# ComplianceAsCode/content

Security automation content in SCAP, Bash, Ansible, and other formats

Repository: https://github.com/ComplianceAsCode/content
Canonical: https://ross.abutalabs.com/products/complianceascode-content
Homepage: https://complianceascode.readthedocs.io/en/latest/
Language: Shell
License: NOASSERTION
License Family: other
Topics: security, compliance, scap, xccdf, oval, cpe, cce, usgcb, pci-dss, ospp, stig, application-security, security-tools, security-hardening, security-automation, security-profile, hardening, information-security, cybersecurity, ansible
Last push: 2026-08-26T20:07:59+00:00

## Health v2 (maintenance only)
Score: 86/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 62, longevity 100
- inputs: {"age_days": 4509, "days_push": 7, "days_rel": 93, "gap_med": 96.0, "n_releases_24m": 7}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2791, forks 819 (observed 2026-08-28T04:07:22.083298+00:00)

## What it is
A collection of machine-readable security policy content for platforms like RHEL, Fedora, Ubuntu, and products like Firefox, expressed in SCAP (XCCDF, OVAL), Ansible, Bash, and CEL formats. It enables automated compliance scanning and remediation against standards such as PCI-DSS, STIG, and OSPP.

## Use cases
- scan linux servers for compliance with pci-dss or stig
- generate ansible playbooks to harden a system
- remediate security configuration drift with bash scripts
- produce scap data streams for compliance auditing
- check kubernetes cluster compliance with cel policies
- automate security baseline enforcement across a fleet

## When to choose
- you need standardized SCAP/XCCDF compliance content for common Linux distributions
- you want automated remediation playbooks for security baselines
- you must meet regulatory profiles like PCI-DSS, STIG, or OSPP

## When to avoid
- you need a scanning engine itself rather than content (use OpenSCAP or similar)
- you need compliance content for platforms not covered by the project
- you want a point-and-click compliance dashboard

## Facets
- artifact type: dataset
- maturity: active
- function: security, configuration-management, developer-tools
- domain: security, legal
- platform: self-hosted, cloud
- tags: scap, xccdf, oval, security-hardening, compliance-automation, ansible-playbooks, stig, pci-dss, openscap, devops, automation, linux

## Member repositories
- ComplianceAsCode/content (main) score 86

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:22.083298+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T08:15:15.630445+00:00, confidence not recorded.
  - readme: https://github.com/ComplianceAsCode/content (fetched 2026-08-28T04:07:22.083298+00:00, sha 7efcef746772)
- Data as of 2026-08-30T08:39:29.467469+00:00.
