API reference

View as Markdown

Every operation in the Proofline Review API 1.0.0, generated from the same OpenAPI document the SDKs are built from. All paths are under /api/v1/organizations/{org_id} and take a token with the scope shown.

The full document is at /docs/openapi.json.

Each example reads the token, the organization and every other required parameter from an environment variable named after it, such as REVIEW_ID for review_id.

Reviews#

Export reviews#

GET /api/v1/organizations/{org_id}/exports/{dataset}

Export review metadata

Returns one page of a version-1 export dataset (reviews, finding_outcomes, finding_validations, spend or findings) for an RFC3339 window of at most 31 days, as NDJSON by default or CSV. Rows respect the token's repository restriction.

  • Scope: analytics:read
  • SDKs: no method, because the response is not JSON. Call it over HTTP.
  • Returns: 200 as application/x-ndjson or text/csv, one ExportRow per row
ParameterInTypeRequiredDescription
datasetpathDatasetyes
org_idpathstring (uuid)yes
cursorquerystring or nullnoTreat this signed continuation as opaque. Retain the same window and grouping.
formatquerystring or nullnondjson (default) or csv. Each CSV page repeats its column header.
fromquerystringyesInclusive RFC3339 creation, debit or first-publication time. At most 31 days.
group_byqueryFindingOutcomesGroupBy or nullnofinding_outcomes only; defaults to repository.
toquerystringyesExclusive RFC3339 creation, debit or first-publication time.
const organizationId = process.env.PROOFLINE_ORGANIZATION_ID!;
const dataset = process.env.DATASET!;
const query = new URLSearchParams({ from: process.env.FROM!, to: process.env.TO! });
const response = await fetch(
  `https://proofline.sh/api/v1/organizations/${organizationId}/exports/${dataset}?${query}`,
  { headers: { Authorization: `Bearer ${process.env.PROOFLINE_TOKEN!}` } },
);
if (!response.ok) {
  throw new Error(`Proofline answered ${response.status}: ${await response.text()}`);
}
console.log(await response.text());

List repositories#

GET /api/v1/organizations/{org_id}/repository-names

List repository names

Returns the ID and full name of each connected repository inside the token's repository restriction, including repositories with no review, so a client can resolve owner/name to an ID.

  • Scope: reviews:read
  • TypeScript: client.listRepositories()
  • Python: client.list_repositories()
  • Returns: 200 RepositoryNames
ParameterInTypeRequiredDescription
org_idpathstring (uuid)yes
import { ProoflineClient } from "@proofline/sdk";

const client = new ProoflineClient({
  baseUrl: "https://proofline.sh",
  token: process.env.PROOFLINE_TOKEN!,
});
const result = await client.listRepositories({
  path: { org_id: process.env.PROOFLINE_ORGANIZATION_ID! },
});
console.log(result);

List reviews#

GET /api/v1/organizations/{org_id}/reviews

List reviews

Lists the latest run of each pull request in the organization, with filters and cursor pagination. A search equal to a full head commit SHA returns the latest run at that commit instead.

  • Scope: reviews:read
  • TypeScript: client.listReviews()
  • Python: client.list_reviews()
  • Returns: 200 ReviewPage
ParameterInTypeRequiredDescription
attentionquerystring or nullnoneeded lists terminal reviews of open pull requests with active findings, FAILED/INCOMPLETE/STOPPED execution, or an earlier reviewed commit.
authorquerystring or nullno
cursorquerystring or nullno
environmentquerystring (uuid) or nullno
findingsquerystring or nullno
kindquerystring or nullno
limitqueryinteger (int64) or nullno
repositoryquerystring (uuid) or nullno
searchquerystring or nullno
statusquerystring or nullno
org_idpathstring (uuid)yes
import { ProoflineClient } from "@proofline/sdk";

const client = new ProoflineClient({
  baseUrl: "https://proofline.sh",
  token: process.env.PROOFLINE_TOKEN!,
});
const result = await client.listReviews({
  path: { org_id: process.env.PROOFLINE_ORGANIZATION_ID! },
});
console.log(result);

Get review#

GET /api/v1/organizations/{org_id}/reviews/{review_id}

Get a review

Returns a review with its subjects, assessments and open items. An incomplete assessment reports its gaps; an empty finding list from it says nothing about the change.

  • Scope: reviews:read
  • TypeScript: client.getReview()
  • Python: client.get_review()
  • Returns: 200 CustomerReviewDetail
ParameterInTypeRequiredDescription
org_idpathstring (uuid)yes
review_idpathstring (uuid)yes
import { ProoflineClient } from "@proofline/sdk";

const client = new ProoflineClient({
  baseUrl: "https://proofline.sh",
  token: process.env.PROOFLINE_TOKEN!,
});
const result = await client.getReview({
  path: {
    org_id: process.env.PROOFLINE_ORGANIZATION_ID!,
    review_id: process.env.REVIEW_ID!,
  },
});
console.log(result);

Get assessment#

GET /api/v1/organizations/{org_id}/reviews/{review_id}/assessments/{assessment_id}

Get an assessment

Returns one assessment of a review with its decision, checks and findings.

