{
  "id": 12151690,
  "title": "Building Sewline: A Compliance-Aware SDLC Engine for High-Integrity",
  "url": "https://urgent.news/2026/10/05/building-sewline-a-compliance-aware-sdlc-engine-for-high-integrity",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-05T12:39:57.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/bhkbdbhatt/building-sewline-a-compliance-aware-sdlc-engine-for-high-integrity-22df"
  },
  "original_language": "en",
  "account": "When engineering regulated products like avionics, medical devices or defense systems, a single compliance oversight can stall an entire product launch for months. Traditional CI/CD platforms such as GitHub Actions or GitLab are excellent at running scripts but have no understanding of compliance frameworks such as DO-178C, AS9100 or ISO 26262. Modern AI tools like GitHub Copilot and Codex help engineers, yet they still require strict human oversight and provenance tracking. Generating audit evidence often involves manually compiling spreadsheets, PDFs and disconnected logs.\n\nTo address this issue, a team has created Sewline, an open-source compliance-aware orchestration engine written in Rust. Sewline does not replace existing tools like GitHub Actions or Parasoft; instead, it sits on top of your existing tools to orchestrate execution, evaluate Policy-as-Code gates, and automatically generate cryptographic evidence. Sewline comprises several key components:\n\n1. A React + Tailwind visualization dashboard for easy monitoring.\n2. An HTTP/gRPC communication layer.\n3. A SEWLINE ENGINE which abstracts third-party tool execution under a clean Rust trait called StageExecutor.\n4. Policy-as-Code gates implemented with Rego/OPA policy rules.\n5. Tamper-evident DSSE attestation generation using Ed25519 cryptography.\n6. Graph-based lineage tracking using the Kùzu graph database.\n\nThe engineering team has structured Sewline as a Cargo workspace with a frontend monorepo. This includes a sewline-core crate that contains the engine, DSL parser, gate evaluator, and graph store. There is also a sewline-agent crate for the AI agent control plane, and a sewline-cli crate for a CLI runner binary. Additionally, there are ui/ and compliance_packs/ directories for the dashboard and pre-built compliance packs. Deployment files for Kubernetes are located in the deploy/ directory.\n\nTo try Sewline locally, you need Rust 1.75+ and Node.js 18+. Clone the repository, run the test suite, launch the agent governance control plane, and start the dashboard. Visit http://localhost:5173 to explore running pipelines and gate statuses.\n\nLooking ahead, the team is working on pre-packaged compliance bundles for DO-178C (DAL A–E), AS9100, and ISO 26262, as well as deeper Kubernetes operator support. The repository is available on GitHub and contributions are welcome.",
  "summary": "When building software for web apps or SaaS products, a failed build or a flaky test breaks a deployment pipeline. But when you are building software for commercial avionics, medical devices, or defense systems, a compliance oversight can stall an entire product launch for months—or worse. Engineers in regulated industries face a unique dilemma: Standard CI/CD platforms (like GitHub Actions or…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}