Audit provenance¶
Every live audit can carry a small secret-safe provenance record that identifies what was audited and under which effective policy.
Fields¶
| Field | Meaning |
|---|---|
target |
Canonical project path when already available, otherwise the supplied target. |
instance_url |
GitLab instance base URL. |
package_version |
Installed gitlab-project-audit version. |
rule_set_fingerprint |
SHA-256 of the canonical effective rule-ID set. |
policy_fingerprint |
SHA-256 of canonical effective policy configuration. |
default_ref |
Audited default branch/ref when available without extra API access. |
Fingerprints¶
Fingerprints are deterministic. Ordering differences in equivalent rule selections or policy lists do not change the digest.
The policy fingerprint includes effective:
- enabled/disabled categories
- enabled/disabled rules
- severity overrides
- suppressions and expiry dates
- failure threshold
- preset identity/version
Security¶
Provenance never contains:
- GitLab access tokens
- request headers
- CI/CD variable values
- raw GitLab response bodies
Contracts¶
Provenance was added in machine-readable schema version 1.1 for reports, portfolio reports, baselines, and snapshots. Historical 1.0 schemas remain packaged, and 1.0 baselines/snapshots remain readable.