Skip to content

Static Analysis Attestation

JSON Schema for static application security testing attestations in CycloneDX format

Attests conformance to the static-analysis standard.Download raw JSON.

What this attestation claims

It asserts exactly one claim: passed-static-analysis.

About: The artifact this claim is about (image digest or PURL).

How it's scored

Each mapped requirement carries two independent 0.0–1.0 scores, each with a rationale: conformance (how fully the requirement is met) and confidence (how sure the assessor is of that judgement).

Who may attest

Each attestation names an assessor described by:

bom-ref (required)
Unique identifier for this assessor
component (required)
the tool that produced the attestation (name + version)
organization
the attesting organization (name + URL)
thirdParty
Whether this is a third-party assessor