Catalog Integrity Attestation
JSON Schema for automated catalog integrity attestations
Attests conformance to the catalog-integrity standard.Download raw JSON.
What this attestation claims
It asserts one of these predicates:
catalog-structure-validcatalog-from-verified-sourcecatalog-cryptographically-signed
About: OCI reference with digest.
How it's scored
Each mapped requirement carries two independent 0.0–1.0 scores, each with a rationale: conformance (how fully the requirement is met) and confidence (how sure the assessor is of that judgement).
Who may attest
Each attestation names an assessor described by:
bom-ref(required)- a BOM reference identifying the assessor entry
component- the tool that produced the attestation (name + version)
organization- the attesting organization (name + URL)
thirdParty- whether the assessor is an independent third party
