{
  "releaseSnapshot": {
    "format": "static-release-reference-v1",
    "sourceVersion": "0.29.0",
    "sourceRegistrySha256": "a2b5ec09bf6c38b9d2879d746a4fded374f5928b445377b0270ef6aa8e6cac65",
    "generatedAt": "2026-10-06T15:38:00Z",
    "releaseAcceptance": "not-verified-by-generator",
    "runtimeReadiness": "not-evaluated",
    "livePaymentsVerified": false,
    "indexingVerified": false,
    "apiOrigin": null,
    "notice": "Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment."
  },
  "exampleResponse": {
    "operation": "dockerfile-audit",
    "version": "0.29.0",
    "result": {
      "profile": "bounded-dockerfile-static-v1",
      "analysis": "bounded-static-observations",
      "inputBytes": 154,
      "physicalLines": 8,
      "instructionCount": 8,
      "finalStageIndex": 1,
      "stages": [
        {
          "index": 0,
          "fromLine": 1,
          "endLine": 4,
          "baseKind": "external-image",
          "digestPinned": false,
          "runtimeUser": "base-unknown",
          "userSourceLine": null
        },
        {
          "index": 1,
          "fromLine": 5,
          "endLine": 8,
          "baseKind": "external-image",
          "digestPinned": false,
          "runtimeUser": "explicit-nonroot",
          "userSourceLine": 7
        }
      ],
      "rulesEvaluated": [
        "DF001",
        "DF002",
        "DF003",
        "DF004",
        "DF005",
        "DF006",
        "DF007",
        "DF008",
        "DF009",
        "DF010",
        "DF011",
        "DF012",
        "DF013",
        "DF014"
      ],
      "findings": [
        {
          "ruleId": "DF002",
          "severity": "info",
          "category": "reproducibility",
          "confidence": "syntactic",
          "line": 1,
          "endLine": 1,
          "stageIndex": 0,
          "evidence": "FROM external image: explicit tag, no sha256 digest",
          "message": "External base image has a tag but no digest pin.",
          "remediation": "Consider pinning a verified digest for reproducibility; arrange updates so pinning does not indefinitely prevent security fixes."
        },
        {
          "ruleId": "DF007",
          "severity": "info",
          "category": "build-hygiene",
          "confidence": "syntactic",
          "line": 3,
          "endLine": 3,
          "stageIndex": 0,
          "evidence": "COPY includes a literal whole-context source; ignore rules not inspected",
          "message": "A local COPY or ADD source includes the context root or a whole-context wildcard.",
          "remediation": "Review .dockerignore and prefer the required paths. Context contents and ignore rules were not supplied, so accidental inclusion is not established."
        },
        {
          "ruleId": "DF002",
          "severity": "info",
          "category": "reproducibility",
          "confidence": "syntactic",
          "line": 5,
          "endLine": 5,
          "stageIndex": 1,
          "evidence": "FROM external image: explicit tag, no sha256 digest",
          "message": "External base image has a tag but no digest pin.",
          "remediation": "Consider pinning a verified digest for reproducibility; arrange updates so pinning does not indefinitely prevent security fixes."
        }
      ],
      "summary": {
        "totalFindings": 3,
        "returnedFindings": 3,
        "bySeverity": {
          "info": 3,
          "warning": 0
        },
        "truncated": false,
        "variableDependentInstructions": 0
      },
      "limitations": [
        "Static observations only: no build, command execution, filesystem access, network requests, registry lookup, vulnerability scan or safety verdict.",
        "Base-image metadata, runtime overrides, build arguments, named contexts, .dockerignore and source files are not available. Variable expressions are not evaluated, including ARG defaults.",
        "Shell programs and package-install commands are opaque. No shell correctness, package pinning or script security analysis is performed.",
        "Recognized instructions without a listed rule are retained for structure only. This is not a complete Docker parser, compiler or build-success check.",
        "Heredocs, ONBUILD, custom/labs frontends, unknown instructions/flags, ambiguous terminal escapes and malformed supported forms are rejected rather than partially interpreted.",
        "Findings are potential issues to review. Secret checks use names only; values, source snippets, image references and URLs are not echoed. A report with no findings does not establish safety.",
        "The final stage is the last textual FROM; --target selection is not an input. Rules inspect all textual stages, including stages a build might skip. Docker #check suppressions do not suppress this profile's rules."
      ]
    },
    "provenance": {
      "inputSha256": "da6f61385220259b52108217ce4cdf1b3ba1cca6ab6e6fc3a888dfc8b17095dc",
      "outputSha256": "590de60e78b37fc2620732486c55052fcc81de4436e975f6161100084cbcab00",
      "deterministic": true,
      "externalRequests": 0
    }
  }
}