  • Scope: findings:read
  • TypeScript: client.getAssessment()
  • Python: client.get_assessment()
  • Returns: 200 CustomerAssessmentDetail
ParameterInTypeRequiredDescription
assessment_idpathstring (uuid)yes
org_idpathstring (uuid)yes
review_idpathstring (uuid)yes
import { ProoflineClient } from "@proofline/sdk";

const client = new ProoflineClient({
  baseUrl: "https://proofline.sh",
  token: process.env.PROOFLINE_TOKEN!,
});
const result = await client.getAssessment({
  path: {
    org_id: process.env.PROOFLINE_ORGANIZATION_ID!,
    review_id: process.env.REVIEW_ID!,
    assessment_id: process.env.ASSESSMENT_ID!,
  },
});
console.log(result);

Rerun review#

POST /api/v1/organizations/{org_id}/reviews/{review_id}/rerun

Rerun a review

Creates a new run of the review's original immutable code subject and leaves earlier runs unchanged. A local patch review is not rerun. Requires live GitHub write access; a repeated request can create another run, so clients make one attempt.

  • Scope: reviews:rerun
  • TypeScript: client.rerunReview()
  • Python: client.rerun_review()
  • Returns: 200 RerunResponse
ParameterInTypeRequiredDescription
org_idpathstring (uuid)yes
review_idpathstring (uuid)yes
import { ProoflineClient } from "@proofline/sdk";

const client = new ProoflineClient({
  baseUrl: "https://proofline.sh",
  token: process.env.PROOFLINE_TOKEN!,
});
const result = await client.rerunReview({
  path: {
    org_id: process.env.PROOFLINE_ORGANIZATION_ID!,
    review_id: process.env.REVIEW_ID!,
  },
});
console.log(result);

Get review routing#

GET /api/v1/organizations/{org_id}/reviews/{review_id}/routing

Get review routing

Returns the review's validated routing plan and recorded finding placements. It reports retained routing facts, not model output or a deployment recommendation.

  • Scope: reviews:read
  • TypeScript: client.getReviewRouting()
  • Python: client.get_review_routing()
  • Returns: 200 ReviewRoutingView
ParameterInTypeRequiredDescription
org_idpathstring (uuid)yes
review_idpathstring (uuid)yes
import { ProoflineClient } from "@proofline/sdk";

const client = new ProoflineClient({
  baseUrl: "https://proofline.sh",
  token: process.env.PROOFLINE_TOKEN!,
});
const result = await client.getReviewRouting({
  path: {
    org_id: process.env.PROOFLINE_ORGANIZATION_ID!,
    review_id: process.env.REVIEW_ID!,
  },
});
console.log(result);

Get deployment review#

GET /api/v1/organizations/{org_id}/reviews/deployments/{public_key}

Get a deployment review

Returns the deployment review with the given public key.

  • Scope: reviews:read
  • TypeScript: client.getDeploymentReview()
  • Python: client.get_deployment_review()
  • Returns: 200 CustomerReviewDetail
ParameterInTypeRequiredDescription
org_idpathstring (uuid)yes
public_keypathstringyes
import { ProoflineClient } from "@proofline/sdk";

const client = new ProoflineClient({
  baseUrl: "https://proofline.sh",
  token: process.env.PROOFLINE_TOKEN!,
});
const result = await client.getDeploymentReview({
  path: {
    org_id: process.env.PROOFLINE_ORGANIZATION_ID!,
    public_key: process.env.PUBLIC_KEY!,
  },
});
console.log(result);

List pull request reviews#

GET /api/v1/organizations/{org_id}/reviews/pr/{repository}/{pull_request_number}

List a pull request's review runs

Lists the review runs of one pull request, addressed by repository name and pull request number.

  • Scope: reviews:read
  • TypeScript: client.listPullRequestReviews()
  • Python: client.list_pull_request_reviews()
  • Returns: 200 ReviewPage
ParameterInTypeRequiredDescription
org_idpathstring (uuid)yes
pull_request_numberpathinteger (int64)yes
repositorypathstringyes
attentionquerystring or nullnoneeded lists terminal reviews of open pull requests with active findings, FAILED/INCOMPLETE/STOPPED execution, or an earlier reviewed commit.
authorquerystring or nullno
cursorquerystring or nullno
environmentquerystring (uuid) or nullno
findingsquerystring or nullno
kindquerystring or nullno
limitqueryinteger (int64) or nullno
repositoryquerystring (uuid) or nullno
searchquerystring or nullno
statusquerystring or nullno
import { ProoflineClient } from "@proofline/sdk";

const client = new ProoflineClient({
  baseUrl: "https://proofline.sh",
  token: process.env.PROOFLINE_TOKEN!,
});
const result = await client.listPullRequestReviews({
  path: {
    org_id: process.env.PROOFLINE_ORGANIZATION_ID!,
    repository: process.env.REPOSITORY!,
    pull_request_number: Number(process.env.PULL_REQUEST_NUMBER),
  },
});
console.log(result);

Get pull request review#

GET /api/v1/organizations/{org_id}/reviews/pr/{repository}/{pull_request_number}/runs/{run_number}

Get a pull request review run

Returns one review run of a pull request, addressed by repository name, pull request number and run number.

