DEV Community

Cover image for Building Sewline: A Compliance-Aware SDLC Engine for High-Integrity
Bhargav Bhatt
Bhargav Bhatt

Posted on Fully Autonomous

Building Sewline: A Compliance-Aware SDLC Engine for High-Integrity

When building software for web apps or SaaS products, a failed build or a flaky test breaks a deployment pipeline. But when you are building software for commercial avionics, medical devices, or defense systems, a compliance oversight can stall an entire product launch for monthsβ€”or worse.

Engineers in regulated industries face a unique dilemma:

  1. Standard CI/CD platforms (like GitHub Actions or GitLab) are great at running scripts, but know nothing about compliance frameworks (DO-178C, AS9100, ISO 26262).
  2. Modern engineering uses AI agents (Copilot, Codex), but regulatory frameworks require strict human-in-the-loop approvals and provenance tracking.
  3. Generating audit evidence usually means manually compiling spreadsheets, PDFs, and disconnected logs.

To solve this, we built Sewlineβ€”an open-source, compliance-aware orchestration engine written in Rust.


πŸ’‘ What is Sewline?

Sewline isn't a replacement for GitHub Actions, Parasoft, or Jama Connect. Instead, it sits on top of your existing tools to orchestrate execution, evaluate Policy-as-Code gates, and automatically generate cryptographic evidence.

                                  +-------------------------------------------------+
                                  |                 USER INTERFACE                  |
                                  |     React + Tailwind Visualization Dashboard     |
                                  +------------------------+------------------------+
                                                           |
                                                      HTTP / gRPC
                                                           |
                                                           v
+-------------------------------------------------------------------------------------------------------------------+
|                                                 SEWLINE ENGINE                                                   |
|                                                                                                                   |
|  +-----------------------------------+     +----------------------------------+     +--------------------------+  |
|  |           Workflow DSL            |     |         Gate Engine              |     |  Context Store           |  |
|  |  Declarative YAML/JSON Pipeline   |---->|  - OPA / Rego Policy Evaluator   |---->|  - KΓΉzu / Lineage Graph  |  |
|  |  Conditional Branches & Parallel  |     |  - DSSE Attestation Generator    |     |  - Traceability Matrix   |  |
|  +-----------------+-----------------+     +-----------------+----------------+     +--------------------------+  |
|                    |                                         |                                                    |
|                    v                                         v                                                    |
|  +----------------------------------------------------------------------------+                                   |
|  |                              STAGE EXECUTOR                                |                                   |
|  |                       Plugin Adapter Abstraction Layer                      |                                   |
|  +--------+----------------------------------+-----------------------+--------+                                   |
|           |                                  |                       |                                            |
+-----------|----------------------------------|-----------------------|--------------------------------------------+
            |                                  |                       |
            v                                  v                       v
+-----------------------+          +-----------------------+  +-----------------------+
|  GitHub Actions / CI  |          | Parasoft C/C++test    |  | Jama Connect          |
|  (Source & Sync)      |          | (Static Analysis)     |  | (Requirements Trace)  |
+-----------------------+          +-----------------------+  +-----------------------+

Enter fullscreen mode Exit fullscreen mode

πŸ”₯ Key Technical Capabilities

1. Unified Plugin-Based Adapters (StageExecutor)

We abstracted all third-party dev tool execution under a clean Rust trait:

#[async_trait]
pub trait StageExecutor: Send + Sync {
    async fn execute(&self, stage: &Stage) -> Result<StageResult, EngineError>;
}

Enter fullscreen mode Exit fullscreen mode

Whether syncing a commit via GitHub Actions, triggering static code analysis with Parasoft, or pulling requirements from Jama, stages run deterministically within the execution DAG.

2. Policy-as-Code Gates (Rego / OPA)

Compliance isn't a post-hoc manual check anymore. Every stage in a Sewline pipeline runs against explicit Policy-as-Code gates:

stages:
  - id: static_analysis
    name: Parasoft Static Analysis
    adapter: adapter-parasoft
    gates:
      - id: gate_zero_misra_violations
        name: Zero MISRA C:2012 Violations
        policy_rule: sewline.parasoft.zero_violations
        enforce: true

Enter fullscreen mode Exit fullscreen mode

3. Tamper-Evident DSSE Attestations

Every time a gate passes or fails, Sewline generates signed, content-addressed DSSE (Dead Simple Signing Envelope) evidence statements using standard Ed25519 cryptography. Auditors don't need to take your word for itβ€”they can verify the cryptographic chain of proof.

4. Graph-Based Lineage Tracking (KΓΉzu)

Using the embedded graph database KΓΉzu, Sewline logs end-to-end lineage across all runs:

$$\text{Requirement} \longleftrightarrow \text{Commit} \longleftrightarrow \text{Static Analysis} \longleftrightarrow \text{DSSE Attestation}$$


πŸ—οΈ The Monorepo Architecture

We structured Sewline as a Cargo Workspace + Frontend Monorepo for clean domain separation:

sewline/
β”œβ”€β”€ Cargo.toml               # Workspace manifest
β”œβ”€β”€ crates/
β”‚   β”œβ”€β”€ sewline-core/        # Engine, DSL parser, Gate evaluator & Graph store
β”‚   β”œβ”€β”€ sewline-agent/       # AI Agent Control Plane (gRPC + SQLite)
β”‚   └── sewline-cli/         # CLI runner binary
β”œβ”€β”€ ui/                      # Dashboard (React + TypeScript + Tailwind)
β”œβ”€β”€ compliance_packs/        # Pre-built Rego rules (DO-178C, AS9100)
└── deploy/                  # Kubernetes Operator & Tenant CRDs

Enter fullscreen mode Exit fullscreen mode

πŸš€ Trying It Out Locally

Interested in running Sewline on your machine? You'll need Rust 1.75+ and Node.js 18+.

# 1. Clone the repo & run test suite
git clone [https://github.com/bhkbdbhatt/sewline.git](https://github.com/bhkbdbhatt/sewline.git)
cd sewline
cargo test --workspace

# 2. Launch the Agent Governance Control Plane
cargo run --bin sewline-agent

# 3. Spin up the Dashboard (in a second terminal)
cd ui
npm install
npm run dev

Enter fullscreen mode Exit fullscreen mode

Visit http://localhost:5173 to explore running pipelines and gate statuses!


πŸ’¬ What's Next?

We are actively building out pre-packaged compliance bundles for DO-178C (DAL A–E), AS9100, and ISO 26262, along with deeper Kubernetes operator support.

Check out the repo on GitHub, star it if you find it interesting, and drop your thoughts or questions in the comments below!

πŸ‘‰ GitHub: github.com/bhkbdbhatt/sewline


<ElicitationsGroup message="Here are a few ways to extend or promote this content:">
  <Elicitation label="Draft social media announcement posts (X/Twitter & LinkedIn)" query="Draft engaging social media post templates for Twitter/X and LinkedIn to promote this DEV.to post and GitHub repository."/>
  <Elicitation label="Create a step-by-step contributing guide (CONTRIBUTING.md)" query="Create a CONTRIBUTING.md file for the Sewline workspace detailing how to add new stage adapters and compliance packs."/>
</ElicitationsGroup>

Enter fullscreen mode Exit fullscreen mode

Top comments (0)