Files
promptfoo--promptfoo/site/static/schemas/modelaudit/modelaudit-scan-result.schema.json
T
wehub-resource-sync 0d3cb498a3
CI / Shell Format Check (push) Has been cancelled
CI / Check Ruby (3.4) (push) Has been cancelled
CI / CI Config (push) Has been cancelled
CI / Test on Node ${{ matrix.node }} and ${{ matrix.os }}${{ matrix.shard && format(' (shard {0}/3)', matrix.shard) || '' }} (push) Has been cancelled
CI / Build on Node ${{ matrix.node }} (push) Has been cancelled
CI / Style Check (push) Has been cancelled
CI / Generate Assets (push) Has been cancelled
CI / Check Python (3.14) (push) Has been cancelled
CI / Check Python (3.9) (push) Has been cancelled
CI / Build Docs (push) Has been cancelled
CI / Code Scan Action (push) Has been cancelled
CI / Site tests (push) Has been cancelled
CI / webui tests (push) Has been cancelled
CI / Run Integration Tests (push) Has been cancelled
CI / Run Smoke Tests (push) Has been cancelled
CI / Go Tests (push) Has been cancelled
CI / Share Test (push) Has been cancelled
CI / Redteam (Production API) (push) Has been cancelled
CI / Redteam (Staging API) (push) Has been cancelled
CI / GitHub Actions Lint (push) Has been cancelled
CI / Check Ruby (3.0) (push) Has been cancelled
release-please / release-please (push) Has been cancelled
release-please / build (push) Has been cancelled
release-please / publish-npm (push) Has been cancelled
release-please / publish-npm-backfill (push) Has been cancelled
release-please / docker (push) Has been cancelled
release-please / publish-code-scan-action (push) Has been cancelled
release-please / attest-code-scan-action (push) Has been cancelled
Deploy local.promptfoo.app / Deploy to Cloudflare Pages (push) Has been cancelled
Test and Publish Multi-arch Docker Image / test (push) Has been cancelled
Test and Publish Multi-arch Docker Image / build-docker-and-push-digests (map[digest-suffix:linux-amd64 platform:linux/amd64 runner:ubuntu-latest]) (push) Has been cancelled
Test and Publish Multi-arch Docker Image / build-docker-and-push-digests (map[digest-suffix:linux-arm64 platform:linux/arm64 runner:ubuntu-24.04-arm]) (push) Has been cancelled
Test and Publish Multi-arch Docker Image / merge-docker-digests (push) Has been cancelled
Test and Publish Multi-arch Docker Image / Attest Multi-arch Image (push) Has been cancelled
Validate Renovate Config / Validate Renovate Configuration (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 13:24:08 +08:00

1226 lines
31 KiB
JSON

{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://www.promptfoo.dev/schemas/modelaudit/modelaudit-scan-result.schema.json",
"$defs": {
"AssetModel": {
"description": "Model for scanned assets",
"properties": {
"path": {
"description": "Path to the asset",
"title": "Path",
"type": "string"
},
"type": {
"description": "Type of asset (e.g., 'pickle')",
"title": "Type",
"type": "string"
},
"size": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Size of the asset in bytes",
"title": "Size"
},
"is_streamed": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
],
"default": null,
"description": "Whether the asset came from an ephemeral streaming scan",
"title": "Is Streamed"
},
"tensors": {
"anyOf": [
{
"items": {
"type": "string"
},
"type": "array"
},
{
"type": "null"
}
],
"default": null,
"description": "List of tensor names (for safetensors)",
"title": "Tensors"
},
"keys": {
"anyOf": [
{
"items": {
"type": "string"
},
"type": "array"
},
{
"type": "null"
}
],
"default": null,
"description": "List of keys (for JSON manifests)",
"title": "Keys"
},
"contents": {
"anyOf": [
{
"items": {
"additionalProperties": true,
"type": "object"
},
"type": "array"
},
{
"type": "null"
}
],
"default": null,
"description": "Contents list (for ZIP files)",
"title": "Contents"
}
},
"required": ["path", "type"],
"title": "AssetModel",
"type": "object"
},
"Check": {
"additionalProperties": true,
"description": "Pydantic model representing a single security check performed during scanning",
"properties": {
"name": {
"description": "Name of the check performed",
"title": "Name",
"type": "string"
},
"status": {
"$ref": "#/$defs/CheckStatus",