  • Scope: reviews:read
  • TypeScript: client.getPullRequestReview()
  • Python: client.get_pull_request_review()
  • Returns: 200 CustomerReviewDetail
ParameterInTypeRequiredDescription
org_idpathstring (uuid)yes
pull_request_numberpathinteger (int64)yes
repositorypathstringyes
run_numberpathinteger (int64)yes
import { ProoflineClient } from "@proofline/sdk";

const client = new ProoflineClient({
  baseUrl: "https://proofline.sh",
  token: process.env.PROOFLINE_TOKEN!,
});
const result = await client.getPullRequestReview({
  path: {
    org_id: process.env.PROOFLINE_ORGANIZATION_ID!,
    repository: process.env.REPOSITORY!,
    pull_request_number: Number(process.env.PULL_REQUEST_NUMBER),
    run_number: Number(process.env.RUN_NUMBER),
  },
});
console.log(result);

Findings#

Get finding#

GET /api/v1/organizations/{org_id}/findings/{finding_id}

Get a finding

Returns one finding with its evidence references, validation state and causal graph.

  • Scope: findings:read
  • TypeScript: client.getFinding()
  • Python: client.get_finding()
  • Returns: 200 CustomerFinding
ParameterInTypeRequiredDescription
finding_idpathstring (uuid)yes
org_idpathstring (uuid)yes
import { ProoflineClient } from "@proofline/sdk";

const client = new ProoflineClient({
  baseUrl: "https://proofline.sh",
  token: process.env.PROOFLINE_TOKEN!,
});
const result = await client.getFinding({
  path: {
    org_id: process.env.PROOFLINE_ORGANIZATION_ID!,
    finding_id: process.env.FINDING_ID!,
  },
});
console.log(result);

Repositories#

Request patch review#

POST /api/v1/organizations/{org_id}/repositories/{repo_id}/patch-reviews

Review local changes

Reviews a unified diff against a commit GitHub has in the repository, and returns that patch's review when one exists. The review reads only that commit and the patch, and is never posted to a pull request. Requires live GitHub read access; the same patch on the same base always returns the same review.

  • Scope: reviews:request
  • TypeScript: client.requestPatchReview()
  • Python: client.request_patch_review()
  • Returns: 200 PatchReviewResponse
ParameterInTypeRequiredDescription
org_idpathstring (uuid)yes
repo_idpathstring (uuid)yes

Request body: PatchReviewRequest

import { ProoflineClient } from "@proofline/sdk";

const client = new ProoflineClient({
  baseUrl: "https://proofline.sh",
  token: process.env.PROOFLINE_TOKEN!,
});
const result = await client.requestPatchReview(
  {
    path: {
      org_id: process.env.PROOFLINE_ORGANIZATION_ID!,
      repo_id: process.env.REPO_ID!,
    },
  },
  { base_commit_sha: process.env.BASE_COMMIT_SHA!, patch: process.env.PATCH! },
);
console.log(result);

Request review#

POST /api/v1/organizations/{org_id}/repositories/{repo_id}/pull-requests/{number}/review

Request a pull request review

Returns the active or result-bearing review at the pull request's live head, or creates a withheld one. The FULL mode creates a new review of the whole change unless one is pending or running. Requires live GitHub write access; a repeated request can create another review, so clients make one attempt.

  • Scope: reviews:request
  • TypeScript: client.requestReview()
  • Python: client.request_review()
  • Returns: 200 RunNowResponse
ParameterInTypeRequiredDescription
numberpathinteger (int64)yes
org_idpathstring (uuid)yes
repo_idpathstring (uuid)yes

Request body: RunNowRequest

import { ProoflineClient } from "@proofline/sdk";

const client = new ProoflineClient({
  baseUrl: "https://proofline.sh",
  token: process.env.PROOFLINE_TOKEN!,
});
const result = await client.requestReview(
  {
    path: {
      org_id: process.env.PROOFLINE_ORGANIZATION_ID!,
      repo_id: process.env.REPO_ID!,
      number: Number(process.env.NUMBER),
    },
  },
  { mode: "EXISTING_OR_NEW" },
);
console.log(result);

Get review guidance#

GET /api/v1/organizations/{org_id}/repositories/{repo_id}/review-guidance

Get repository review guidance

Returns the review guidance configured for a repository, for tools and coding agents that read it before writing code.

  • Scope: guidance:read
  • TypeScript: client.getReviewGuidance()
  • Python: client.get_review_guidance()
  • Returns: 200 RepositoryGuidance
ParameterInTypeRequiredDescription
org_idpathstring (uuid)yes
repo_idpathstring (uuid)yes
import { ProoflineClient } from "@proofline/sdk";

const client = new ProoflineClient({
  baseUrl: "https://proofline.sh",
  token: process.env.PROOFLINE_TOKEN!,
});
const result = await client.getReviewGuidance({
  path: {
    org_id: process.env.PROOFLINE_ORGANIZATION_ID!,
    repo_id: process.env.REPO_ID!,
  },
});
console.log(result);

Schemas#

Errors use Problem, an RFC 9457 problem document. The HTTP status is authoritative.

ActionUnavailability#

Type: READ_ONLY, REPOSITORY_UNAVAILABLE, REPOSITORY_WRITE_REQUIRED, PERMISSION_CHECK_UNAVAILABLE

ActorView#

The person behind an action on a review, as the page names them.

