From 01cbadad8c5adb0e2be5dcee42ca704ee398aa61 Mon Sep 17 00:00:00 2001 From: om986 Date: Fri, 2 Oct 2026 10:25:32 -0400 Subject: [PATCH] Mark Phase 3 complete so the open rule pack no longer looks unfinished. Co-authored-by: Cursor --- README.md | 2 +- docs/ROADMAP.md | 9 +++++++-- 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 18c298b..785a6c7 100644 --- a/README.md +++ b/README.md @@ -75,7 +75,7 @@ deploy/helm/ Production Kubernetes chart ## Quick start -Phase 2 stack — Postgres, multi-cloud + Kubernetes collectors, CSPM rules, CVE enrichment, blast-radius analysis, exports, and a web console. +Phase 3 has shipped — Postgres, multi-cloud and Kubernetes collectors, CSPM rules, inventory-backed CVE enrichment, blast-radius analysis, attack-path findings, cloud audit context, exports, a collector plugin SDK, a Helm chart, and a web console. ```bash git clone https://github.com/OpenSourceOM/core.git diff --git a/docs/ROADMAP.md b/docs/ROADMAP.md index 4572dac..a5f0f9f 100644 --- a/docs/ROADMAP.md +++ b/docs/ROADMAP.md @@ -33,11 +33,12 @@ High-level plan for OpenSourceOM core. Timelines are approximate and community-d ## Phase 3 — Ecosystem +Phase 3 is complete. + - [x] Plugin SDK for custom collectors (`sdk/collector`, `om scan plugin`) - [x] Helm chart for production Kubernetes - [x] Community rule packs (CIS AWS–inspired YAML pack + embed loader) - [x] Sample environment (`om scan demo`) -- [ ] Broader community rule packs (PCI and additional CIS mappings) — [#10](https://github.com/OpenSourceOM/core/issues/10). This stays open for a contributor. It does not close the phase. Phases 0–2 shipped the walking skeleton. Exposure and identity edges now follow the cloud and Kubernetes. CVE findings follow package and image inventory on the workload. Datastores carry a sensitivity mark when a tag or label names one. A rules run writes an attack-path finding for each finding already on an internet-reachable workload that can reach a datastore. `om scan aws` attaches recent CloudTrail management events, `om scan azure` attaches recent Activity Log events, and `om scan gcp` attaches recent Admin Activity audit logs, to the identity and resource they name. Path queries return an event when that resource is on the path. @@ -55,7 +56,11 @@ The path, in order: `om scan aws` reads CloudTrail management events from the last 24 hours. `om scan azure` reads administrative Activity Log events over the same window. `om scan gcp` reads Admin Activity audit logs over the same window. An event is stored on the identity and the resource it names when that resource sits on an exposed path. Named path queries list those events when the resource is on the returned path. Data Access logs, Entra ID sign-in logs, and S3 object data events such as `GetObject` stay out. -The ordered path above is complete. [#10](https://github.com/OpenSourceOM/core/issues/10) stays open for a contributor who wants another rule pack. It does not reopen the phase. +The ordered path above is complete. + +## After Phase 3 + +[#10](https://github.com/OpenSourceOM/core/issues/10) stays open for a contributor who wants another rule pack (PCI and additional CIS mappings). It does not reopen Phase 3. ## Open source vs. commercial