When building software for web apps or SaaS products, a failed build or a flaky test breaks a deployment pipeline. But when you are building software for commercial avionics, medical devices, or defense systems, a compliance oversight can stall an entire product launch for monthsβor worse.
Engineers in regulated industries face a unique dilemma:
- Standard CI/CD platforms (like GitHub Actions or GitLab) are great at running scripts, but know nothing about compliance frameworks (DO-178C, AS9100, ISO 26262).
- Modern engineering uses AI agents (Copilot, Codex), but regulatory frameworks require strict human-in-the-loop approvals and provenance tracking.
- Generating audit evidence usually means manually compiling spreadsheets, PDFs, and disconnected logs.
To solve this, we built Sewlineβan open-source, compliance-aware orchestration engine written in Rust.
π‘ What is Sewline?
Sewline isn't a replacement for GitHub Actions, Parasoft, or Jama Connect. Instead, it sits on top of your existing tools to orchestrate execution, evaluate Policy-as-Code gates, and automatically generate cryptographic evidence.
+-------------------------------------------------+
| USER INTERFACE |
| React + Tailwind Visualization Dashboard |
+------------------------+------------------------+
|
HTTP / gRPC
|
v
+-------------------------------------------------------------------------------------------------------------------+
| SEWLINE ENGINE |
| |
| +-----------------------------------+ +----------------------------------+ +--------------------------+ |
| | Workflow DSL | | Gate Engine | | Context Store | |
| | Declarative YAML/JSON Pipeline |---->| - OPA / Rego Policy Evaluator |---->| - KΓΉzu / Lineage Graph | |
| | Conditional Branches & Parallel | | - DSSE Attestation Generator | | - Traceability Matrix | |
| +-----------------+-----------------+ +-----------------+----------------+ +--------------------------+ |
| | | |
| v v |
| +----------------------------------------------------------------------------+ |
| | STAGE EXECUTOR | |
| | Plugin Adapter Abstraction Layer | |
| +--------+----------------------------------+-----------------------+--------+ |
| | | | |
+-----------|----------------------------------|-----------------------|--------------------------------------------+
| | |
v v v
+-----------------------+ +-----------------------+ +-----------------------+
| GitHub Actions / CI | | Parasoft C/C++test | | Jama Connect |
| (Source & Sync) | | (Static Analysis) | | (Requirements Trace) |
+-----------------------+ +-----------------------+ +-----------------------+
π₯ Key Technical Capabilities
1. Unified Plugin-Based Adapters (StageExecutor)
We abstracted all third-party dev tool execution under a clean Rust trait:
#[async_trait]
pub trait StageExecutor: Send + Sync {
async fn execute(&self, stage: &Stage) -> Result<StageResult, EngineError>;
}
Whether syncing a commit via GitHub Actions, triggering static code analysis with Parasoft, or pulling requirements from Jama, stages run deterministically within the execution DAG.
2. Policy-as-Code Gates (Rego / OPA)
Compliance isn't a post-hoc manual check anymore. Every stage in a Sewline pipeline runs against explicit Policy-as-Code gates:
stages:
- id: static_analysis
name: Parasoft Static Analysis
adapter: adapter-parasoft
gates:
- id: gate_zero_misra_violations
name: Zero MISRA C:2012 Violations
policy_rule: sewline.parasoft.zero_violations
enforce: true
3. Tamper-Evident DSSE Attestations
Every time a gate passes or fails, Sewline generates signed, content-addressed DSSE (Dead Simple Signing Envelope) evidence statements using standard Ed25519 cryptography. Auditors don't need to take your word for itβthey can verify the cryptographic chain of proof.
4. Graph-Based Lineage Tracking (KΓΉzu)
Using the embedded graph database KΓΉzu, Sewline logs end-to-end lineage across all runs:
$$\text{Requirement} \longleftrightarrow \text{Commit} \longleftrightarrow \text{Static Analysis} \longleftrightarrow \text{DSSE Attestation}$$
ποΈ The Monorepo Architecture
We structured Sewline as a Cargo Workspace + Frontend Monorepo for clean domain separation:
sewline/
βββ Cargo.toml # Workspace manifest
βββ crates/
β βββ sewline-core/ # Engine, DSL parser, Gate evaluator & Graph store
β βββ sewline-agent/ # AI Agent Control Plane (gRPC + SQLite)
β βββ sewline-cli/ # CLI runner binary
βββ ui/ # Dashboard (React + TypeScript + Tailwind)
βββ compliance_packs/ # Pre-built Rego rules (DO-178C, AS9100)
βββ deploy/ # Kubernetes Operator & Tenant CRDs
π Trying It Out Locally
Interested in running Sewline on your machine? You'll need Rust 1.75+ and Node.js 18+.
# 1. Clone the repo & run test suite
git clone [https://github.com/bhkbdbhatt/sewline.git](https://github.com/bhkbdbhatt/sewline.git)
cd sewline
cargo test --workspace
# 2. Launch the Agent Governance Control Plane
cargo run --bin sewline-agent
# 3. Spin up the Dashboard (in a second terminal)
cd ui
npm install
npm run dev
Visit http://localhost:5173 to explore running pipelines and gate statuses!
π¬ What's Next?
We are actively building out pre-packaged compliance bundles for DO-178C (DAL AβE), AS9100, and ISO 26262, along with deeper Kubernetes operator support.
Check out the repo on GitHub, star it if you find it interesting, and drop your thoughts or questions in the comments below!
π GitHub: github.com/bhkbdbhatt/sewline
<ElicitationsGroup message="Here are a few ways to extend or promote this content:">
<Elicitation label="Draft social media announcement posts (X/Twitter & LinkedIn)" query="Draft engaging social media post templates for Twitter/X and LinkedIn to promote this DEV.to post and GitHub repository."/>
<Elicitation label="Create a step-by-step contributing guide (CONTRIBUTING.md)" query="Create a CONTRIBUTING.md file for the Sewline workspace detailing how to add new stage adapters and compliance packs."/>
</ElicitationsGroup>
Top comments (0)