{
  "schema": "finetic.release-evidence.v1",
  "product": "Finetic",
  "version": "0.1.92",
  "channel": "preview",
  "releasedAt": "2026-07-28T12:33:45Z",
  "sourceRevision": "b456ca9f4e51d41f1aa392968b7fa01bb3d8e149",
  "releaseTag": "v0.1.92-public-preview",
  "workflow": {
    "name": "Public Preview Image",
    "result": "success",
    "url": "https://github.com/360john360/finetic/actions/runs/30358982116"
  },
  "container": {
    "reference": "ghcr.io/360john360/finetic",
    "indexDigest": "sha256:f755291c2e21c6e91548853b8e2a4a02bc18880b40fd6fe59f0383b7c447923d",
    "platforms": {
      "linux/amd64": "sha256:af9f3f818e9463ae0ffededed40f1161130d4c6d39b78048bbad44d5a2a7849b",
      "linux/arm64": "sha256:c5b91e086fe0aede3ddb4d7aab75ce5ad0fb7f8cc99edd96b8c492c2f084b839"
    },
    "attestations": "BuildKit provenance and SBOM attestations are attached to the OCI index."
  },
  "validation": {
    "tests": {
      "executed": 470,
      "passed": 460,
      "failed": 0,
      "skippedFixtureDependent": 10
    },
    "typescript": "passed",
    "compiledReleaseBuild": "passed",
    "applicationPentest": {
      "checks": 35,
      "passed": 35,
      "failed": 0,
      "authorization": "Owner-authorized isolated application assessment",
      "sha256": "e109959dc2da0e6f15e25708e6faaaf6719c27a2627eac7fba35de650443d398"
    }
  },
  "inventory": {
    "format": "CycloneDX JSON",
    "components": 428,
    "sha256": "befe7713c79e72e7d6dd7097623ccafa8e5d70b5d8b37ba21d2df4eabac8cea0"
  },
  "vulnerabilities": {
    "scanner": "Trivy",
    "records": 718,
    "uniqueAdvisoryIds": 317,
    "recordsBySeverity": {
      "critical": 23,
      "high": 89,
      "medium": 223,
      "low": 228,
      "unknown": 155
    },
    "recordsWithAvailableFix": 0,
    "fixableHighOrCriticalRecords": 0,
    "secretFindings": 0,
    "sha256": "1bacd28f9b60555a1e060915ca512e09fe6a3e4e54984a51c575c7c487d1fdc0",
    "interpretation": "Counts include duplicated Debian package/advisory relationships and findings without a vendor-provided fixed version. Severity does not by itself establish reachability."
  },
  "limitations": [
    "The application assessment and release evidence are first-party, not independent certification.",
    "The published vulnerability report is a package inventory comparison and does not prove or disprove exploitability.",
    "The amd64 published image was rescanned directly; the arm64 image was produced from the same context by the attested multi-platform workflow.",
    "Ten fixture-dependent media tests were explicitly skipped because their external test corpus was not mounted into the isolated release gate."
  ]
}
