Add canonical assertion envelopes for v0.4.0
This commit is contained in:
@@ -0,0 +1,41 @@
|
||||
{
|
||||
"registry_version": "1.0",
|
||||
"provenance_schema_version": "1.0",
|
||||
"application_version": "0.4.0",
|
||||
"name": "assertion-boundary-kinds",
|
||||
"description": "Machine-readable boundaries preventing an unqualified exact conclusion.",
|
||||
"entries": [
|
||||
{
|
||||
"code": "missing_provenance",
|
||||
"meaning": "Required provenance basis or evidence identity is absent."
|
||||
},
|
||||
{
|
||||
"code": "unknown_generation",
|
||||
"meaning": "A required source or dependency generation is unknown."
|
||||
},
|
||||
{
|
||||
"code": "evidence_access",
|
||||
"meaning": "Evidence exists or is expected but cannot currently be accessed."
|
||||
},
|
||||
{
|
||||
"code": "compatibility",
|
||||
"meaning": "The observed schema or producer contract is incompatible."
|
||||
},
|
||||
{
|
||||
"code": "dependency_change",
|
||||
"meaning": "A dependency digest, generation, or source anchor changed."
|
||||
},
|
||||
{
|
||||
"code": "policy",
|
||||
"meaning": "A retention, authorization, or disclosure policy prohibits evaluation."
|
||||
},
|
||||
{
|
||||
"code": "interpretation",
|
||||
"meaning": "Evidence integrity is known but its asserted interpretation is limited."
|
||||
},
|
||||
{
|
||||
"code": "coverage",
|
||||
"meaning": "The evaluation does not cover every element required by the assertion scope."
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"registry_version": "1.0",
|
||||
"provenance_schema_version": "1.0",
|
||||
"application_version": "0.4.0",
|
||||
"name": "assertion-confidence-dimensions",
|
||||
"description": "Independent non-numeric confidence dimensions.",
|
||||
"values": [
|
||||
"exact",
|
||||
"degraded",
|
||||
"unverified",
|
||||
"not_applicable"
|
||||
],
|
||||
"entries": [
|
||||
{
|
||||
"code": "integrity",
|
||||
"meaning": "Whether canonical bytes, digests, and chain bindings validate."
|
||||
},
|
||||
{
|
||||
"code": "identity",
|
||||
"meaning": "Whether referenced subjects, objects, producers, and evidence identities resolve."
|
||||
},
|
||||
{
|
||||
"code": "chronology",
|
||||
"meaning": "Whether ordering and generation coordinates are complete and consistent."
|
||||
},
|
||||
{
|
||||
"code": "derivation",
|
||||
"meaning": "Whether the asserted transformation or relationship is supported by evidence."
|
||||
},
|
||||
{
|
||||
"code": "authorship",
|
||||
"meaning": "Whether the claimed actor relationship is supported without percentage attribution."
|
||||
},
|
||||
{
|
||||
"code": "completeness",
|
||||
"meaning": "Whether all evidence required for the asserted scope was evaluated."
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,34 @@
|
||||
{
|
||||
"registry_version": "1.0",
|
||||
"provenance_schema_version": "1.0",
|
||||
"application_version": "0.4.0",
|
||||
"name": "assertion-evaluation-statuses",
|
||||
"description": "Consumer-facing point-in-time assertion conclusions.",
|
||||
"entries": [
|
||||
{
|
||||
"code": "exact",
|
||||
"consumer_action": "promote",
|
||||
"meaning": "All mandatory evidence and relevant confidence dimensions support the asserted scope."
|
||||
},
|
||||
{
|
||||
"code": "degraded",
|
||||
"consumer_action": "warn",
|
||||
"meaning": "Use is possible only within the recorded uncertainty boundary."
|
||||
},
|
||||
{
|
||||
"code": "refused",
|
||||
"consumer_action": "refuse",
|
||||
"meaning": "Policy, authorization, or compatibility prohibits a conclusion."
|
||||
},
|
||||
{
|
||||
"code": "stale",
|
||||
"consumer_action": "reevaluate",
|
||||
"meaning": "A source anchor, digest, or generation dependency changed."
|
||||
},
|
||||
{
|
||||
"code": "unverified",
|
||||
"consumer_action": "withhold_exact",
|
||||
"meaning": "Mandatory evaluation or evidence is incomplete without a demonstrated contradiction."
