Skip to main content

Decision predicate

The predicate type is one frozen URI: https://coderifts.com/attestations/decision/v1.

What it copies

The four fields are copied off a receipt the gate already verified: execution_action, operation, target_id, and expires_at.

The predicate copies four fields and invents none.

Each field is the copied value or null. target_id is the envelope target_id, or artifact_digest when that is absent. expires_at is the payload expires_at, or the envelope expires_at, or null.

The predicate file does not sign anything and does not add a field to the receipt.

Field list

No JSON Schema file for this predicate is in coderifts/contract-gate. The field list is those four keys.

execution_action
operation
target_id
expires_at

Who writes it

The Action input predicate-path names the workspace file. The default is decision-predicate.json. An empty string writes nothing.

The file is not signed and it is not committed.

the predicate file is written only for a verified receipt and only when a path is given

The Action writes that file on the enforcing profile after a carried receipt verifies, and after an issued receipt verifies. A receipt that does not verify writes nothing.

examples/attest-decision.yml names this predicate type. The gate step omits predicate-path. actions/attest@v4 reads decision-predicate.json. The workflow does not sign the receipt and does not add a field to it.

examples/kyverno-decision.yaml names the same predicate type.

src/decision-predicate.js

action.yml

examples/attest-decision.yml

examples/kyverno-decision.yaml

test/decision-predicate.test.js

Boundary

no published artifact emits a DSSE or in-toto envelope today; the predicate is written only for a verified receipt and only when a path is given

src/from-dsse.js unpacks an envelope whose predicate type is https://coderifts.com/attestations/agent-action-authorization/v1. It does not write this predicate.

src/from-dsse.js

src/index.js