result.json — schema v1
Stable contract for SecureFix CLI / GUI / Evidence Bundle.
Product 2.0 · pilot candidate — same schema for
go, python, and javascript.
Public site samples remain Go fixtures; Python/JS and mixed delivery use this schema in the operator GUI.
Demo fixtures only — not a compliance standard.
Full field notes also live in the ENISA dossier (RESULT-SCHEMA.md). Public summary:
schema— always"1"until a breaking bumpaudit_run_id,submission_id,tenant_idproduct_version,language(go|python|javascript— dominant language in mixed runs)languages[],run_kind(mixed_deliverywhen one pack covers multiple contour languages),language_scopes[]status,findings[](optionalfinding.language),exit_codes,duration_secpolicy_pack— technical rule profile (e.g.baseline), not a certification claimprovenance— git commit/branch/working_tree, config_hash, excluded_paths / scope (when available)code_fingerprint— hash of audited sources when set
Bundle companions: scanner_versions.json, validation.json / manifest hashes,
human PDF / markdown report. Hashes prove pack integrity after seal — not cryptographic attestation of who pressed Run (roadmap).