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"registry_version": "1.0",
|
||||
"provenance_schema_version": "1.0",
|
||||
"application_version": "0.4.0",
|
||||
"name": "assertion-evidence-classes",
|
||||
"description": "Evidence availability and authority requirements.",
|
||||
"entries": [
|
||||
{
|
||||
"code": "mandatory_live",
|
||||
"exact_effect": "required",
|
||||
"meaning": "Current accessible evidence is required for exact evaluation."
|
||||
},
|
||||
{
|
||||
"code": "mandatory_retained",
|
||||
"exact_effect": "required",
|
||||
"meaning": "Retained authoritative evidence and its digest are required for exact evaluation."
|
||||
},
|
||||
{
|
||||
"code": "advisory",
|
||||
"exact_effect": "may_degrade",
|
||||
"meaning": "Absence may degrade a named dimension but does not alter authoritative evidence."
|
||||
},
|
||||
{
|
||||
"code": "shadow",
|
||||
"exact_effect": "no_authority",
|
||||
"meaning": "Comparison-only evidence that never becomes authoritative by observation."
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,45 @@
|
||||
{
|
||||
"registry_version": "1.0",
|
||||
"provenance_schema_version": "1.0",
|
||||
"application_version": "0.4.0",
|
||||
"name": "assertion-lifecycle-phases",
|
||||
"description": "Immutable assertion lifecycle phase observed when the relationship was asserted.",
|
||||
"entries": [
|
||||
{
|
||||
"code": "proposed",
|
||||
"meaning": "A relationship has been proposed but not adopted."
|
||||
},
|
||||
{
|
||||
"code": "generated",
|
||||
"meaning": "A relationship was produced by a deterministic or model-assisted operation."
|
||||
},
|
||||
{
|
||||
"code": "staged_preview",
|
||||
"meaning": "The relationship is visible for review but not accepted into canonical work."
|
||||
},
|
||||
{
|
||||
"code": "accepted_into_work",
|
||||
"meaning": "The relationship was explicitly accepted into canonical project work."
|
||||
},
|
||||
{
|
||||
"code": "revised",
|
||||
"meaning": "The relationship describes a later immutable revision."
|
||||
},
|
||||
{
|
||||
"code": "finalized",
|
||||
"meaning": "The relationship belongs to finalized project content."
|
||||
},
|
||||
{
|
||||
"code": "published",
|
||||
"meaning": "The relationship is bound into a published release."
|
||||
},
|
||||
{
|
||||
"code": "superseded",
|
||||
"meaning": "A later assertion replaces this relationship for current interpretation without erasing it."
|
||||
},
|
||||
{
|
||||
"code": "purged",
|
||||
"meaning": "The relationship is affected by an explicitly disclosed emergency reconstitution."
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,124 @@
|
||||
{
|
||||
"registry_version": "1.0",
|
||||
"provenance_schema_version": "1.0",
|
||||
"application_version": "0.4.0",
|
||||
"name": "assertion-reason-codes",
|
||||
"description": "Stable explanations for assertion creation and evaluation outcomes.",
|
||||
"entries": [
|
||||
{
|
||||
"code": "DIRECT_HASH_LINKED_DERIVATION",
|
||||
"permitted_statuses": [
|
||||
"exact"
|
||||
],
|
||||
"meaning": "The asserted relationship is supported by direct retained records and matching digests."
|
||||
},
|
||||
{
|
||||
"code": "VERIFIED_TRANSITIVE_DERIVATION",
|
||||
"permitted_statuses": [
|
||||
"exact"
|
||||
],
|
||||
"meaning": "A deterministic verified chain of assertions supports the relationship."
