Analysis Provenance Attestation
JSON Schema for analysis-provenance attestations in CycloneDX declarations format. Shape-only: inputRefs resolution into the sealed catalog, methodRef gate resolution, and Fulcio identity comparison (author distinct from approver) are verifier (adbom-cli) checks. Normative requirements: https://sec.hypermedia.au/standards/analysis-provenance/v1 Cross-document convention (ratified 2026-07-18): map.requirement cites the requirement's published URL (pattern-pinned, offline-checkable); claim.target is a BOM-Link to the L2 Finding. These deliberately reference documents outside this BOM; resolution is via sec.hypermedia.au and BOM-Links.
Attests conformance to the analysis-provenance standard.Download raw JSON.
What this attestation claims
It asserts exactly one claim: produced-from-declared-evidence.
About: APRV-008: BOM-Link to the L2 Finding — matching ^urn:cdx:.+#finding-.+.
Reasoning: a written justification is optional.
Evidence: one or more references to evidence items, by bom-ref.
How it's scored
Each mapped requirement carries two independent 0.0–1.0 scores, each with a rationale: conformance (how fully the requirement is met) and confidence (how sure the assessor is of that judgement).
Signing & trust
Signed with ES256 / ES384 / ES512.
Keyless signing via a Fulcio certificate — the signer's identity is bound in the certificate path, so there's no long-lived key to manage.
Who may attest
Each attestation names an assessor described by:
bom-ref(required)- a BOM reference identifying the assessor entry
thirdParty- whether the assessor is an independent third party
organization(required)- the attesting organization (name + URL)
