Curbpack prepares structural evidence for human review; it does not perform conformity assessment.
A local-first command-line tool that evaluates rule packs (JSON checklists shaped like regulatory annex drafts—not law) against a git repository and writes documentation and dependency checks for humans. Default pack is house-policy; Cyber Resilience Act (CRA)–shaped packs are opt-in only. Pair with software composition analysis (SCA) and secret scanners for depth.
| Artifact | Trust level (honest) |
|---|---|
| Gate JSON / action report | Structural evidence — reproducible locally; not a legal finding |
Read-only scan (curbpack scan) | Diagnosis only — writes nothing; default pack cra-baseline for Art 14 clock; not certification |
| SARIF export | Same gates in CI/IDE format — not certification |
| Buyer-questions / ContextPack / lay-of-land | Human checklist, washed assistant snapshot, map — not a CVE product or certification |
| Review pack / buyer one-pager | Procurement snapshot — not a certificate of conformity |
| SBOM / OpenVEX drafts | Best-effort inventory and draft notes |
| Git Notes attest | Signed only if ssh-agent signed — unsigned ≠ verified |
| Explain-packet | Sanitized tutor surface — never greenlights gates |
Development supported by RISE Research Institutes of Sweden as an applied research / competence object. RISE does not certify products that use Curbpack gate results. Never claim “RISE-approved,” “NCSC-approved,” or agency-endorsed product claims. Repo: promotion firewall.
Daily check needs no remote policy service. Packs ship embedded; refresh via offline import or a sha256-pinned network update. Install verifies release checksums fail-closed.
Full markdown: vision/docs/for-authorities.md · Art 14 campaign: Art 14 scan · ENISA mapping (preliminary — not domain-verified): vision/docs/mappings/enisa-cra-mapping.md · Voice: policies/voice-and-terms.md · Glossary: vision/docs/glossary-and-audience.md