Skip to content

Commit 7dd911f

Browse files
committed
update records latest manifest
2 parents 75de001 + 0f77c44 commit 7dd911f

14 files changed

Lines changed: 236 additions & 4 deletions

‎.github/workflows/codeql.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -30,11 +30,11 @@ jobs:
3030
uses: actions/checkout@v4
3131

3232
- name: Initialize CodeQL
33-
uses: github/codeql-action/init@v4.38.0
33+
uses: github/codeql-action/init@v4.38.1
3434
with:
3535
languages: ${{ matrix.language }}
3636

3737
- name: Perform CodeQL analysis
38-
uses: github/codeql-action/analyze@v4.38.0
38+
uses: github/codeql-action/analyze@v4.38.1
3939
with:
4040
category: "/language:${{ matrix.language }}"

‎.github/workflows/scorecard.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,6 @@ jobs:
4040
retention-days: 5
4141

4242
- name: Upload to code-scanning
43-
uses: github/codeql-action/upload-sarif@v4.38.0
43+
uses: github/codeql-action/upload-sarif@v4.38.1
4444
with:
4545
sarif_file: results.sarif
Lines changed: 150 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,150 @@
1+
{
2+
"$schema": "https://aveproject.org/schema/crosswalk-1.0.0.schema.json",
3+
"source": {
4+
"standard": "AVE",
5+
"version": "1.1.0",
6+
"url": "https://aveproject.org",
7+
"record_count": 80,
8+
"commit": "1e29789e4941b6c1c2435508dbf3c245eedc8d04"
9+
},
10+
"target": {
11+
"registry": "agent-evidence-vocabulary",
12+
"version": "0.2.0",
13+
"license": "CC0-1.0",
14+
"url": "https://github.com/probityai/agent-evidence-vocabulary",
15+
"registry_file": "vocabulary.yaml",
16+
"term_count": 8,
17+
"checked_against_live_file": "2026-09-15",
18+
"commit": "66177d65690e9d7eb7e4ff59df8f91792a90735b"
19+
},
20+
"generated": "2026-09-15",
21+
"note": "A field-level crosswalk between AVE's evidence-provenance properties and the agent-evidence-vocabulary registry, which names the axes an execution-evidence claim is read on: who observed the execution, how directly, and what the claim leaves out. The unit is a schema property rather than a category, because the two sides describe different things: AVE enumerates behavioral vulnerability classes and the registry names the provenance axes any claim about an execution carries. They meet at exactly one place, which is how AVE says where its evidence came from. Read coverage before trusting a row: none of the 80 records carries evidence_vantage, evidence_method or verification_basis. All three are optional in schema v1.1.0 and all three read absent on every record at the commit above, verified by fetching each record file rather than by reading the schema. Every mapping below is therefore evidence: inferred, established by comparing two schema definitions, and none is evidence: emitted. A row moves to emitted when a record carries the field and a reviewer can fetch it.",
22+
"mappings": [
23+
{
24+
"ave_field": "evidence_vantage",
25+
"ave_values": [
26+
"substrate",
27+
"artifact"
28+
],
29+
"registry_term": "observation_vantage",
30+
"registry_section": "evidence_dimensions",
31+
"registry_values": [
32+
"substrate",
33+
"artifact"
34+
],
35+
"match_type": "exact",
36+
"evidence": "inferred",
37+
"notes": "Value sets are identical and so is the composition rule: both take the weakest input, so a claim mixing substrate and artifact observations inherits artifact. The two definitions were written independently and reached the same two-value split, which is the case for mapping them exact rather than structural. The registry adds one consumer-side requirement AVE's schema does not state, that a consumer with no policy-pinned substrate root must treat a substrate row as unattested rather than infer the root from the claim."
38+
},
39+
{
40+
"ave_field": "evidence_method",
41+
"ave_values": [
42+
"intercepted",
43+
"reconstructed"
44+
],
45+
"registry_term": "observation_directness",
46+
"registry_section": "evidence_dimensions",
47+
"registry_values": [
48+
"intercepted",
49+
"reconstructed"
50+
],
51+
"match_type": "exact",
52+
"evidence": "inferred",
53+
"notes": "Identical value sets, identical weakest-input composition, and both treat reconstructed as the floor a producer may always truthfully state. AVE's schema says an absent value reads as reconstructed; the registry does not state a default, so a producer emitting both sides should write the value rather than rely on either reading."
54+
},
55+
{
56+
"ave_field": "verification_basis",
57+
"ave_values": [
58+
"substrate_intercepted",
59+
"substrate_reconstructed",
60+
"artifact_intercepted",
61+
"artifact_reconstructed"
62+
],
63+
"registry_term": "observation_vantage + observation_directness",
64+
"registry_section": "evidence_dimensions",
65+
"match_type": "structural",
66+
"evidence": "inferred",
67+
"notes": "The four values are the product of the two axes above, which is what scripts/write_verification_basis.py composes. The registry keeps the axes separate and does not define the composed term, so this is a structural correspondence rather than a term pairing: a consumer holding an AVE verification_basis can split it into the two registry axes without loss, and a consumer holding both registry values can compose the AVE value without loss."
68+
},
69+
{
70+
"ave_field": "evidence_basis_engines",
71+
"ave_values": [
72+
"pattern",
73+
"yara",
74+
"semgrep",
75+
"llm",
76+
"sandbox",
77+
"magika",
78+
"external_authority"
79+
],
80+
"registry_term": "observation_vantage",
81+
"registry_section": "evidence_dimensions",
82+
"match_type": "partial",
83+
"evidence": "inferred",
84+
"notes": "One value carries vantage information and the rest do not. external_authority means a party outside the observed artifact answered, which is the substrate side of the registry's axis; sandbox observes execution and is the other candidate. pattern, yara, semgrep, llm and magika all read the artifact's own bytes, so they sit on the artifact side. AVE's own schema already composes this field into verification_basis by weakest input, so the partial mapping is not a gap in AVE, it is the reason the composed field exists."
85+
}
86+
],
87+
"gaps": [
88+
{
89+
"side": "registry",
90+
"registry_term": "field_evidence_partition",
91+
"reason": "Declares which identity's signature backs which field inside one mixed claim. AVE records a vulnerability class rather than a signed claim, so there is no per-field signer to partition."
92+
},
93+
{
94+
"side": "registry",
95+
"registry_term": "issuance_time_basis",
96+
"reason": "Distinguishes a timestamp anchored to a beacon from one the producer asserts. AVE records carry published and last_updated as editorial dates on the record, not as claims about when an execution was observed."
97+
},
98+
{
99+
"side": "registry",
100+
"registry_term": "containment_posture",
101+
"reason": "Describes the network posture an execution ran under. AVE classifies component behavior independently of any one run's containment."
102+
},
103+
