result.json — schema v1
Stable contract for SecureFix CLI / GUI / Evidence Bundle. Phase 1 commercial language: Go. Demo fixtures only — not a compliance standard.
Full field notes also live in the ENISA dossier (RESULT-SCHEMA.md). Public summary:
schema— always"1"until a breaking bumpaudit_run_id,submission_id,tenant_idproduct_version,language(Phase 1 offer:go)status,findings[],exit_codes,duration_secpolicy_pack— technical rule profile (e.g.securefix-default-v1), not a certification claimprovenance— git commit/branch/working_tree, config_hash, excluded_paths / scope (when available)code_fingerprint— hash of audited sources when set
Bundle companions: scanner_versions.json, validation.json / manifest hashes,
human PDF / markdown report. Hashes prove pack integrity after seal — not cryptographic attestation of who pressed Run (roadmap).