|
||||
},
|
||||
{
|
||||
"code": "REQUIRED_PROVENANCE_UNKNOWN",
|
||||
"permitted_statuses": [
|
||||
"unverified"
|
||||
],
|
||||
"meaning": "Required provenance basis or evidence identity is unknown."
|
||||
},
|
||||
{
|
||||
"code": "SOURCE_GENERATION_UNKNOWN",
|
||||
"permitted_statuses": [
|
||||
"unverified"
|
||||
],
|
||||
"meaning": "A required project, artifact, or transcript generation is unknown."
|
||||
},
|
||||
{
|
||||
"code": "REQUIRED_EVIDENCE_MISSING",
|
||||
"permitted_statuses": [
|
||||
"unverified"
|
||||
],
|
||||
"meaning": "Evidence required for evaluation is absent."
|
||||
},
|
||||
{
|
||||
"code": "DEPENDENCY_DIGEST_MISMATCH",
|
||||
"permitted_statuses": [
|
||||
"stale"
|
||||
],
|
||||
"meaning": "A dependency digest differs from the asserted expectation."
|
||||
},
|
||||
{
|
||||
"code": "DEPENDENCY_GENERATION_MISMATCH",
|
||||
"permitted_statuses": [
|
||||
"stale"
|
||||
],
|
||||
"meaning": "A dependency generation differs from the asserted expectation."
|
||||
},
|
||||
{
|
||||
"code": "SOURCE_ANCHOR_STALE",
|
||||
"permitted_statuses": [
|
||||
"stale"
|
||||
],
|
||||
"meaning": "The source anchor no longer matches the evaluation target."
|
||||
},
|
||||
{
|
||||
"code": "SCHEMA_INCOMPATIBLE",
|
||||
"permitted_statuses": [
|
||||
"refused"
|
||||
],
|
||||
"meaning": "The available schema cannot be evaluated under the required contract."
|
||||
},
|
||||
{
|
||||
"code": "POLICY_REFUSED",
|
||||
"permitted_statuses": [
|
||||
"refused"
|
||||
],
|
||||
"meaning": "Policy explicitly prohibits producing the requested conclusion."
|
||||
},
|
||||
{
|
||||
"code": "AUTHORIZED_EVIDENCE_UNAVAILABLE",
|
||||
"permitted_statuses": [
|
||||
"refused",
|
||||
"unverified"
|
||||
],
|
||||
"meaning": "Required protected evidence cannot be evaluated with current authorization."
|
||||
},
|
||||
{
|
||||
"code": "ADVISORY_EVIDENCE_UNAVAILABLE",
|
||||
"permitted_statuses": [
|
||||
"degraded"
|
||||
],
|
||||
"meaning": "Advisory evidence is unavailable and the named confidence dimensions are degraded."
|
||||
},
|
||||
{
|
||||
"code": "ASSERTION_NOT_EVALUATED",
|
||||
"permitted_statuses": [
|
||||
"unverified"
|
||||
],
|
||||
"meaning": "No authoritative evaluation has completed for this assertion and target."
|
||||
},
|
||||
{
|
||||
"code": "AUTHORSHIP_UNCERTAIN",
|
||||
"permitted_statuses": [
|
||||
"degraded"
|
||||
],
|
||||
"meaning": "Evidence does not support an exact authorship interpretation."
|
||||
},
|
||||
{
|
||||
"code": "CHRONOLOGY_INCOMPLETE",
|
||||
"permitted_statuses": [
|
||||
"degraded",
|
||||
"unverified"
|
||||
],
|
||||
"meaning": "Ordering or generation evidence is incomplete."
|
||||
},
|
||||
{
|
||||
"code": "COMPLETENESS_INCOMPLETE",
|
||||
"permitted_statuses": [
|
||||
"degraded",
|
||||
"unverified"
|
||||
],
|
||||
"meaning": "The evaluation does not cover all evidence required by its asserted scope."
|
||||
}
|
||||
]
|
||||
}
|
||||
Reference in New Issue
Block a user