs are not collected. -Further community rule packs (PCI and additional CIS mappings) stay open for contributors ([#10](https://github.com/OpenSourceOM/core/issues/10)). That issue does not close the phase. +Further community rule packs (PCI and additional CIS mappings) stay open for contributors ([#10](https://github.com/OpenSourceOM/core/issues/10)). Issue links: [ROADMAP.md](./ROADMAP.md)