FieldTypeRequiredDescription
github_user_idinteger (int64)yesStable GitHub identity. The login below is display metadata.
loginstringyesThe login they were known by when they acted. Display metadata.
profile_urlstring or nullnoTheir profile on the deployment's GitHub host.

AssessmentProjection#

FieldTypeRequiredDescription
assessment_idstring (uuid)yesAssessment that owns this route binding.
environment_idstring (uuid)yesEnvironment that the assessment covers.
pass_output_recordedbooleanyesWhether this assessment retained a generalist output record.
pass_output_sha256string or nullnoDigest of the immutable generalist output, when the assessment retained one.
passesarray of PassProjectionyesPass and symbolic model binding retained by the plan.
reachstringyesEnvironment reach retained by the plan.

AttributedChange#

How one condition relates to the review's base revision.

Type: string or string or string or string or string

AttributedConditionView#

FieldTypeRequiredDescription
changeAttributedChangeyesHow this condition relates to the review's base revision.
reviewed_tree_citationsarray of ReviewedTreeCitationViewyesThe member that declares the site at each revision that declares it.
revisionAttributedRevisionyesThe revision that holds the condition: the base for RESOLVED, the proposed revision for INTRODUCED, CHANGED and UNCHANGED, and either for UNATTRIBUTED.
subjectUntrustedTextyesWorld's label of the condition's site and what it declares, such as .github/workflows/ci.yml jobs.test.steps[0].uses: actions/checkout@v4. It quotes repository text.

AttributedRevision#

Type: string or string

AttributionStatus#

Type: string or string or string

AuthorChoice#

FieldTypeRequiredDescription
idinteger (int64)yesThe pull request author's GitHub user ID, the value the author filter accepts.
loginstring or nullnoThe author's most recently recorded GitHub login, a display label. Null when none is recorded.

Authority#

Type: ADVISORY, DEPLOYMENT_POLICY

Availability#

Type: RECORDED, NOT_RECORDED, LEGACY, OPERATIONAL_FAILURE or string

ChangeAttributionView#

Which conditions behind a check's result the change brought, and which World found at the review's base revision. It sits beside the result and never changes it: a condition already at the base is still a condition.

FieldTypeRequiredDescription
complete_recordCompleteRecordView or nullnoWhere every condition is recorded when some are omitted. Absent when conditions lists them all.
condition_countinteger (uint32)yesHow many conditions World attributed, listed or not. Zero unless status is COMPARED.
conditionsarray of AttributedConditionViewyesEvery condition, each once, in World's order, never netted against another. Empty unless status is COMPARED, and empty when some are omitted: it never lists only some of them.
countsarray of ChangeCountViewyesHow many conditions there are of each change at each revision, over every condition, listed or not. Changes with none are left out.
detail_codestring or nullnoWorld's code for why it could not read that revision, such as BASE_REVIEWED_TREE_NOT_DECLARED. Present exactly when status is UNAVAILABLE.
listed_conditionsarray of AttributedConditionView or nullnoThe conditions a summary lists when some are omitted: the first ones in the order counts gives, each whole, at most 50 and always fewer than condition_count. Present exactly when omitted_condition_count is not zero.
omitted_condition_countinteger (uint32)yesHow many of those conditions this response does not list. Zero when the result kept World's attribution whole. Otherwise the result kept a summary: listed_conditions lists the first ones, counts is still exact, and World's recorded evaluation holds every condition.
revisionAttributedRevision or nullnoThe revision World could not read. Present exactly when status is UNAVAILABLE.
statusAttributionStatusyesWhether World compared both revisions, could not read one, or recorded an attribution this build cannot read.

ChangeCountView#

How many conditions are of one change at one revision.

FieldTypeRequiredDescription
changeAttributedChangeyesHow the counted conditions relate to the review's base revision.
countinteger (uint32)yesHow many conditions have this change at this revision, over every condition, listed or not.
revisionAttributedRevisionyesThe revision that holds the counted conditions.

CheckLifecycle#

World's lifecycle disclosure for the evaluator version that answered, as the receipt recorded it. A deployment gate counts only GATING results (DeterministicCoverage::gate_effective_status), and only when it evaluates a deployment; the lifecycle alone permits or blocks nothing.

Type: string or string or string or string or string

CommentAddressEvaluationView#

One stored post-merge judgment of a finding comment.

FieldTypeRequiredDescription
evaluated_atstring (date-time)yesWhen the evaluation was made.
outcomeCommentAddressOutcomeyesADDRESSED, NOT_ADDRESSED, or INCOMPLETE when the merged code could not be judged.
reasonstringyesServer-authored reason. Render as text.

CommentAddressOutcome#

Type: ADDRESSED, NOT_ADDRESSED, INCOMPLETE

CommentReaction#

Type: THUMBS_UP, THUMBS_DOWN, LAUGH, HOORAY, CONFUSED, HEART, ROCKET, EYES

CommentReactionView#

One stored reaction on the finding's root comment.

FieldTypeRequiredDescription
actor_github_user_idinteger (int64)yesThe stable GitHub identity of whoever reacted.
actor_loginstring or nullnoProvider text. Render as text.
github_comment_idinteger (int64)yesThe GitHub comment the reaction is on: the finding's root comment.
reactionCommentReactionyesThe reaction as GitHub names it.

