ak.schema.sdk_conformance_claim.v1
ak.schema.sdk_conformance_claim.v1 · file: schemas/sdk-conformance-claim.schema.json Signed, artifact-bound SDK release claim. The proof covers RFC 8785 JCS bytes of the object with proof omitted, prefixed by the UTF-8 domain separator arkret-sdk-conformance-claim-v1 followed by LF.
* $ · object
Signed, artifact-bound SDK release claim. The proof covers RFC 8785 JCS bytes of the object with proof omitted, prefixed by the UTF-8 domain separator arkret-sdk-conformance-claim-v1 followed by LF.
* sdk_name ·
string* sdk_version ·
string* sdk_artifact · object · $ref #/$defs/artifact_subject
* uri ·
stringpattern:
^(https|oci|git|urn):.+$* digest · allOf[2] · $ref #/$defs/nonzero_digest
allOf · allOf[0] ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$allOf · allOf[1] ·
?* spec_revision ·
stringpattern:
^[0-9a-f]{40}$* contract_digest · allOf[2] · $ref #/$defs/nonzero_digest
allOf · allOf[0] ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$allOf · allOf[1] ·
?* issued_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer · object · $ref #/$defs/issuer
* id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verification_method ·
stringpattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* clause_claims · array<$ref #/$defs/clause_claim>
items · object · $ref #/$defs/clause_claim
allOf · allOf[0] ·
?* clause_id ·
stringpattern:
^AK-SDK-[0-9]{3}$* result ·
string (enum)enum:
"pass" "fail" "not_applicable"* evidence · array<$ref #/$defs/evidence>
items · object · $ref #/$defs/evidence
One evidence reference. A vector_result entry MUST name the exact vectors it covers; the other kinds MUST NOT carry covers_vectors.
allOf · allOf[0] ·
?* kind ·
string (enum)enum:
"vector_result" "public_api_inventory" "build_variant_inventory" "code_audit" "config_audit" "data_flow_audit"* evidence_ref ·
string* digest · allOf[2] · $ref #/$defs/nonzero_digest
allOf · allOf[0] ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$allOf · allOf[1] ·
?covers_vectors · array<string>
Exact conformance vector ids this run produced results for. REQUIRED when kind is vector_result; the verifier checks the union against the clause's expanded vector_evidence.vectors and its decision_points.
items ·
stringpattern:
^ak\.vector\.[a-z0-9_]+(\.[a-z0-9_]+)+\.v[0-9]+$rationale ·
stringbuild_variants · array<$ref #/$defs/build_variant>
Optional per-build profile inventory for source or multi-variant SDK distributions. Each complete features/configuration inventory is covered by the claim proof and the existing AK-SDK-015 build_variant_inventory digest. Variant IDs MUST be unique; no separate per-feature digest is carried.
items · object · $ref #/$defs/build_variant
* variant_id ·
stringpattern:
^[a-z0-9][a-z0-9._-]{0,127}$* features · array<string>
Complete enabled feature names, sorted in strictly increasing ASCII order. An empty array explicitly represents no enabled optional features.
items ·
stringpattern:
^[A-Za-z0-9][A-Za-z0-9._+:/-]{0,127}$* configuration ·
objectComplete non-secret behavior-affecting build configuration, including target, compiler/toolchain, profile, default-feature policy and relevant flags. Keys are tool-qualified stable names, values are exact canonical build inputs. Defaults MUST be expanded. Secrets MUST NOT be included. The publisher MUST fail closed if the inventory cannot reproduce the claimed configuration.
* claimed_profiles · array<string>
items ·
stringpattern:
^ak\.profile\.[a-z0-9_.-]+\.v1$* proof · object · $ref #/$defs/proof
* kid ·
stringpattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature_algorithm ·
string (enum)enum:
"Ed25519"* signature ·
stringpattern:
^[A-Za-z0-9_-]+$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/sdk-conformance-claim.schema.json