{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://openai.com/codex-security/schemas/scan-manifest.schema.json",
  "title": "Codex Security sealed scan manifest",
  "type": "object",
  "required": ["documentType", "schemaVersion", "scan"],
  "properties": {
    "documentType": {
      "const": "codex-security.scan-manifest"
    },
    "schemaVersion": {
      "const": "1.0"
    },
    "scan": {
      "type": "object",
      "required": [
        "id",
        "producer",
        "status",
        "startedAt",
        "completedAt",
        "sealedAt",
        "target",
        "scope",
        "coverageRef",
        "findingsRef",
        "artifacts"
      ],
      "properties": {
        "id": {
          "type": "string",
          "minLength": 1
        },
        "producer": {
          "type": "object",
          "required": ["name", "version"],
          "properties": {
            "name": {
              "type": "string",
              "minLength": 1
            },
            "version": {
              "type": "string",
              "minLength": 1
            }
          }
        },
        "status": {
          "enum": ["completed", "failed", "canceled", "interrupted"]
        },
        "startedAt": {
          "type": "string",
          "format": "date-time"
        },
        "completedAt": {
          "type": "string",
          "format": "date-time"
        },
        "sealedAt": {
          "type": "string",
          "format": "date-time"
        },
        "target": {
          "type": "object",
          "required": ["kind", "targetId", "displayName"],
          "properties": {
            "kind": {
              "enum": [
                "git_revision",
                "git_worktree",
                "git_diff",
                "directory_snapshot"
              ]
            },
            "targetId": {
              "type": "string",
              "minLength": 1
            },
            "displayName": {
              "type": "string",
              "minLength": 1
            },
            "remote": {
              "type": "string",
              "pattern": "^(?![^:/?#]+://[^/?#]*@)[^?#]+$"
            },
            "revision": {
              "type": "string"
            },
            "baseRevision": {
              "type": "string"
            },
            "headRevision": {
              "type": "string"
            },
            "snapshotDigest": {
              "type": "string",
              "pattern": "^codex-security-snapshot/v1:sha256:[a-f0-9]{64}$"
            }
          },
          "allOf": [
            {
              "if": {
                "properties": {
                  "kind": {
                    "const": "git_revision"
                  }
                }
              },
              "then": {
                "required": ["revision"]
              }
            },
            {
              "if": {
                "properties": {
                  "kind": {
                    "enum": ["git_worktree", "git_diff", "directory_snapshot"]
                  }
                }
              },
              "then": {
                "required": ["snapshotDigest"]
              }
            }
          ]
        },
        "scope": {
          "type": "object",
          "required": ["includePaths", "excludePaths"],
          "properties": {
            "includePaths": {
              "type": "array",
              "items": {
                "type": "string"
              }
            },
            "excludePaths": {
              "type": "array",
              "items": {
                "type": "string"
              }
            },
            "summary": {
              "type": "string",
              "minLength": 1
            },
            "artifactsReviewed": {
              "type": "array",
              "items": {
                "type": "string",
                "minLength": 1
              }
            },
            "runtimeStatus": {
              "type": "string",
              "minLength": 1
            },
            "validationMode": {
              "type": "string",
              "minLength": 1
            },
            "context": {
              "type": "string",
              "minLength": 1
            },
            "limitations": {
              "type": "array",
              "items": {
                "type": "string",
                "minLength": 1
              }
            }
          }
        },
        "threatModel": {
          "description": "Retained threat-model content. Existing structured models remain supported; Markdown documents preserve their complete original body.",
          "anyOf": [
            {
              "type": "object",
              "required": ["summary"],
              "properties": {
                "summary": {
                  "type": "string",
                  "minLength": 1
                },
                "assets": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "minLength": 1
                  }
                },
                "trustBoundaries": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "minLength": 1
                  }
                },
                "attackerCapabilities": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "minLength": 1
                  }
                },
                "securityObjectives": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "minLength": 1
                  }
                },
                "assumptions": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "minLength": 1
                  }
                }
              }
            },
            {
              "type": "object",
              "properties": {
                "format": {
                  "const": "markdown"
                },
                "content": {
                  "type": "string",
                  "minLength": 1,
                  "pattern": "^[\\s\\S]*\\S[\\s\\S]*$"
                },
                "scope": {
                  "type": "object",
                  "description": "The modeled source scope, which may differ from the scan scope. Omit when unknown.",
                  "properties": {
                    "includePaths": {
                      "type": "array",
                      "items": {
                        "type": "string",
                        "minLength": 1
                      }
                    },
                    "excludePaths": {
                      "type": "array",
                      "items": {
                        "type": "string",
                        "minLength": 1
                      }
                    },
                    "summary": {
                      "type": "string",
                      "minLength": 1
                    }
                  },
                  "required": ["includePaths"],
                  "additionalProperties": true
                },
                "origin": {
                  "enum": ["generated", "provided", "reconciled", "recovered"]
                }
              },
              "required": ["format", "content"],
              "additionalProperties": true
            }
          ]
        },
        "hardening": {
          "type": "object",
          "required": ["portfolioPath"],
          "properties": {
            "portfolioPath": {
              "const": "hardening/hardening.md"
            }
          }
        },
        "coverageRef": {
          "const": "coverage.json"
        },
        "findingsRef": {
          "const": "findings.json"
        },
        "artifacts": {
          "type": "array",
          "minItems": 1,
          "items": {
            "type": "object",
            "required": ["path", "sha256", "mediaType"],
            "properties": {
              "path": {
                "type": "string",
                "minLength": 1,
                "pattern": "^(?!/)(?!.*(?:^|/)\\.\\.(?:/|$))(?!.*\\\\).+$"
              },
              "sha256": {
                "type": "string",
                "pattern": "^[a-f0-9]{64}$"
              },
              "mediaType": {
                "type": "string",
                "minLength": 1
              }
            }
          }
        }
      },
      "allOf": [
        {
          "properties": {
            "artifacts": {
              "contains": {
                "type": "object",
                "required": ["path"],
                "properties": {
                  "path": {
                    "const": "findings.json"
                  }
                }
              },
              "minContains": 1,
              "maxContains": 1
            }
          }
        },
        {
          "properties": {
            "artifacts": {
              "contains": {
                "type": "object",
                "required": ["path"],
                "properties": {
                  "path": {
                    "const": "coverage.json"
                  }
                }
              },
              "minContains": 1,
              "maxContains": 1
            }
          }
        }
      ]
    }
  }
}