CompleteRecordView#

World's immutable record of the complete answer an omitted list comes from.

FieldTypeRequiredDescription
attribution_digeststringyesThe sha256: digest of the complete attribution in that record.
world_evaluation_idstringyesThe evaluation World recorded, which holds every condition.

CustomerAssessment#

FieldTypeRequiredDescription
checksCustomerChecksyesThe deterministic World checks recorded for this assessment.
completed_atstring (date-time) or nullnoWhen the assessment completed. Null while it has not.
decision_presentationCustomerDecision or nullnoThe retained decision disclosure, which grants no deployment authorization. Absent when none is recorded and the review kind records no decision basis.
domainsarray of DomainViewyesThe risk domains the assessment evaluated, each with its status and reason, ordered by domain.
environment_display_namestringyesThe display name of the environment this assessment covers.
findingsarray of CustomerFindingyesThe findings this assessment recorded, SERIOUS first.
idstring (uuid)yesThe assessment's ID.
incompleteness_kindstring or nullnoWhy an INCOMPLETE assessment is incomplete: NOT_CONFIGURED, POLICY_EXCLUDED, EVIDENCE_UNAVAILABLE, HYPOTHESES_UNRESOLVED or MODEL_BUDGET_EXHAUSTED. Absent otherwise; an unclassified gap is not a complete assessment.
reason_codesarray of string or nullnoThe assessment gap codes the backend recorded. Absent on historical records.
release_evidence_gapstring or nullnoThe typed gap the automatic release-set read recorded. Null when the read is pending, pinned a release, or was never attempted.
started_atstring (date-time) or nullnoWhen the assessment started. Null until it starts.
statusstringyesThe assessment's recorded status, such as RUNNING, COMPLETED or INCOMPLETE.

CustomerAssessmentDetail#

FieldTypeRequiredDescription
checksCustomerChecksyesThe deterministic World checks recorded for this assessment.
completed_atstring (date-time) or nullnoWhen the assessment completed. Null while it has not.
decision_presentationCustomerDecision or nullnoThe retained decision disclosure, which grants no deployment authorization. Absent when none is recorded and the review kind records no decision basis.
domainsarray of DomainViewyesThe risk domains the assessment evaluated, each with its status and reason, ordered by domain.
environment_display_namestringyesThe display name of the environment this assessment covers.
findingsarray of CustomerFindingyesThe findings this assessment recorded, SERIOUS first.
idstring (uuid)yesThe assessment's ID.
incompleteness_kindstring or nullnoWhy an INCOMPLETE assessment is incomplete: NOT_CONFIGURED, POLICY_EXCLUDED, EVIDENCE_UNAVAILABLE, HYPOTHESES_UNRESOLVED or MODEL_BUDGET_EXHAUSTED. Absent otherwise; an unclassified gap is not a complete assessment.
reason_codesarray of string or nullnoThe assessment gap codes the backend recorded. Absent on historical records.
release_evidence_gapstring or nullnoThe typed gap the automatic release-set read recorded. Null when the read is pending, pinned a release, or was never attempted.
review_idstring (uuid)yesThe review this assessment belongs to.
started_atstring (date-time) or nullnoWhen the assessment started. Null until it starts.
statusstringyesThe assessment's recorded status, such as RUNNING, COMPLETED or INCOMPLETE.
subjectsarray of SubjectViewyesThe review subjects this assessment's own release set authorized, plus each PRIMARY subject that carries no release authorization.

CustomerCheck#

FieldTypeRequiredDescription
change_attributionChangeAttributionView or nullnoWhich conditions behind the outcome the change brought and which were already at the review's base revision. It never changes the outcome: a condition already at the base is pre-existing, not safe. Absent for a check whose evaluator does not compare the two revisions.
detailstring or nullnoWhy World refused the check, or otherwise World's recorded explanation of the result. Null when neither is recorded.
evaluated_atstring or nullnoWhen World evaluated this answer. A reused answer is evidence from this instant, which can precede the assessment.
lifecycleCheckLifecycleyesThe lifecycle of the evaluator version that answered. It says whether a deployment gate could count this result, not whether one did.
namestringyesThe check's readable name, derived from its key.
outcomestringyesThe outcome the receipt recorded, which is the outcome a deployment gate weighed: READY, BLOCKED, UNRESOLVED, UNAVAILABLE, NOT_APPLICABLE or NOT_ASKED. A verdict never rewrites it.
unresolved_reasonUnresolvedReason or nullnoWhy an UNRESOLVED check did not settle, as World's verdict gave it. Absent on every other outcome, and on an unresolved receipt whose verdict names none of these reasons.

CustomerChecks#

FieldTypeRequiredDescription
familiesarray of CustomerCheckyesOne entry per recorded check result, ordered by check key and version. Empty when no receipt exists.
receipt_recordedbooleanyesWhether these checks come from an immutable deterministic coverage receipt. When false, no check result is recorded.
statusstringyesThe receipt's status, or PENDING, SUPERSEDED, STOPPED, NOT_ATTEMPTED or UNAVAILABLE when no receipt exists.

