generated: '2026-08-29' method: derived source: >- grpc/ (18 OpenCue .proto files harvested from github.com/AcademySoftwareFoundation/OpenCue/tree/master/proto/src), https://github.com/AcademySoftwareFoundation/OpenCue/blob/master/docs/_docs/reference/rest-api-reference.md, https://github.com/AcademySoftwareFoundation/tac standards: - id: protobuf3 name: Protocol Buffers v3 conforms: true evidence: >- All 18 harvested .proto files declare syntax = "proto3". 28 services, 304 RPCs. grpc/academy-software-foundation-opencue-job.proto alone declares FrameInterface, GroupInterface, JobInterface and LayerInterface. - id: grpc name: gRPC conforms: true evidence: >- Every OpenCue interface is a gRPC service; Cuebot is the server and PyCue (pypi opencue-pycue) is the first-party client. Compiled stubs ship as pypi opencue-proto. - id: grpc-gateway name: grpc-gateway HTTP/JSON transcoding conforms: true evidence: >- The REST Gateway is generated by grpc-gateway with generate_unbound_methods=true; paths take the form POST /./ and bodies are camel-cased protobuf messages. - id: openapi2 name: OpenAPI 2.0 (Swagger) conforms: true partial: true evidence: >- The gateway serves 18 OpenAPI 2.0 documents at /swagger/specs/.swagger.json, generated at Docker build time by protoc-gen-openapiv2. They are not committed to the repository, so they can only be fetched from a running gateway — this repo holds the .proto sources they are generated from instead. - id: jwt name: JSON Web Token (RFC 7519) conforms: true evidence: 'HS256, required claims sub and exp, Authorization: Bearer .' - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: >- Errors are gRPC statuses rendered as JSON ({"code":5,"message":"Not Found","details":[]}), not application/problem+json. - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No authorization server. /.well-known/oauth-authorization-server returned 404 on every ASWF host probed 2026-08-29. - id: oidc name: OpenID Connect conforms: false evidence: /.well-known/openid-configuration returned 404 on every ASWF host probed 2026-08-29. - id: rfc9727 name: RFC 9727 api-catalog conforms: true evidence: >- https://www.aswf.io/.well-known/api-catalog returns HTTP 200 with content-type application/linkset+json and a linkset naming service-desc https://www.aswf.io/wp-json/. Saved verbatim at well-known/academy-software-foundation-api-catalog.json. caveat: >- This describes the WordPress REST API behind the foundation's own website, not an ASWF product API. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: 404 on every host probed; disclosure policy is published as per-repository SECURITY.md instead. - id: rfc8594 name: RFC 8594 Sunset header conforms: false evidence: No ASWF-operated origin exists to emit Sunset or Deprecation headers. - id: idempotency name: Idempotency keys conforms: false evidence: No idempotency key or dedupe window is documented for any gateway endpoint. - id: pagination name: Collection pagination conforms: false evidence: >- No page/limit/offset/cursor parameter in any proto request message; collections are returned whole and narrowed with search-criteria messages. domain_standards: note: >- REWARD-ONLY and deliberately conservative. ASWF's market — motion picture, VFX and animation pipelines — does have domain standards, and ASWF AUTHORS several of them. But domain_standard_conformance reads the CONTRACT declaring a standard, and the OpenCue protos declare none: render-farm management has no cross-vendor standard for OpenCue to speak. The entries below record what ASWF publishes as a standards body, with evidence, and are NOT claimed as conformance of this repo's contracts. authored_by_provider: - standard: OpenEXR / SMPTE ST 2065-4 container role: reference implementation and specification url: https://openexr.com/ - standard: OpenColorIO color transform configuration role: specification and reference implementation url: https://opencolorio.org/ - standard: OpenTimelineIO editorial interchange schema role: specification, JSON serialization and reference API url: https://opentimeline.io/ - standard: MaterialX material interchange role: specification and reference implementation url: https://www.materialx.org/Specification.html - standard: OpenFX image effect plug-in API role: specification url: https://openfx.io/ - standard: OpenPBR Surface shading model role: specification and reference implementation url: https://academysoftwarefoundation.github.io/OpenPBR/ - standard: OpenAPV (Advanced Professional Video) codec role: royalty-free specification and reference implementation url: https://github.com/AcademySoftwareFoundation/openapv - standard: Open Shading Language role: language specification and reference implementation url: https://github.com/AcademySoftwareFoundation/OpenShadingLanguage contract_declared_domain_standard: false compliance: certifications: [] note: >- ASWF is a Linux Foundation directed fund, not a service operator, so it holds no SOC 2, ISO 27001, PCI or FedRAMP attestation and publishes no trust center. Its published assurance program is governance-shaped: Technical Charters, CLA templates, license scans at project intake, an OpenSSF Best Practices badge process, and per-project coordinated disclosure with a 48-hour acknowledgement SLA. Recorded honestly rather than left blank. governance_artifacts: - name: Project lifecycle policy url: https://github.com/AcademySoftwareFoundation/tac/blob/main/process/lifecycle.md - name: Security best practices guide url: https://github.com/AcademySoftwareFoundation/tac/blob/main/project_best_practices_guides/security.md - name: OpenSSF Best Practices badge process url: https://github.com/AcademySoftwareFoundation/tac/blob/main/process/best_practices_badge.md - name: Contributor License Agreement templates url: https://github.com/AcademySoftwareFoundation/tac/tree/main/process/cla - name: Linux Foundation trademark usage policy url: https://www.linuxfoundation.org/trademark-usage