Skip to content

6: Evidence data model

erDiagram
    TARGET_BUILD ||--o{ EXECUTION : runs
    INPUT ||--o{ EXECUTION : supplied_to
    EXECUTION ||--|| OBSERVATION : produces
    OBSERVATION ||--o| CRASH_IDENTITY : identifies
    FINDING ||--|{ WITNESS : supported_by
    WITNESS }o--|| EXECUTION : cites
    FINDING ||--o| REMEDY : may_have
    FINDING ||--o{ DISCLOSURE_ARTIFACT : routes_through

    TARGET_BUILD {
        string commit
        boolean dirty
        string binary_sha256
        string env_digest
        string harness_manifest_sha256
    }
    INPUT {
        string path
        string sha256
        string role "control|crafted|candidate"
    }
    EXECUTION {
        boolean command_started
        boolean target_ran
        int exit_code
        int signal
        boolean timeout
        string raw_output_sha256
    }
    OBSERVATION {
        string admission
        string evidence_class
        string kind
        boolean needs_human_triage
        string target_attribution
    }
    CRASH_IDENTITY {
        string exact_id "build-local dedup"
        string stable_id "cross-build tracking"
        string legacy_hash "oracle compatibility"
    }
    FINDING {
        string id
        string primitive
        string evidence_tier
        string state
        string severity "operator-ratified or UNRATED"
    }
    WITNESS {
        string control_sha256
        string crafted_sha256
        string source_site
        string tested_commit
    }
    REMEDY {
        string patch_ref
        boolean closes_poc
        boolean accepts_genuine
        boolean patched_lines_executed
    }
    DISCLOSURE_ARTIFACT {
        string channel
        string role
        string content_sha256
        string submitted_cwe
        string assigner_cwe
        string proposed_cvss
        string assigner_cvss
    }

reports/findings.yaml is the structured finding store and is parse-gated for duplicate keys. Generated counts and public CVE tables come from their structured ledgers. Disclosure text remains a separate artifact because what was sent, what an assigner concluded, and what the current record says are different provenance sources.

Reviewed: 2026-08-20.