CustomerDecision#

FieldTypeRequiredDescription
authorityAuthorityyesWhether the decision is ADVISORY or comes from a DEPLOYMENT_POLICY.
availabilityAvailabilityyesWhether a verified decision record is present, absent, legacy, failed, or too large for this projection.
basisCustomerDecisionBasis or nullnoThe permission, evidence classification and reason code of the verified recorded basis. Null when no verified basis is recorded.
gate_stateGateState or nullnoThe local deployment gate state and any recorded override. Null unless the decision belongs to a deployment gate.

CustomerDecisionBasis#

FieldTypeRequiredDescription
evidenceEvidenceViewyesHow the recorded basis classified its evidence.
permissionPermissionViewyesThe permission the recorded basis reached: PERMIT or BLOCK.
reason_codestringyesThe reason code the recorded basis gives for its permission.

CustomerEvidenceRef#

FieldTypeRequiredDescription
commit_shastring or nullnoThe commit a file or commit reference reads. Null for other kinds, and for a file reference whose review recorded no head commit.
companion_repositorystring or nullnoThe repository a companion_repository_file reference reads from. Null for every other kind.
end_lineinteger (uint32) or nullnoThe last cited line of a file reference. Null when the reference names no end line or is not a file reference.
kindstringyesThe reference's kind: repository_file, companion_repository_file, commit, workflow_run, world_entity, deterministic_test, recorded_read or text.
labelstringyesThe reference's display label, such as a path with its line range. A recorded read or an unnamed World entity carries a fixed label, and a deterministic test carries its check's readable name.
legacy_textstring or nullnoThe unstructured text of a text reference. Null for structured references and for recorded reads.
provenance_statusstringyesHow the reference was obtained: VERIFIED_REPOSITORY_READ, PINNED_WORLD_ENTITY, EXECUTED_DETERMINISTIC_TEST, PROVIDER_REFERENCE, RECORDED_READ or LEGACY_UNSTRUCTURED.
repository_pathstring or nullnoThe cited file's path for a file reference. Null for every other kind.
start_lineinteger (uint32) or nullnoThe first cited line of a file reference. Null when the reference cites no line or is not a file reference.
urlstring or nullnoThe link the reference resolves to. Null when it resolves to none or the review's repository or head commit is unknown.
workflow_attemptinteger (int32) or nullnoThe run attempt of a workflow_run reference. Null when the reference names no attempt or is another kind.
workflow_run_idinteger (int64) or nullnoThe GitHub Actions run ID of a workflow_run reference. Null for every other kind.

CustomerFinding#

FieldTypeRequiredDescription
causal_graphFindingCausalGraphView or nullnoThe typed causal graph the reviewer supplied for an ordering or reachability finding. Null when the finding carries none.
claimstringyesWhat the reviewer states is wrong.
comment_evaluationCommentAddressEvaluationView or nullnoThe post-merge judgment of whether the finding comment was addressed. It is not a finding decision; null when none is recorded.
comment_reactionsarray of CommentReactionViewyesEmoji reactions stored on the Proofline finding comment. They are not a finding decision.
evidence_classFindingEvidenceClass or nullnoThe kind of proof the finding rests on, derived from the typed evidence it cites. Null on findings recorded before the class existed.
evidence_refsarray of CustomerEvidenceRefyesThe references the finding cites, resolved as the pull request comment resolves them.
github_comment_urlstring or nullnoThe inline GitHub comment published for this occurrence of the finding. Null when none was published; earlier runs are never used as a fallback.
idstring (uuid)yesThe finding's ID.
impactstringyesThe consequence the reviewer states the claim has.
latest_validationCustomerFindingValidation or nullnoThe latest decision on the finding's series, with who made it, where and when. Null when no decision is recorded.
lifecycle_statestringyesThe finding's recorded lifecycle state: NEW, UNCHANGED, RESOLVED or REINTRODUCED.
remediationstring or nullnoThe reviewer's proposed fix. Null when it proposed none.
risk_domainstringyesThe risk domain the reviewer assigned to the finding.
severitystringyesSERIOUS or WARNING.
supporting_evidenceFindingSupport or nullnoThe verdict explanation and evidence of the supported hypothesis that produced this finding. Null when the finding links no supported hypothesis.
symbolsarray of stringyesThe code identifiers the reviewer declared in the finding's prose, in declaration order, so a reader can set each as code.
thread_observationThreadObservationView or nullnoThe latest observation of the finding's GitHub thread state. It is not a finding decision; null when none is recorded.
validationstring or nullnoThe latest decision on the finding, the same value latest_validation carries. Null when no decision is recorded.

CustomerFindingValidation#

FieldTypeRequiredDescription
actor_github_user_idinteger (int64) or nullnoThe actor's stable GitHub user ID. Null for the automatic decision.
actor_loginstring or nullnoThe actor's GitHub login, a display label to render as text. Null for the automatic decision.
covering_author_kindstring or nullnoFor ALREADY_COVERED, HUMAN or BOT. Null for every other decision.
covering_author_loginstring or nullnoFor ALREADY_COVERED, the login of whoever wrote the covering comment, to render as text. Null for every other decision.
covering_comment_created_atstring (date-time) or nullnoFor ALREADY_COVERED, when the covering comment was written. Null for every other decision.
github_comment_urlstring or nullnoThe comment that carried a decision made on GitHub, or, for ALREADY_COVERED, the other reviewer's comment the decision rests on.
recorded_atstring (date-time)yesWhen Proofline recorded the decision.
sourcestringyesWhere the decision came from: UI for the app's assessment controls, GITHUB_COMMENT for a pull request comment, or PROOFLINE for the automatic ALREADY_COVERED decision.
validationstringyesThe decision: CONFIRMED, DISMISSED, FIXED, ACCEPTED_RISK or ALREADY_COVERED.

