CDF provenance
What produced a governed artefact. CORRECTED against real artefacts: the record is never written bare. It is wrapped under a cdf key in Markdown front-matter, and wrapped again as {artefact_path, cdf} in .cdf/specs/<slug>/provenance.jsonl. The TypeScript interface describes only the inner record, and nothing in the type system said so. Validate a front-matter block against #/definitions/frontMatter, a journal line against #/definitions/journalEntry, and the inner object against #/definitions/record. anyOf, not oneOf: a journal entry also satisfies the front-matter shape, since that only requires cdf. Prefer validating against the precise definition you expect.
- Schema
provenance.schema.json, served as JSON at its$id: https://cognitive-delivery.github.io/contract/1.x/provenance.schema.json- Dialect
http://json-schema.org/draft-07/schema#- Root
- object; any of: (1) #journalEntry; (2) #frontMatter
- Stability
- none stated at the root; every declared property carries its own
- Properties
- 25 declared: 0 under the root, 25 in definitions
Properties
Every declared property under the root, in the schema's own order. [] is an array's items, .* the shape of every unnamed member, #name a definition. Objects carry additional properties unless a row says otherwise.
The root declares no properties of its own; see the definitions.
Definitions
The named shapes this schema refers to as #name. A row above that links here is not expanded in place; its constraints are the definition's.
#record: The provenance record itself
| Path | Type | Required | Description | Constraints | Stability |
|---|---|---|---|---|---|
#record | object | The provenance record itself | |||
#record.schema_version | string | yes | Contract version this record was written against. Required: a conformant writer always writes it. A reader meeting a pre-contract artefact without it MAY read it as 1.0; it must not emit one. Written as major.minor. | pattern ^\d+\.\d+$ | stable |
#record.spec | string | yes | Slug of the governed spec this artefact belongs to: lower-case letters, digits and hyphens, at most 80 characters. It names a directory, so a path form is refused; every one of the reference deployment's 263 specs already conformed. | pattern ^[a-z0-9][a-z0-9-]{0,79}$ | stable |
#record.phase | string | yes | The lifecycle phase this artefact was produced in. An OPEN string, deliberately: the phase vocabulary belongs to the domain, not to the contract. A reader must not assume any fixed set of values. | stable | |
#record.author | string | yes | stable | ||
#record.runtime_agent | string | yes | Which agent produced this. Attribution, not authentication. | stable | |
#record.coding_assistant | string | stable | |||
#record.model_vendor | string | yes | stable | ||
#record.model_family | string | yes | stable | ||
#record.model_version | string | stable | |||
#record.adoption_tier | integer | yes | How much governance this workspace has adopted. Closed: the tiers are the framework. | one of 1, 2, 3, 4max 9007199254740991 | stable |
#record.prompt_hash | string | yes | SHA-256 of the request, lower-case hex. NEVER the request itself; the pattern refuses anything that is not a 64-character digest. | pattern ^[0-9a-f]{64}$ | stable |
#record.steering_hash | string | yes | SHA-256 of the steering the artefact was produced under, lower-case hex. A writer that cannot compute it writes 64 zeros, which the reference deployment did for 4,524 of 4,535 records; the shape is still a digest. | pattern ^[0-9a-f]{64}$ | stable |
#record.content_hash | string | SHA-256 of the artefact body only, excluding this front-matter block, lower-case hex. | pattern ^[0-9a-f]{64}$ | stable | |
#record.timestamp | string | yes | ISO 8601 with a timezone. | pattern ^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}(\.\d+)?(Z|[+-]\d{2}:\d{2})$ | stable |
#record.reviewer | string | null | yes | Null means not yet reviewed. Null is a value here, not an omission. | stable | |
#record.review_id | string | null | yes | stable | ||
#record.policy_version | string | yes | stable | ||
#record.implemented_symbols | array | Resolved implementing symbols for the spec's declared requirements. Additive and optional: omitted entirely when nothing resolves, never an empty array. Excluded from content_hash, so it can never affect verification. | stable | ||
#record.implemented_symbols[] | object | ||||
#record.implemented_symbols[].requirementId | string | stable | |||
#record.implemented_symbols[].symbolName | string | stable | |||
#record.implemented_symbols[].path | string | stable | |||
#record.implemented_symbols[].line | integer | max 9007199254740991 | stable |
#frontMatter
| Path | Type | Required | Description | Constraints | Stability |
|---|---|---|---|---|---|
#frontMatter | object | The front-matter form: the record under a cdf key. No artefact_path — the file is the artefact. | |||
#frontMatter.cdf | object #record | yes | stable |
#journalEntry
| Path | Type | Required | Description | Constraints | Stability |
|---|---|---|---|---|---|
#journalEntry | object | One line of provenance.jsonl: the record under cdf, plus the path of the artefact it describes. | |||
#journalEntry.artefact_path | string | yes | stable | ||
#journalEntry.cdf | object #record | yes | stable |