Real packages, direct
Imports STIG XCCDF XML straight from Cyber Exchange ZIP packages — profile selection, resolved values, and readable rendering of rich check and fix content, as a cancellable background job.
A cross-platform desktop editor for DoD STIG checklists, built with Go + Wails. It imports Cyber Exchange ZIP/XML packages, tracks review states and evidence, matches your host against the official STIG catalog, and exports CKL and STIG Viewer 3 CKLB files.
Reviewing STIGs normally means STIG Viewer plus manual bookkeeping: fragile unsaved work, format churn between JSON, CKL, and CKLB, and matching hosts to the right STIGs by hand. This editor makes the whole loop one keyboard-driven tool.
Imports STIG XCCDF XML straight from Cyber Exchange ZIP packages — profile selection, resolved values, and readable rendering of rich check and fix content, as a cancellable background job.
Open, Closed, Not Applicable, and Not Reviewed — with Findings, Comments, reviewer fields, and backend-authored guidance when evidence is missing or inconsistent.
Saves editable checklist JSON and exports classic CKL plus STIG Viewer 3 CKLB 1.0 — with real target-asset metadata carried into every format.
Reads local OS and installed-software inventory, matches it against the public DoD Cyber Exchange catalog, and downloads official packages only from dl.dod.cyber.mil.
Multi-rule selection, batch status changes, batch Findings and Comments with explicit Keep, Append, or Replace modes, column sorting, and desktop keyboard shortcuts.
Dirty-state tracking guards Import, Open, Create, and native window close; atomic private autosaves offer recovery on next launch instead of silently losing an afternoon of review.
The editor walks the full checklist lifecycle without leaving the app.
Read the local OS and installed software, then match against the current public Cyber Exchange catalog.
Preview XCCDF profiles with their rule counts, then run validation and queue construction with live progress.
Work the queue with four review states, findings, comments, and batch actions — sorted and filtered your way.
Save the editable JSON working copy, then export CKL or CKLB for the ATO package.
The repository is private while the editor matures. If you review STIGs for a living and want a walkthrough, email me.