CustomerReviewDetail#

FieldTypeRequiredDescription
actionsReviewActionsyesWhich review actions the caller may take now.
assessment_countinteger (int64)yesHow many environment assessments this review has.
assessmentsarray of CustomerAssessmentyesThe environment assessments this review recorded.
base_branch_commit_shastring or nullnoThe base branch tip GitHub reported when the review was triggered, display metadata that differs from base_commit_sha when the base branch moved after the branch point.
base_commit_shastring or nullnoThe base revision the review compares against; for a pull request, the merge base of its head and base branch. Null until pinned, and for a first deployment.
base_commit_urlstring or nullnoThe GitHub page for base_commit_sha. Null when that commit or the repository is unknown.
base_refstring or nullnoThe pull request's base branch name as last recorded from GitHub, for orientation only. Null when no pull request state is recorded.
check_run_urlstring or nullnoThe GitHub check run Proofline published for this review. Null when none was published.
compare_urlstring or nullnoThe GitHub comparison of the base and head commits. Null unless both are pinned and the repository is known, and for a patch review, whose head GitHub does not have.
completed_atstring (date-time) or nullnoWhen the review reached a terminal status. Absent while it is still pending or running.
created_atstring (date-time)yesWhen the review was created.
current_head_commit_shastring or nullnoThe pull request's head commit as the latest provider projection reports it, which can differ from head_commit_sha. Set only on a single-review read, and absent for a deployment review or a pull request with no projection.
diff_statsReviewDiffStats or nullnoLine totals from this run's pinned comparison. Null until recorded, or when the provider's changed-file list was incomplete.
environment_display_namesarray of stringyesDisplay names of this review's assessed environments, not current repository links.
finding_countinteger (int64)yesHow many findings this review's assessments recorded, across all of them.
head_commit_shastring or nullnoThe head commit this review is pinned to. For a patch review, the revision ID Proofline derives from its base commit and patch digest, which is not a commit. Absent when the review recorded none.
head_commit_urlstring or nullnoThe exact revision reviewed. A commit URL, never a branch URL: the branch moves, the reviewed input does not. Absent for a patch review.
head_refstring or nullnoThe pull request's head branch name as last recorded from GitHub, for orientation only. Null when no pull request state is recorded.
idstring (uuid)yesThe review's identifier.
kindstringyesPULL_REQUEST, DEPLOYMENT or PATCH, a review of local changes sent as a patch.
merge_gatePullRequestMergeGate or nullnoThe deterministic policy for this exact repository/head, when opted in. Its captured review owner and GitHub bypass remain separate history.
open_itemsOpenItemsView or nullnoWhat Proofline still has open for the reviewed head, counted from the current finding decisions. Absent while the review is PENDING or RUNNING.
open_items_observationReviewOpenItems or nullnoDated PR counts with head, evaluated-scope and bounded thread proof. Absent when that observation is unavailable; scalar counts remain separate.
public_keystringyesThe review's stable public address: rev_ followed by its identifier without hyphens.
publicationstringyesWhether the review reached the pull request: PUBLISHED, WITHHELD, PUBLICATION_REQUESTED or PUBLICATION_REFUSED. A review run from Proofline is withheld until somebody publishes it.
publication_detailstring or nullnoWhy a publication was refused, or how one failed. Server text.
pull_request_author_avatar_urlstring or nullnoProvider-supplied avatar URL. Login-derived .png URLs do not work for GitHub App bot accounts and are not portable across GitHub hosts.
pull_request_author_github_user_idinteger (int64) or nullnoThe author's stable GitHub user id: identity for profile lookups, never display text. Absent when GitHub named no author.
pull_request_author_loginstring or nullnoProvider display metadata for the pull request author, not the rerun requester.
pull_request_author_urlstring or nullnoThe author's profile on the deployment's GitHub host. Absent when no author login is known.
pull_request_numberinteger (int64) or nullnoThe pull request number. Absent for a deployment or patch review.
pull_request_statestring or nullnoCurrent provider state of the pull request: OPEN, CLOSED, or MERGED. Absent for deployment reviews or a missing projection.
pull_request_titlestring or nullnoThe pull request's title as provider state last reported it, so it names the change rather than only numbering it. Untrusted text: renderers must treat it as text, never markup.
pull_request_urlstring or nullnoThe pull request on GitHub. Absent for a deployment review or when the repository is unknown.
related_reviewsarray of RelatedReviewyesEvery other run for this pull request the caller can see, plus reviews joined to this one by supersession or rerun.
repository_full_namestring or nullnoThe repository's owner/name. Absent when the review names no repository.
repository_idstring (uuid) or nullnoThe review's repository. Set only on a single-review read, and absent there when the review names no repository.
repository_namestring or nullnoThe repository's name within its owner. Absent when the review names no repository.
repository_urlstring or nullnoThe repository on GitHub. Absent when the deployment's web base cannot be joined with the stored name.
requested_byActorView or nullnoWho asked for this review, for a review a person requested. Null on automatic reviews and on reviews recorded before requesters were.
review_comment_urlstring or nullnoThe pull request review Proofline submitted for this review. Null when it submitted none.
review_retracted_atstring (date-time) or nullnoWhen a submitted pull request review was marked retracted, a marker only older versions set. Null otherwise.
run_numberinteger (int64) or nullnoOne-based, append-only ordinal within one repository pull request.
statusstringyesThe review's lifecycle status: PENDING, RUNNING, COMPLETED, INCOMPLETE, FAILED, SUPERSEDED, STOPPED or EXCLUDED.
stoppablebooleanyesWhether the stop action applies: the review is PENDING or RUNNING and decides no deployment gate. It says nothing about the caller's permission.
stopped_atstring (date-time) or nullnoWhen the review was stopped. Null unless it was stopped.
stopped_byActorView or nullnoWho stopped this review, for a STOPPED review whose stop recorded its actor. Null otherwise.
stopped_fromstring or nullnoWhere the review was stopped: PROOFLINE or PULL_REQUEST. Null unless the stop recorded it.
subjectsarray of SubjectViewyesWhat this review covers: the revision under review and any companion repositories, workflow runs, artifacts or deployments.
superseded_by_review_idstring (uuid) or nullnoThe newer review that superseded this one. Null when none did or the caller cannot see it.
trigger_originstringyesWho asked for this review: AUTOMATIC, COMMAND, RERUN, MANUAL, or UNKNOWN for a trigger key this build does not recognise.

