Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,18 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

### Changed

- **FedRAMP CR26 vendored schemas re-synced to the upstream 1.0.0 graduation**
(`FedRAMP/schemas` @ `ae0dc43e`, 2026-07-15 — caught by a manual drift probe
inside the weekly sentinel's blind window): the Security Decision Record
schema's `$schemaVersion` moved 0.1.0 → **1.0.0**, fixing the Public-Preview
draft's vacuous `items` wrapper nesting so the per-KSI constraints now
actually enforce — constraints `evidentia conmon ksi` output already
satisfies (emitted documents re-validated against upstream 1.0.0, zero
emitter changes). `fedramp-common-definitions` re-vendored byte-identical at
0.1.1; `UPSTREAM.json` pins refreshed (all 11 tracked `$schemaVersion`s).
The documented one-line cross-document `$ref` delta is retained — upstream
fix PR #4 remains unmerged; the 1.0.0 graduation did not include it.

- **Claim-accuracy sweep across the public docs** (pre-v0.11.0; every change
traced to the 2026-07-15 primary-source verification pass): CLI↔GUI parity
claims recomputed from the manifest (98% → **93.4%**, 99 full / 7 api-only /
Expand Down
5 changes: 4 additions & 1 deletion docs/releases/plans/v0.11-plan.md
Original file line number Diff line number Diff line change
Expand Up @@ -154,7 +154,10 @@ DEFER-WITH-TRIGGER — emitted documents stay on 1.2.1.**
deleted; FedRAMP/docs renamed docs-legacy). The live target is the
`keySecurityIndicators` block of the CR26 **Security Decision Record**
per `fedramp-security-decision-record-schema-2026-06-24.json`
(`FedRAMP/schemas`, `$schemaVersion` 0.1.0), populated from the KSI
(`FedRAMP/schemas`, `$schemaVersion` 0.1.0 at ratification; graduated
to 1.0.0 upstream 2026-07-15 and re-vendored pre-release — the 1.0.0
change enforces the per-item constraints the emitter already met),
populated from the KSI
catalog in `fedramp-consolidated-rules.json` (`FedRAMP/rules` — 10
families / 46 indicators, all `stable` and unchanged since the
2026-06-24 CR26 launch). Obligation anchor: SDR-CSO-FRR (SDR in JSON is
Expand Down
12 changes: 12 additions & 0 deletions docs/wiki/6-project/changelog.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,18 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

### Changed

- **FedRAMP CR26 vendored schemas re-synced to the upstream 1.0.0 graduation**
(`FedRAMP/schemas` @ `ae0dc43e`, 2026-07-15 — caught by a manual drift probe
inside the weekly sentinel's blind window): the Security Decision Record
schema's `$schemaVersion` moved 0.1.0 → **1.0.0**, fixing the Public-Preview
draft's vacuous `items` wrapper nesting so the per-KSI constraints now
actually enforce — constraints `evidentia conmon ksi` output already
satisfies (emitted documents re-validated against upstream 1.0.0, zero
emitter changes). `fedramp-common-definitions` re-vendored byte-identical at
0.1.1; `UPSTREAM.json` pins refreshed (all 11 tracked `$schemaVersion`s).
The documented one-line cross-document `$ref` delta is retained — upstream
fix PR #4 remains unmerged; the 1.0.0 graduation did not include it.