{
104+
"side": "registry",
105+
"registry_term": "coverage_denominator",
106+
"reason": "States the population a claim was measured over. An AVE record is a class definition rather than a measurement, so it has no denominator to declare."
107+
},
108+
{
109+
"side": "registry",
110+
"registry_term": "does_not_assert",
111+
"reason": "Carries, inside the signed bytes, what a claim deliberately leaves out. AVE has no signed-claim envelope for this to sit in; the nearest thing is prose in vulnerability_rationale."
112+
},
113+
{
114+
"side": "registry",
115+
"registry_term": "result",
116+
"reason": "A recomputable outcome lattice over one execution: fail, degraded, pass_indirect, pass. AVE scores a class with AIVSS rather than recording an outcome, and the registry's own out-of-scope block rules out reading its lattice as a threshold anyway."
117+
},
118+
{
119+
"side": "ave",
120+
"ave_field": "confidence_baseline",
121+
"reason": "A scanner's prior on a single-engine match. The registry's out-of-scope block excludes scored assessment, so there is deliberately no term for it and there will not be one."
122+
},
123+
{
124+
"side": "ave",
125+
"ave_field": "detection_stage",
126+
"reason": "Says when in a component's lifecycle a class is detectable. The registry has no lifecycle axis."
127+
},
128+
{
129+
"side": "ave",
130+
"ave_field": "detection_layer",
131+
"reason": "Says which layer of a component a detector reads. The registry's vantage axis is about the relation between observer and observed, not about which layer was read, and the two are orthogonal."
132+
},
133+
{
134+
"side": "ave",
135+
"ave_field": "evidence_kind_default",
136+
"reason": "A scanner hint naming the detection technique. The registry names where a claim came from rather than how it was computed."
137+
}
138+
],
139+
"coverage": {
140+
"registry_terms_total": 8,
141+
"registry_terms_mapped": 2,
142+
"registry_terms_structurally_covered": 1,
143+
"registry_terms_unmapped": 6,
144+
"ave_evidence_fields_total": 7,
145+
"ave_evidence_fields_mapped": 4,
146+
"ave_records_total": 80,
147+
"ave_records_carrying_any_mapped_field": 0,
148+
"what_the_counts_leave_out": "registry_terms_mapped counts observation_vantage and observation_directness. verification_basis covers the same two axes composed, so it is counted once as structural rather than twice, and registry_terms_unmapped plus the two mapped terms is 8. ave_records_carrying_any_mapped_field is 0 because evidence_vantage, evidence_method and verification_basis are absent from all 80 record files at the pinned commit, checked by fetching each file. evidence_basis_engines is present on records and is the partial row, so the zero describes the three composed fields rather than the whole mapping."
149+
}
150+
}
Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
# AVE to agent-evidence-vocabulary
2+
3+
A field-level crosswalk between AVE's evidence-provenance properties and the
4+
agent-evidence-vocabulary registry, which names the axes an execution-evidence
5+
claim is read on: who observed the execution, how directly, and what the claim
6+
leaves out. Machine-readable form in
7+
[`ave-to-agent-evidence-vocabulary.json`](ave-to-agent-evidence-vocabulary.json),
8+
against
9+
[`schema/crosswalk-1.0.0.schema.json`](../schema/crosswalk-1.0.0.schema.json).
10+
11+
| | |
12+
|---|---|
13+
| Source | AVE 1.1.0, 80 records, commit `1e29789e4941b6c1c2435508dbf3c245eedc8d04` |
14+
| Target | [agent-evidence-vocabulary](https://github.com/probityai/agent-evidence-vocabulary) 0.2.0, 8 terms, CC0-1.0, commit `66177d65690e9d7eb7e4ff59df8f91792a90735b` |
15+
| Generated | 2026-09-15 |
16+
| Unit | one schema property, not one category |
17+
18+
## Read this first
19+
20+
None of the 80 records carries `evidence_vantage`, `evidence_method` or
21+
`verification_basis`. All three are optional in schema v1.1.0, and all three
22+
read absent on every record file at the pinned commit. That was checked by
23+
fetching each of the 80 files, not by reading the schema.
24+
25+
So every row below carries an evidence state of inferred, established by
26+
comparing two schema definitions. None carries emitted, and a reviewer should
27+
not read one that way. A row moves to emitted when a record carries the field
28+
and the reviewer can fetch it. The script that writes verification_basis has
29+
nothing to derive over until that happens.
30+
31+
## The mapping
32+
33+
| AVE field | Registry term | Match | Why |
34+
|---|---|---|---|
35+
| `evidence_vantage` | `observation_vantage` | exact | `substrate` and `artifact` on both sides, same two values, same weakest-input composition |
36+
| `evidence_method` | `observation_directness` | exact | `intercepted` and `reconstructed` on both sides, same composition, same floor |
37+
| `verification_basis` | `observation_vantage` + `observation_directness` | structural | AVE's four values are the product of the two registry axes; either side converts without loss |
38+
| `evidence_basis_engines` | `observation_vantage` | partial | `external_authority` and `sandbox` sit on the substrate side; the five artifact-reading engines sit on the other |
39+
40+
The two exact rows are unusual and worth a sentence. The definitions were
41+
written independently, on different sides, and reached the same two-value split
42+
with the same composition rule. That is the case for calling them exact rather
43+
than approximate: there is nothing to reconcile.
44+
45+
## What does not map
46+
47+
Six registry terms have no AVE counterpart, because an AVE record classifies a
48+
component's behavior while the registry describes one observed execution.
49+
50+
| Registry term with no AVE counterpart | AVE field with no registry counterpart |
51+
|---|---|
52+
| `field_evidence_partition` | `confidence_baseline` |
53+
| `issuance_time_basis` | `detection_stage` |
54+
| `containment_posture` | `detection_layer` |
55+
| `coverage_denominator` | `evidence_kind_default` |
56+
| `does_not_assert` | |
57+
| `result` | |
58+
59+
The first field in the right-hand column will never get a counterpart. The
60+
registry's own out-of-scope block excludes scored assessment of an actor, so a
61+
confidence prior sits outside it by design and not by omission.
62+
63+
The per-field reasons are in the gaps array of the JSON.
64+
65+
## Offered as a basis for collaboration
66+
67+
The registry is CC0-1.0 and its eight terms all carry the status proposed and none carries canonical. Its
68+
promotion rule is that a term becomes canonical only when an independently
69+
maintained system emits it in a running artifact and files a crosswalk with a
70+
source path a reviewer can fetch. AVE already declares two of those fields in
71+
its schema. If records start carrying them, the two exact rows above become the
72+
evidence that rule asks for, and the coverage number in the JSON moves without
73+
the mapping changing.

