# tmobile/pacbot

PacBot (Policy as Code Bot)

Repository: https://github.com/tmobile/pacbot
Canonical: https://ross.abutalabs.com/products/pacbot
Homepage: https://tmobile.github.io/pacbot/
Language: Java
License: Apache-2.0
License Family: permissive
Topics: cloud-security, security, aws, continous-compliance, cloud-auditing, policy-as-code, cloud, security-automation, aws-security, java, angularjs, cloud-compliance-reporting, cloud-native, spring-boot
Last push: 2022-12-08T16:43:24+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2906, "days_push": 1364, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1310, forks 280 (observed 2026-08-28T04:04:19.940771+00:00)

## What it is
PacBot is a platform for continuous compliance monitoring, compliance reporting, and security automation for the cloud, where security and compliance policies are implemented as code. It discovers cloud resources, evaluates them against policies, records violations as issues, and can auto-remediate them via an auto-fix framework.

## Use cases
- continuously monitor AWS resources for security policy violations
- generate cloud compliance reports and dashboards
- automatically remediate cloud misconfigurations
- audit cloud infrastructure against policy-as-code rules
- ingest vulnerability scan data and flag non-compliant resources
- manage policy exceptions for cloud compliance findings

## When to choose
- you need continuous compliance monitoring and reporting for AWS cloud infrastructure
- you want policies defined as code with automated remediation hooks
- you need a plugin-based platform to combine cloud, vulnerability, and other security data sources into one compliance view

## When to avoid
- you only need simple static infrastructure-as-code scanning rather than a full compliance platform
- your environment is primarily non-AWS, since core support is AWS-centric
- you need a lightweight tool without running a Java/Angular platform with its own data stores

## Facets
- artifact type: application
- maturity: maintenance
- function: security, monitoring, workflow-automation, plugin-system
- domain: security, cloud-computing, legal
- platform: cloud, self-hosted, jvm
- tags: policy-as-code, cloud-security, continuous-compliance, cloud-auditing, security-automation, auto-remediation, aws-security, compliance-reporting, reporting, devops, docker, web-server

## Member repositories
- tmobile/pacbot (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:19.940771+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:49:56.725782+00:00, confidence not recorded.
  - readme: https://github.com/tmobile/pacbot (fetched 2026-08-28T04:04:19.940771+00:00, sha 7564e378c94e)
  - homepage: https://tmobile.github.io/pacbot/ (fetched 2026-08-29T12:08:00.514007+00:00, sha 0346d8190297)
- Data as of 2026-08-30T08:39:29.467469+00:00.