"description": "Whether the check passed or failed"
},
"message": {
"description": "Description of what was checked",
"title": "Message",
"type": "string"
},
"severity": {
"anyOf": [
{
"$ref": "#/$defs/IssueSeverity"
},
{
"type": "null"
}
],
"default": null,
"description": "Severity (only for failed checks)"
},
"location": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "File position, line number, etc.",
"title": "Location"
},
"details": {
"additionalProperties": true,
"description": "Additional check details",
"title": "Details",
"type": "object"
},
"why": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Explanation (mainly for failed checks)",
"title": "Why"
},
"rule_code": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Rule code associated with this check",
"title": "Rule Code"
},
"timestamp": {
"description": "Timestamp when check was performed",
"title": "Timestamp",
"type": "number"
}
},
"required": ["name", "status", "message"],
"title": "Check",
"type": "object"
},
"CheckStatus": {
"description": "Enum for check status",
"enum": ["passed", "failed", "skipped"],
"title": "CheckStatus",
"type": "string"
},
"CopyrightNoticeModel": {
"description": "Model for copyright notice information",
"properties": {
"holder": {
"description": "Copyright holder name",
"title": "Holder",
"type": "string"
},
"year": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Copyright year(s)",
"title": "Year"
},
"text": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Full copyright notice text",
"title": "Text"
},
"confidence": {
"default": 0.0,
"description": "Confidence in copyright detection",
"maximum": 1.0,
"minimum": 0.0,
"title": "Confidence",
"type": "number"
}
},
"required": ["holder"],
"title": "CopyrightNoticeModel",
"type": "object"
},
"FileHashesModel": {
"description": "Model for file hash information with validation",
"properties": {
"md5": {
"anyOf": [
{
"pattern": "^[a-fA-F0-9]{32}$",
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "MD5 hash",
"title": "Md5"
},
"sha1": {
"anyOf": [
{
"pattern": "^[a-fA-F0-9]{40}$",
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "SHA1 hash",
"title": "Sha1"
},
"sha256": {
"anyOf": [
{
"pattern": "^[a-fA-F0-9]{64}$",
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "SHA256 hash",
"title": "Sha256"
},
"sha256_prefix": {
"anyOf": [
{
"pattern": "^[a-fA-F0-9]{64}$",
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "SHA256 hash for a bounded prefix only; not a complete file hash",
"title": "Sha256 Prefix"
},
"sha512": {
"anyOf": [
{
"pattern": "^[a-fA-F0-9]{128}$",
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "SHA512 hash",
"title": "Sha512"
}
},
"title": "FileHashesModel",
"type": "object"
},
"FileMetadataModel": {
"additionalProperties": true,
"description": "Enhanced model for individual file metadata with structured validation",
"properties": {
"file_size": {
"anyOf": [
{
"minimum": 0,
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "File size in bytes",
"title": "File Size"
},
"file_hashes": {
"anyOf": [
{
"$ref": "#/$defs/FileHashesModel"
},
{
"type": "null"
}
],
"default": null,
"description": "File hashes with validation"
},
"member_file_hashes": {
"additionalProperties": {
"$ref": "#/$defs/MemberFileIntegrityModel"
},
"description": "Nested member integrity metadata keyed by a collision-free structured member identity",
"title": "Member File Hashes",
"type": "object"
},
"member_file_hashes_total": {
"anyOf": [
{
"minimum": 0,
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Total nested member hash records observed",
"title": "Member File Hashes Total"
},
"member_file_hashes_truncated": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
],
"default": null,
"description": "Whether nested member hash records were omitted after the retention bound",
"title": "Member File Hashes Truncated"
},
"member_file_hashes_omitted": {
"anyOf": [
{
"minimum": 0,
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Number of nested member hash records omitted after the retention bound",
"title": "Member File Hashes Omitted"
},
"max_stack_depth": {
"anyOf": [
{
"minimum": 0,
