Skip to content

Audit provenance

Every live audit can carry a small secret-safe provenance record that identifies what was audited and under which effective policy.

Fields

Field Meaning
target Canonical project path when already available, otherwise the supplied target.
instance_url GitLab instance base URL.
package_version Installed gitlab-project-audit version.
rule_set_fingerprint SHA-256 of the canonical effective rule-ID set.
policy_fingerprint SHA-256 of canonical effective policy configuration.
default_ref Audited default branch/ref when available without extra API access.

Fingerprints

Fingerprints are deterministic. Ordering differences in equivalent rule selections or policy lists do not change the digest.

The policy fingerprint includes effective:

  • enabled/disabled categories
  • enabled/disabled rules
  • severity overrides
  • suppressions and expiry dates
  • failure threshold
  • preset identity/version

Security

Provenance never contains:

  • GitLab access tokens
  • request headers
  • CI/CD variable values
  • raw GitLab response bodies

Contracts

Provenance was added in machine-readable schema version 1.1 for reports, portfolio reports, baselines, and snapshots. Historical 1.0 schemas remain packaged, and 1.0 baselines/snapshots remain readable.