Attestation-scoped input

The input an attestation-scoped policy receives, with TypeScript types and a sample.

This page lists the JSON input an attestation-scoped policy receives, whether it is built in the Visual Builder or written in Rego or JavaScript. For how to write a policy, see Write and test policies.

Top-level fields

An attestation-scoped policy is called once per attestation, with attestation carrying its metadata and raw the document contents as JSON (converted if the source is XML). raw is only loaded when the policy text contains input.raw, so a policy that only reads metadata stays fast:

{
  attestation: { ... },
  raw: { ... },
  namespace: { tenantId, space }
}
Policy input
NamespacetenantId, space
Attestationstatus, type, format, hashes, TLP
Raw contentsdocument JSON, converted from XML
AttestationComponentpurl, name, version, type
LicenseChoice[]expression or License
Supplieralso as manufacturer
ExternalReference[]type, url, hashes

TypeScript types

Below is the input as TypeScript types. Not every field is set on every input, so check for missing values in a policy.

// this is the top-level object that is passed to the policy
type PolicyInputType = {
  namespace?: Namespace;
  attestation?: Attestation;
};

type Namespace = {
  tenantId: OrganizationId;
  space: string;
};

type AttestationStatus = "pending" | "ok" | "invalid" | "archived";
type AttestationType = "SPDX" | "CycloneDx" | "OpenVEX" | "SLSA" | "in-toto" | "Kubernetes" | "unknown";
type AttestationContentType = "SBOM" | "CBOM" | "HBOM" | "VEX" | "VDR" | "Provenance";
type DocumentFormat = "JSON" | "YAML" | "XML" | "RDF" | "TAG-VALUE" | "unknown";

type AttestationComponent = {
  id?: ComponentRef;
  type?: ComponentType;
  packageUrl?: string;
  name?: string;
  group?: string;
  version?: string;
  supplier?: Supplier;
  manufacturer?: Supplier;
  externalReferences?: ExternalReference[];
  hashes?: Record<string, string>;
  licenses?: LicenseChoice[];
  properties?: Record<string, any>;
};

type Attestation = {
  id: string;
  status: AttestationStatus;
  errorMessage?: string;
  type: AttestationType;
  contents?: AttestationContentType[];
  typeSpecVersion: string;
  format: DocumentFormat;
  sourceFileName: string;
  component: AttestationComponent;
  componentsCount: number;
  distributionConstraints: DistributionConstraints;
  hashes: Record<string, string>;
  timestamp: string;
  properties?: Record<string, any>;
  createdAt: string;
  updatedAt: string;
};

type SupplierType = "ORGANIZATION" | "PERSON";

type Supplier = {
  id?: SupplierId;
  name: string;
  type: SupplierType;
  address?: OrganizationalPostalAddress;
  url?: string[];
  contact?: OrganizationalContact[];
  createdAt?: string;
  updatedAt?: string;
  annotation?: SupplierAnnotation;
};

type SupplierAnnotation = {
  id?: SupplierId;
  displayName?: string;
  url?: string;
  contact?: OrganizationalContact;
  address?: OrganizationalPostalAddress;
  lei?: string;
  vat?: string;
  eori?: string;
  euid?: string;
  brn?: string;
  internalId?: string;
  cpeVendor?: string;
  duns?: string;
  uei?: string;
  cage?: string;
  gln?: string;
  iso6523?: string;
  notes: string;
  properties?: Record<string, string>;
  tags?: string[];
  createdAt?: string;
  updatedAt?: string;
};

type OrganizationalContact = {
  name?: string;
  email?: string;
  phone?: string;
};

type OrganizationalPostalAddress = {
  country?: string;
  region?: string;
  locality?: string;
  postOfficeBoxNumber?: string;
  postalCode?: string;
  streetAddress?: string;
};

type ExternalReference = {
  type: ExternalReferenceType;
  url?: string;
  hashes?: Record<string, string>;
};

type License = {
  id?: string;
  name?: string;
  url?: string;
};

type LicenseChoice = {
  license?: License;
  expression?: string;
};

type DistributionConstraints = {
  tlp?: TLPClassification;
};

type TLPClassification =
  | "CLEAR"
  | "GREEN"
  | "AMBER"
  | "AMBER_AND_STRICT"
  | "RED";

type ComponentRef = string;
type ComponentType = string;
type ExternalReferenceType = string;
type OrganizationId = string;
type SupplierId = string;