Decision predicate
The predicate type is one frozen URI: https://coderifts.com/attestations/decision/v1.
What it copies
The four fields are copied off a receipt the gate already verified: execution_action, operation, target_id, and expires_at.
The predicate copies four fields and invents none.
Each field is the copied value or null. target_id is the envelope target_id, or artifact_digest when that is absent. expires_at is the payload expires_at, or the envelope expires_at, or null.
The predicate file does not sign anything and does not add a field to the receipt.
Field list
No JSON Schema file for this predicate is in coderifts/contract-gate. The field list is those four keys.
execution_action operation target_id expires_at
Who writes it
The Action input predicate-path names the workspace file. The default is decision-predicate.json. An empty string writes nothing.
The file is not signed and it is not committed.
the predicate file is written only for a verified receipt and only when a path is given
The Action writes that file on the enforcing profile after a carried receipt verifies, and after an issued receipt verifies. A receipt that does not verify writes nothing.
examples/attest-decision.yml names this predicate type. The gate step omits predicate-path. actions/attest@v4 reads decision-predicate.json. The workflow does not sign the receipt and does not add a field to it.
examples/kyverno-decision.yaml names the same predicate type.
examples/kyverno-decision.yaml
test/decision-predicate.test.js
Boundary
no published artifact emits a DSSE or in-toto envelope today; the predicate is written only for a verified receipt and only when a path is given
src/from-dsse.js unpacks an envelope whose predicate type is https://coderifts.com/attestations/agent-action-authorization/v1. It does not write this predicate.