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Maximum stack depth for pickle files",
"title": "Max Stack Depth"
},
"opcode_count": {
"anyOf": [
{
"minimum": 0,
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Number of opcodes for pickle files",
"title": "Opcode Count"
},
"suspicious_count": {
"anyOf": [
{
"minimum": 0,
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Count of suspicious patterns",
"title": "Suspicious Count"
},
"ml_context": {
"anyOf": [
{
"$ref": "#/$defs/MLContextModel"
},
{
"type": "null"
}
],
"default": null,
"description": "ML context information"
},
"license": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Legacy license field for backward compatibility",
"title": "License"
},
"license_info": {
"description": "Structured license information",
"items": {
"$ref": "#/$defs/LicenseInfoModel"
},
"title": "License Info",
"type": "array"
},
"copyright_notices": {
"description": "Structured copyright notices",
"items": {
"$ref": "#/$defs/CopyrightNoticeModel"
},
"title": "Copyright Notices",
"type": "array"
},
"license_files_nearby": {
"description": "License files found nearby",
"items": {
"type": "string"
},
"title": "License Files Nearby",
"type": "array"
},
"is_dataset": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
],
"default": null,
"description": "Whether file appears to be a dataset",
"title": "Is Dataset"
},
"is_model": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
],
"default": null,
"description": "Whether file appears to be a model",
"title": "Is Model"
},
"risk_score": {
"default": 0.0,
"description": "Calculated risk score (0.0 to 1.0)",
"maximum": 1.0,
"minimum": 0.0,
"title": "Risk Score",
"type": "number"
},
"scan_timestamp": {
"description": "When this metadata was collected",
"title": "Scan Timestamp",
"type": "number"
}
},
"title": "FileMetadataModel",
"type": "object"
},
"Issue": {
"additionalProperties": true,
"description": "Pydantic model representing a single issue found during scanning",
"properties": {
"message": {
"description": "Description of the issue",
"title": "Message",
"type": "string"
},
"severity": {
"$ref": "#/$defs/IssueSeverity",
"default": "warning",
"description": "Issue severity level"
},
"location": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "File position, line number, etc.",
"title": "Location"
},
"details": {
"additionalProperties": true,
"description": "Additional details about the issue",
"title": "Details",
"type": "object"
},
"why": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Explanation of why this is a security concern",
"title": "Why"
},
"timestamp": {
"description": "Timestamp when issue was detected",
"title": "Timestamp",
"type": "number"
},
"type": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Type of issue for categorization",
"title": "Type"
},
"rule_code": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Rule code associated with this issue",
"title": "Rule Code"
}
},
"required": ["message"],
"title": "Issue",
"type": "object"
},
"IssueSeverity": {
"description": "Enum for issue severity levels",
"enum": ["debug", "info", "warning", "critical"],
"title": "IssueSeverity",
"type": "string"
},
"LicenseInfoModel": {
"description": "Model for structured license information",
"properties": {
"spdx_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "SPDX license identifier",
"title": "Spdx Id"
},
"name": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "License name",
"title": "Name"
},
"url": {
"anyOf": [
{
"format": "uri",
"maxLength": 2083,
"minLength": 1,
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "License URL",
"title": "Url"
},
"text": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "License text content",
"title": "Text"
},
"confidence": {
"default": 0.0,
"description": "Confidence in license detection",
"maximum": 1.0,
"minimum": 0.0,
"title": "Confidence",
"type": "number"
},
"source": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Source of license detection (file, header, etc.)",
"title": "Source"
},
"commercial_allowed": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
],
"default": null,
