Schemas: the published contracts
Every artifact codafort emits follows a public, versioned contract whose $id resolves to this page. Whoever receives a report or a counter-signed declaration validates the file against the contract, without relying on whoever produced it.
The contracts
The name coda-<modality>/1 says the kind of analysis; the tool that emitted the file is in the tool field.
Counter-signed declaration (Ed25519) over a scan result, with the evidence from each analysis in
evidence[] and the artifacts in artifacts[] (in-toto format).
coda-finding/1The canonical Finding, shared by code analysis (src) and runtime analysis (run). coda-fort/1
Source-code analysis envelope. coda-dast/1
DAST envelope (live app, outside-in). coda-iast/1
IAST report: which static findings the running app confirmed and which it did not measure. coda-vet/1
The
vet verdict on a change (AI-generated code), with the axes that ran and the ones that didn't.
coda-crash/1Crash, heap and
hs_err analysis from codacrash; the kind field says which.
coda-profile/1Performance profile from codacrash. codafort-interaction/1
An agent's use of codafort in a repository connected to the platform.
Examples captured from real runs at /schemas/fixtures/. How the artifacts fit together: The evidence chain.
Versioning
New fields are optional and only appear when used. A breaking change gets a new tag (/2). Signed artifacts are never re-signed: tokens already issued stay verifiable, including those in the old codafort-attestation/1 format.
What these artifacts do not prove
A counter-signed declaration proves the integrity and authorship of the result, not the absence of vulnerabilities. artifacts[] is declared by the emitter and does not prove the link between build and source (that's build provenance, SLSA L2+). The report states what was not measured (unreached, axes_skipped), and not measured never means safe. Verification (/verify, offline) is free for any party, forever.