The evidence chain
Every codafort output follows a public, versioned contract. See what each one carries, from the finding to the counter-signed declaration.
The schemas, with resolvable $id, are at codafort.dev/schemas.
The contracts
| Contract | What it is | Emitted by |
|---|---|---|
coda-finding/1 | The canonical Finding: id, moment (src/run), rule, severity, exploitability, confidence, tier, cwe, owasp, location, dataflow_path, evidence, fix, provenance | every tool |
coda-fort/1 | Source-code analysis envelope (SAST, SCA, quality, secrets/IaC, risk) | codafort engine analyze |
coda-vet/1 | Verdict on one change: blocking, advisory, axes.ran/axes.skipped, contract_breaks, scope | codafort vet |
coda-iast/1 | IAST report: which static findings were confirmed at runtime and which were not measured | codatrace collect |
coda-dast/1 | DAST report: confirmed moment: run findings, with the audit-log anchor | codaprobe scan |
coda-crash/1 · coda-profile/1 | Crash forensics (kind: analysis, triage, heap, hserr) and performance forensics | codacrash |
coda-evidence/1 | The summary each tool contributes to the counter-signed declaration | each tool |
coda-attestation/1 | The counter-signed payload: result, evidence[] and artifacts[] | codafort attest |
In the coda-<modality>/1 tag, the modality is the kind of analysis; the tool that emitted it goes in the tool field.
Evidence from other tools: coda-evidence/1
Each tool summarises its own report in a coda-evidence/1 file, which you pass to codafort attest with --evidence (full flow in Counter-signed declaration). The common fields are schema, modality (iast, vet, dast, run) and granularity (file-line, cwe); the rest depends on the modality. An IAST summary:
{ "schema": "coda-evidence/1", "modality": "iast", "granularity": "file-line",
"static_findings": 2, "confirmed_at_runtime": 1, "sanitized_at_runtime": 0, "unreached": 1,
"confirmation_rate": "0.500", "instrumentation": { "sinks_covered": 3, "by_runtime": { "python": 2, "node": 1, "jvm": 0 } } }
Examples for all four modalities at /schemas/fixtures/coda-evidence*.json.
What was not measured does not count as safe
Evidence only adds confidence. Absence of observation never becomes "safe":
unreachedmeans not measured: the route was not exercised, the sink was called with internal data, or the category produces no runtime event.axes_skippedlists the axesvetdid not run. A skipped axis is not a clean axis.granularityprevents adding up results of different precision, such as IAST'sfile-lineand DAST'scwe.- In the declaration's verdict, evidence only tightens:
confirmed-at-runtimecan turnpassintofail, andunreachedandsanitized-at-runtimedo not change the verdict.
More evidence on the same scan
To add evidence to a scan that was already declared (same commit and same result), create another declaration with --supersedes. The previous one is not edited; the new one points to it in the supersedes field. A different scan needs a new declaration, without --supersedes.
See it in practice
- Counter-signed declaration: create, verify, bundle
- What the declaration proves and does not prove, for whoever receives it, at codafort.com/attestation
- Offline verifier at codafort.com/verify