- **Claim-accuracy sweep across the public docs** (pre-v0.11.0; every change
traced to the 2026-07-15 primary-source verification pass): CLI↔GUI parity
claims recomputed from the manifest (98% → **93.4%**, 99 full / 7 api-only /
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,11 @@ As published, every cross-document `$ref` in the CR26 schema set places the
JSON Pointer in the URI **path** (`...json/$defs/x`) instead of the **fragment**
(`...json#/$defs/x`), so no conforming JSON Schema 2020-12 validator can
resolve them (upstream [issue #3](https://github.com/FedRAMP/schemas/issues/3),
fix [PR #4](https://github.com/FedRAMP/schemas/pull/4) — unmerged at vendor
time). The vendored SDR schema carries exactly **one** such rewrite. When the
fix [PR #4](https://github.com/FedRAMP/schemas/pull/4) — still unmerged at the
2026-07-16 re-vendor; the SDR schema's 0.1.0 → 1.0.0 graduation fixed the
draft's vacuous `items` wrapper nesting and added proper **local** `#/$defs`
refs, but left the one cross-document ref malformed). The vendored SDR schema
carries exactly **one** such rewrite. When the
upstream fix merges, re-vendor byte-identical and clear the `local_delta` note
in `UPSTREAM.json`. The `fedramp-schema-watch` sentinel flags upstream movement
on these files, so the merge will surface on its own.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"comment": "Provenance pins for the vendored FedRAMP CR26 artifacts. Single source of truth for scripts/check_fedramp_upstream_drift.py (the fedramp-schema-watch sentinel baseline) and for scripts/catalogs/gen_fedramp_ksi.py (the KSI catalog generator pin). Update ONLY via a deliberate re-sync: re-vendor, re-verify, and re-run the generator together. See README.md in this directory.",
"verified_at": "2026-07-14",
"verified_at": "2026-07-16",
"rules": {
"repo": "FedRAMP/rules",
"commit": "12fe1b60f578ab448c26d143baac99d16d8bfe14",
Expand All @@ -14,30 +14,30 @@
},
"schemas": {
"repo": "FedRAMP/schemas",
"commit": "d6f69b81392ef369bc216c228bde51713209a6bf",
"commit": "ae0dc43ecfc7287d557f16681f49d98d72e3d94d",
"ruleset_date": "2026-06-24",
"schema_versions": {
"fedramp-accepted-vulnerability-info-schema-2026-06-24.json": "0.1.0",
"fedramp-advisor-information-schema-2026-06-24.json": "0.1.0",
"fedramp-assessor-information-schema-2026-06-24.json": "0.1.0",
"fedramp-certification-package-overview-schema-2026-06-24.json": "0.1.1",
"fedramp-common-definitions-schema-2026-06-24.json": "0.1.0",
"fedramp-advisor-information-schema-2026-06-24.json": "0.1.1",
"fedramp-assessor-information-schema-2026-06-24.json": "0.1.1",
"fedramp-certification-package-overview-schema-2026-06-24.json": "0.1.2",
"fedramp-common-definitions-schema-2026-06-24.json": "0.1.1",
"fedramp-historical-ver-activity-schema-2026-06-24.json": "0.1.0",
"fedramp-incident-report-schema-2026-06-24.json": "0.1.0",
"fedramp-ongoing-certification-report-schema-2026-06-24.json": "0.1.0",
"fedramp-security-decision-record-schema-2026-06-24.json": "0.1.0",
"fedramp-significant-change-notifications-schema-2026-06-24.json": "0.1.0",
"fedramp-incident-report-schema-2026-06-24.json": "0.1.1",
"fedramp-ongoing-certification-report-schema-2026-06-24.json": "0.1.1",
"fedramp-security-decision-record-schema-2026-06-24.json": "1.0.0",
"fedramp-significant-change-notifications-schema-2026-06-24.json": "0.1.1",
"fedramp-vulnerability-detail-report-schema-2026-06-24.json": "0.1.0"
},
"vendored": {
"fedramp-security-decision-record-schema-2026-06-24.json": {
"blob_sha": "e35c7862b97da9654b83048781ab8ed435be5d9c",
"sha256_upstream": "968b887431d5c9e3b5c3d0b62d836113061b190893ceca6f2fd3d14f0c7dd517",
"local_delta": "One cross-document $ref rewritten from '...json/$defs/certificationPackageOverviewUri' to '...json#/$defs/certificationPackageOverviewUri' (JSON Pointer moved into the URI fragment, as JSON Schema 2020-12 requires). Upstream defect: FedRAMP/schemas issue #3, fix PR #4 (unmerged at vendor time). Drop this delta when the upstream fix merges and re-vendor byte-identical."
"blob_sha": "31d2b7207ec04037fb7537392375c7bb045ced9a",
"sha256_upstream": "d598637cd4bb0f52425d7186ddc6f9463dcdda02734533623322e031d9b97b1a",
"local_delta": "One cross-document $ref rewritten from '...json/$defs/certificationPackageOverviewUri' to '...json#/$defs/certificationPackageOverviewUri' (JSON Pointer moved into the URI fragment, as JSON Schema 2020-12 requires). Upstream defect: FedRAMP/schemas issue #3, fix PR #4 (still unmerged at the 2026-07-16 re-vendor; the 1.0.0 graduation did NOT include it — re-verified). Drop this delta when the upstream fix merges and re-vendor byte-identical."
},
"fedramp-common-definitions-schema-2026-06-24.json": {
"blob_sha": "db532e342230b01a531b3cb66dbae7f4f7a0dba6",
"sha256_upstream": "26e637a9ee0cde2c4b6794d3f4cb3d56cc026780227c3e92fcab98dc2e354083",
"blob_sha": "534853e39c2863997ccf03245fcadbc293bcc5b3",
"sha256_upstream": "b6cffd3632ba524cc5a5e44f6c62e6fdcae7993221e558d32761f15d212117c1",
"local_delta": null
}
}
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://fedramp.gov/schemas/fedramp-common-definitions-schema-2026-06-24.json",
"$schemaVersion": "0.1.0",
"$schemaVersion": "0.1.1",
"title": "FedRAMP Common Definitions",
"description": "Shared type definitions referenced by other FedRAMP schemas.",
"$defs": {
Expand Down Expand Up @@ -161,14 +161,14 @@
"properties": {
"isOverdue": {
"title": "Is Overdue",
"description": "True if the vulnerability is overdue.",
"description": "True if the vulnerability is overdue.",
"const": true
}
}
},
"then": {
"title": "Explanation",
"description": "Reason for the overdue status.",
"description": "Reason for the overdue status.",
"required": [
"explanation"
]
Expand Down
Loading
Loading