"description": "Whether commercial use is allowed",
"title": "Commercial Allowed"
}
},
"title": "LicenseInfoModel",
"type": "object"
},
"MLContextModel": {
"additionalProperties": true,
"description": "Enhanced model for ML context metadata with comprehensive validation",
"properties": {
"frameworks": {
"additionalProperties": {
"$ref": "#/$defs/MLFrameworkInfo"
},
"description": "Detected ML frameworks with details",
"title": "Frameworks",
"type": "object"
},
"overall_confidence": {
"default": 0.0,
"description": "Overall ML content confidence score",
"maximum": 1.0,
"minimum": 0.0,
"title": "Overall Confidence",
"type": "number"
},
"is_ml_content": {
"default": false,
"description": "Whether content is ML-related",
"title": "Is Ml Content",
"type": "boolean"
},
"detected_patterns": {
"description": "Detected ML patterns",
"items": {
"type": "string"
},
"title": "Detected Patterns",
"type": "array"
},
"weight_analysis": {
"anyOf": [
{
"$ref": "#/$defs/WeightAnalysisModel"
},
{
"type": "null"
}
],
"default": null,
"description": "Analysis of potential weight data"
},
"model_type": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Detected model type (e.g., 'transformer', 'cnn', 'rnn')",
"title": "Model Type"
},
"layer_count_estimate": {
"anyOf": [
{
"minimum": 0,
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Estimated number of layers",
"title": "Layer Count Estimate"
},
"parameter_count_estimate": {
"anyOf": [
{
"minimum": 0,
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Estimated parameter count",
"title": "Parameter Count Estimate"
},
"training_framework": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Framework likely used for training",
"title": "Training Framework"
},
"precision_type": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Detected precision (fp32, fp16, int8, etc.)",
"title": "Precision Type"
},
"optimization_hints": {
"description": "Detected optimization techniques",
"items": {
"type": "string"
},
"title": "Optimization Hints",
"type": "array"
}
},
"title": "MLContextModel",
"type": "object"
},
"MLFrameworkInfo": {
"description": "Model for individual ML framework detection info",
"properties": {
"name": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Framework name (e.g., 'pytorch', 'tensorflow')",
"title": "Name"
},
"version": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Detected version if available",
"title": "Version"
},
"confidence": {
"default": 0.0,
"description": "Confidence in detection (0.0 to 1.0)",
"maximum": 1.0,
"minimum": 0.0,
"title": "Confidence",
"type": "number"
},
"indicators": {
"anyOf": [
{
"items": {
"type": "string"
},
"type": "array"
},
{
"type": "null"
}
],
"description": "Patterns that indicated this framework",
"title": "Indicators"
},
"file_patterns": {
"anyOf": [
{
"items": {
"type": "string"
},
"type": "array"
},
{
"type": "null"
}
],
"description": "File patterns that matched",
"title": "File Patterns"
}
},
"title": "MLFrameworkInfo",
"type": "object"
},
"MemberFileIntegrityModel": {
"additionalProperties": true,
"description": "Integrity metadata for a nested archive/member payload.",
"properties": {
"file_hashes": {
"anyOf": [
{
"$ref": "#/$defs/FileHashesModel"
},
{
"type": "null"
}
],
"default": null,
"description": "Complete member hashes"
},
"file_size": {
"anyOf": [
{
"minimum": 0,
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Member size in bytes",
"title": "File Size"
},
"bytes_hashed": {
"anyOf": [
{
"minimum": 0,
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Bytes covered by the member hash",
"title": "Bytes Hashed"
},
"hash_complete": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
],
"default": null,
"description": "Whether the member hash covered the full payload",
"title": "Hash Complete"
},
"hash_status": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Hash coverage status",
"title": "Hash Status"
},
"sha256_prefix": {
"anyOf": [
{
"pattern": "^[a-fA-F0-9]{64}$",
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "SHA256 hash for a bounded member prefix only",
"title": "Sha256 Prefix"
},
