{"uri":"at://did:web:lexicon.atcr.io/com.atproto.lexicon.schema/io.atcr.hold.scan","cid":"bafyreidqtmx2ivfrmj5cfki2zej5fgjqux4svdv3rrkv2evs5f2jdld5yi","value":{"id":"io.atcr.hold.scan","defs":{"main":{"key":"any","type":"record","record":{"type":"object","required":["manifest","repository","userDid","critical","high","medium","low","total","scannerVersion","scannedAt"],"properties":{"low":{"type":"integer","minimum":0,"description":"Count of low severity vulnerabilities"},"high":{"type":"integer","minimum":0,"description":"Count of high severity vulnerabilities"},"total":{"type":"integer","minimum":0,"description":"Total vulnerability count"},"medium":{"type":"integer","minimum":0,"description":"Count of medium severity vulnerabilities"},"reason":{"type":"string","maxLength":256,"description":"Optional human-readable explanation for non-ok status (e.g. 'unscannable artifact type application/vnd.cncf.helm.config.v1+json')."},"status":{"type":"string","maxLength":32,"description":"Outcome of the scan attempt. 'ok' (or omitted, for back-compat) means the scanner produced an SBOM. 'failed' means the scanner ran but errored. 'skipped' means the scanner intentionally bypassed this artifact type (e.g. helm charts).","knownValues":["ok","failed","skipped"]},"userDid":{"type":"string","format":"did","description":"DID of the image owner"},"critical":{"type":"integer","minimum":0,"description":"Count of critical severity vulnerabilities"},"manifest":{"type":"string","format":"at-uri","description":"AT-URI of the scanned manifest (e.g., at://did:plc:xyz/io.atcr.manifest/abc123...)"},"sbomBlob":{"type":"blob","accept":["application/spdx+json"],"description":"SBOM blob (SPDX JSON format) uploaded to the hold's blob storage"},"scannedAt":{"type":"string","format":"datetime","description":"RFC3339 timestamp of when the scan completed"},"repository":{"type":"string","maxLength":256,"description":"Repository name (e.g., myapp)"},"scannerVersion":{"type":"string","maxLength":64,"description":"Version of the scanner that produced this result (e.g., atcr-scanner-v1.0.0)"},"vulnReportBlob":{"type":"blob","accept":["application/vnd.atcr.vulnerabilities+json"],"description":"Grype vulnerability report blob (JSON) with full CVE details"}}},"description":"Vulnerability scan results for a container manifest. Stored in the hold's embedded PDS. Record key is deterministic: the manifest digest hex without the 'sha256:' prefix, so re-scans upsert the existing record."}},"$type":"com.atproto.lexicon.schema","lexicon":1}}