‎dist/ave-records-latest.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11636,4 +11636,4 @@
1163611636
}
1163711637
}
1163811638
}
11639-
]
11639+
]

‎records/AVE-2026-00004.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -121,6 +121,7 @@
121121
"detection_stage": "static_detection",
122122
"detection_layer": "content",
123123
"confidence_baseline": 0.9,
124+
"evidence_vantage": "artifact",
124125
"evidence_basis_engines": [
125126
"pattern",
126127
"semgrep",

‎records/AVE-2026-00005.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -120,6 +120,7 @@
120120
"detection_stage": "static_detection",
121121
"detection_layer": "content",
122122
"confidence_baseline": 0.9,
123+
"evidence_vantage": "artifact",
123124
"evidence_basis_engines": [
124125
"pattern",
125126
"semgrep",

‎records/AVE-2026-00024.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -113,6 +113,7 @@
113113
"detection_stage": "static_detection",
114114
"detection_layer": "content",
115115
"confidence_baseline": 0.9,
116+
"evidence_vantage": "artifact",
116117
"evidence_basis_engines": [
117118
"pattern",
118119
"semgrep",

‎records/AVE-2026-00032.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -115,6 +115,7 @@
115115
"detection_stage": "static_detection",
116116
"detection_layer": "content",
117117
"confidence_baseline": 0.9,
118+
"evidence_vantage": "artifact",
118119
"evidence_basis_engines": [
119120
"pattern",
120121
"semgrep",

‎records/AVE-2026-00033.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -116,6 +116,7 @@
116116
"detection_stage": "static_detection",
117117
"detection_layer": "content",
118118
"confidence_baseline": 0.9,
119+
"evidence_vantage": "artifact",
119120
"evidence_basis_engines": [
120121
"pattern",
121122
"semgrep",

0 commit comments

Comments
 (0)