Static Analysis Attestation
JSON Schema for static application security testing attestations in CycloneDX format
Attests conformance to the static-analysis standard.Download raw JSON.
What this attestation claims
It asserts exactly one claim: passed-static-analysis.
About: The artifact this claim is about (image digest or PURL).
How it's scored
Each mapped requirement carries two independent 0.0–1.0 scores, each with a rationale: conformance (how fully the requirement is met) and confidence (how sure the assessor is of that judgement).
Who may attest
Each attestation names an assessor described by:
bom-ref(required)- Unique identifier for this assessor
component(required)- the tool that produced the attestation (name + version)
organization- the attesting organization (name + URL)
thirdParty- Whether this is a third-party assessor
