kaos-compliance is a continuously-refreshed, public compliance and supply-chain dashboard. A stdlib-only collector reads only public sources — the GitHub API, PyPI, sigstore's transparency log, the OSV and GitHub advisory databases — on a schedule, writes one signed JSON snapshot, and renders it to a set of static pages. The dashboard tracks the same 18 packages listed on /packages; it is the authority that page is reconciled against.
It is anchored to the frameworks security and procurement teams already cite — OpenSSF Scorecard, SLSA, NIST SSDF (SP 800-218), the CISA SBOM Minimum Elements, PEP 740 with sigstore and PyPI Trusted Publishers, and the EU Cyber Resilience Act. And it is deliberately restrained: no invented composite score, no GitHub-star count, no maintainer-identity signals. Its own README puts it plainly — it should make maintainers slightly uncomfortable and procurement slightly happier.