{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://dotbabel.dev/schemas/dotbabel.quality-result.schema.json",
  "title": "dotbabel quality result envelope",
  "type": "object",
  "additionalProperties": true,
  "required": ["schema_version", "command", "state"],
  "properties": {
    "schema_version": {
      "const": 1
    },
    "command": {
      "enum": ["check", "detect", "explain", "baseline"]
    },
    "state": {
      "enum": ["checked", "configured", "disabled", "candidate", "written", "error"]
    },
    "critical_matches": {
      "type": "array",
      "items": {
        "type": "string",
        "minLength": 1
      },
      "uniqueItems": true
    },
    "components": {
      "type": "array",
      "items": {
        "type": "object",
        "required": ["id"],
        "properties": {
          "id": {
            "type": "string",
            "minLength": 1
          }
        }
      }
    },
    "executions": {
      "type": "array",
      "items": {
        "type": "object",
        "required": ["componentId", "state"],
        "properties": {
          "componentId": {
            "type": "string",
            "minLength": 1
          },
          "state": {
            "enum": [
              "checked",
              "unsupported",
              "not_configured",
              "not_triggered",
              "unavailable",
              "not_applicable",
              "skipped"
            ]
          },
          "reused": {
            "type": "object",
            "description": "Present when this execution's result came from a passed local-attest leg at the same commit rather than from running the tool here.",
            "required": ["leg", "head_sha"],
            "properties": {
              "leg": {
                "type": "string",
                "minLength": 1
              },
              "head_sha": {
                "type": "string",
                "pattern": "^[0-9a-f]{40}$"
              }
            }
          }
        }
      }
    },
    "results": {
      "type": "array",
      "items": {
        "type": "object",
        "required": ["rule", "state", "verdict"],
        "properties": {
          "rule": {
            "type": "string",
            "minLength": 1
          },
          "state": {
            "enum": [
              "checked",
              "unsupported",
              "not_configured",
              "not_triggered",
              "unavailable",
              "not_applicable",
              "skipped"
            ]
          },
          "verdict": {
            "enum": ["pass", "fail", "warn", "info"]
          }
        }
      }
    },
    "reuse": {
      "type": "array",
      "description": "One entry per capability that `--reuse` named: whether a passed local-attest leg stood in for running the tool, and when it did not, why. Present only when `--reuse` was requested.",
      "items": {
        "type": "object",
        "required": ["capability", "leg", "reused"],
        "properties": {
          "capability": {
            "type": "string",
            "minLength": 1
          },
          "leg": {
            "type": "string",
            "minLength": 1
          },
          "reused": {
            "type": "boolean"
          },
          "reason": {
            "enum": [
              "NO_MANIFEST",
              "HEAD_MISMATCH",
              "DIRTY_TREE",
              "LEG_MISSING",
              "LEG_NOT_PASSED",
              "REPORT_NOT_PRODUCED",
              "REPORT_CHANGED",
              "REPORT_UNREADABLE"
            ],
            "description": "Why the tool ran instead. Every reason is the fail-safe direction: the tool ran itself."
          }
        }
      }
    }
  }
}
