6: Evidence data model¶
erDiagram
TARGET_BUILD ||--o{ EXECUTION : runs
INPUT ||--o{ EXECUTION : supplied_to
EXECUTION ||--|| OBSERVATION : produces
OBSERVATION ||--o| CRASH_IDENTITY : identifies
FINDING ||--|{ WITNESS : supported_by
WITNESS }o--|| EXECUTION : cites
FINDING ||--o| REMEDY : may_have
FINDING ||--o{ DISCLOSURE_ARTIFACT : routes_through
TARGET_BUILD {
string commit
boolean dirty
string binary_sha256
string env_digest
string harness_manifest_sha256
}
INPUT {
string path
string sha256
string role "control|crafted|candidate"
}
EXECUTION {
boolean command_started
boolean target_ran
int exit_code
int signal
boolean timeout
string raw_output_sha256
}
OBSERVATION {
string admission
string evidence_class
string kind
boolean needs_human_triage
string target_attribution
}
CRASH_IDENTITY {
string exact_id "build-local dedup"
string stable_id "cross-build tracking"
string legacy_hash "oracle compatibility"
}
FINDING {
string id
string primitive
string evidence_tier
string state
string severity "operator-ratified or UNRATED"
}
WITNESS {
string control_sha256
string crafted_sha256
string source_site
string tested_commit
}
REMEDY {
string patch_ref
boolean closes_poc
boolean accepts_genuine
boolean patched_lines_executed
}
DISCLOSURE_ARTIFACT {
string channel
string role
string content_sha256
string submitted_cwe
string assigner_cwe
string proposed_cvss
string assigner_cvss
} reports/findings.yaml is the structured finding store and is parse-gated for duplicate keys. Generated counts and public CVE tables come from their structured ledgers. Disclosure text remains a separate artifact because what was sent, what an assigner concluded, and what the current record says are different provenance sources.
Reviewed: 2026-08-20.