"scanner_name": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Scanner that produced the member hash",
"title": "Scanner Name"
},
"logical_path": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Original logical path when duplicate keys are disambiguated",
"title": "Logical Path"
},
"path_segments": {
"description": "Raw nested archive path segments",
"items": {
"type": "string"
},
"title": "Path Segments",
"type": "array"
},
"occurrence": {
"anyOf": [
{
"minimum": 1,
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Occurrence number for duplicate logical member paths",
"title": "Occurrence"
}
},
"title": "MemberFileIntegrityModel",
"type": "object"
},
"WeightAnalysisModel": {
"description": "Model for weight pattern analysis results",
"properties": {
"appears_to_be_weights": {
"default": false,
"description": "Whether data appears to be ML weights",
"title": "Appears To Be Weights",
"type": "boolean"
},
"weight_confidence": {
"default": 0.0,
"description": "Confidence in weight detection",
"maximum": 1.0,
"minimum": 0.0,
"title": "Weight Confidence",
"type": "number"
},
"pattern_density": {
"default": 0.0,
"description": "Density of detected patterns",
"maximum": 1.0,
"minimum": 0.0,
"title": "Pattern Density",
"type": "number"
},
"float_ratio": {
"default": 0.0,
"description": "Ratio of floating-point data",
"maximum": 1.0,
"minimum": 0.0,
"title": "Float Ratio",
"type": "number"
},
"statistical_expectation": {
"default": 0.0,
"description": "Statistical expectation for patterns",
"maximum": 1.0,
"minimum": 0.0,
"title": "Statistical Expectation",
"type": "number"
},
"file_size_factor": {
"default": 0.0,
"description": "File size influence factor",
"maximum": 1.0,
"minimum": 0.0,
"title": "File Size Factor",
"type": "number"
}
},
"title": "WeightAnalysisModel",
"type": "object"
}
},
"additionalProperties": true,
"description": "Pydantic model matching the exact current ModelAudit JSON output format",
"properties": {
"bytes_scanned": {
"description": "Total bytes scanned",
"title": "Bytes Scanned",
"type": "integer"
},
"issues": {
"description": "List of security issues found",
"items": {
"$ref": "#/$defs/Issue"
},
"title": "Issues",
"type": "array"
},
"checks": {
"description": "List of all checks performed",
"items": {
"$ref": "#/$defs/Check"
},
"title": "Checks",
"type": "array"
},
"files_scanned": {
"description": "Number of files scanned",
"title": "Files Scanned",
"type": "integer"
},
"assets": {
"description": "List of scanned assets",
"items": {
"$ref": "#/$defs/AssetModel"
},
"title": "Assets",
"type": "array"
},
"has_errors": {
"description": "Whether operational errors occurred during scanning",
"title": "Has Errors",
"type": "boolean"
},
"scanner_names": {
"description": "Names of scanners used",
"items": {
"type": "string"
},
"title": "Scanner Names",
"type": "array"
},
"scanner_selection": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "Effective scanner selection policy",
"title": "Scanner Selection"
},
"file_metadata": {
"additionalProperties": {
"$ref": "#/$defs/FileMetadataModel"
},
"description": "Metadata for each file",
"title": "File Metadata",
"type": "object"
},
"content_hash": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Aggregate SHA-256 hash of all scanned files (for deduplication)",
"title": "Content Hash"
},
"start_time": {
"description": "Scan start timestamp",
"title": "Start Time",
"type": "number"
},
"duration": {
"description": "Scan duration in seconds",
"title": "Duration",
"type": "number"
},
"total_checks": {
"description": "Total number of checks performed",
"title": "Total Checks",
"type": "integer"
},
"passed_checks": {
"description": "Number of checks that passed",
"title": "Passed Checks",
"type": "integer"
},
"failed_checks": {
"description": "Number of checks that failed",
"title": "Failed Checks",
"type": "integer"
},
"success": {
"default": true,
"description": "Whether the scan completed successfully",
"title": "Success",
"type": "boolean"
}
},
"required": [
"bytes_scanned",
"files_scanned",
"has_errors",
"start_time",
"duration",
"total_checks",
"passed_checks",
"failed_checks"
],
"title": "ModelAuditResultModel",
"type": "object"
}