The evidence chain

Every codafort output follows a public, versioned contract. See what each one carries, from the finding to the counter-signed declaration.

The schemas, with resolvable $id, are at codafort.dev/schemas.

The contracts

ContractWhat it isEmitted by
coda-finding/1The canonical Finding: id, moment (src/run), rule, severity, exploitability, confidence, tier, cwe, owasp, location, dataflow_path, evidence, fix, provenanceevery tool
coda-fort/1Source-code analysis envelope (SAST, SCA, quality, secrets/IaC, risk)codafort engine analyze
coda-vet/1Verdict on one change: blocking, advisory, axes.ran/axes.skipped, contract_breaks, scopecodafort vet
coda-iast/1IAST report: which static findings were confirmed at runtime and which were not measuredcodatrace collect
coda-dast/1DAST report: confirmed moment: run findings, with the audit-log anchorcodaprobe scan
coda-crash/1 · coda-profile/1Crash forensics (kind: analysis, triage, heap, hserr) and performance forensicscodacrash
coda-evidence/1The summary each tool contributes to the counter-signed declarationeach tool
coda-attestation/1The counter-signed payload: result, evidence[] and artifacts[]codafort attest

In the coda-<modality>/1 tag, the modality is the kind of analysis; the tool that emitted it goes in the tool field.

Evidence from other tools: coda-evidence/1

Each tool summarises its own report in a coda-evidence/1 file, which you pass to codafort attest with --evidence (full flow in Counter-signed declaration). The common fields are schema, modality (iast, vet, dast, run) and granularity (file-line, cwe); the rest depends on the modality. An IAST summary:

{ "schema": "coda-evidence/1", "modality": "iast", "granularity": "file-line",
  "static_findings": 2, "confirmed_at_runtime": 1, "sanitized_at_runtime": 0, "unreached": 1,
  "confirmation_rate": "0.500", "instrumentation": { "sinks_covered": 3, "by_runtime": { "python": 2, "node": 1, "jvm": 0 } } }

Examples for all four modalities at /schemas/fixtures/coda-evidence*.json.

What was not measured does not count as safe

Evidence only adds confidence. Absence of observation never becomes "safe":

  • unreached means not measured: the route was not exercised, the sink was called with internal data, or the category produces no runtime event.
  • axes_skipped lists the axes vet did not run. A skipped axis is not a clean axis.
  • granularity prevents adding up results of different precision, such as IAST's file-line and DAST's cwe.
  • In the declaration's verdict, evidence only tightens: confirmed-at-runtime can turn pass into fail, and unreached and sanitized-at-runtime do not change the verdict.

More evidence on the same scan

To add evidence to a scan that was already declared (same commit and same result), create another declaration with --supersedes. The previous one is not edited; the new one points to it in the supersedes field. A different scan needs a new declaration, without --supersedes.

See it in practice