Dataset#

Type: reviews, finding_outcomes, finding_validations, spend, findings

DomainView#

FieldTypeRequiredDescription
domainstringyesThe risk domain this evaluation covers.
reasonstringyesWhy the domain was considered or skipped, as recorded with the evaluation.
statusstringyesCONSIDERED or SKIPPED.

EvidenceView#

Type: REQUIRED_PROPERTIES_ESTABLISHED, INCOMPLETE, NO_APPLICABLE_OBLIGATIONS

ExportEvidenceKind#

Type: repository_file, repository_file_at_commit, companion_repository_file, commit, workflow_run, world_entity, deterministic_test, recorded_read, text

ExportEvidenceRef#

FieldTypeRequiredDescription
idstringyesStable opaque occurrence-local identity, independent of evidence values.
kindExportEvidenceKindyesThe recorded reference kind, or text for a kind this export does not recognize.

ExportFindingLifecycle#

Type: NEW, UNCHANGED, RESOLVED, REINTRODUCED

ExportFindingSeverity#

Type: WARNING, SERIOUS

ExportReviewKind#

Type: PULL_REQUEST, DEPLOYMENT, PATCH

ExportReviewStatus#

Type: PENDING, RUNNING, COMPLETED, INCOMPLETE, FAILED, SUPERSEDED, STOPPED, EXCLUDED

ExportRow#

The closed row vocabulary of the existing raw-stream export operation.

Type: ReviewsExportRow or FindingOutcomesExportRow or FindingValidationsExportRow or SpendExportRow or FindingsExportRow

ExportValidation#

Type: UNKNOWN, CONFIRMED, DISMISSED, FIXED, ACCEPTED_RISK, ALREADY_COVERED

ExportValidationSource#

Type: ui, github_comment, proofline

FileProjection#

FieldTypeRequiredDescription
depthstringyesThe code-inspection depth retained by the plan.
passesarray of stringyesThe review passes bound to this file.
pathstringyesRepository-relative path retained by the routing plan.

FilterChoice#

FieldTypeRequiredDescription
idstring (uuid)yesThe repository or environment ID to pass as the filter value.
namestringyesThe repository's full name or the environment's display name.

FindingCausalEdgeView#

FieldTypeRequiredDescription
fromstringyesThe id of the node the edge starts at.
labelstring or nullnoWhat the relation is. Model-authored text, and absent when the reviewer gave none.
tostringyesThe id of the node the edge ends at.

FindingCausalGraphView#

FieldTypeRequiredDescription
edgesarray of FindingCausalEdgeViewyesDirected relations between nodes. An edge can name a node identifier that no node carries.
nodesarray of FindingCausalNodeViewyesThe actors in the finding, as the reviewer named them.

FindingCausalNodeView#

FieldTypeRequiredDescription
idstringyesThe reviewer-assigned node identifier that edges refer to. Model-authored text.
labelstringyesWhat the node is. Model-authored text: render as text.
rolestringyesOne of change, dependency, failure, blocked or ok, or empty; a value outside that set is returned as recorded.

FindingEvidenceClass#

Type: ANALYZER_BACKED, CODE_ONLY or string or string

FindingOutcomesCount#

FieldTypeRequiredDescription
countinteger (int64)yesPublished finding series in the group whose series disposition is RESOLVED_BY_PUSH.
drilldownFindingOutcomesDrilldownyesThe query that lists the series behind count.

FindingOutcomesDrilldown#

FieldTypeRequiredDescription
group_keystringyesThe group_key query value that limits the listed series to this count's group.
outcomeFindingOutcomesOutcome or nullnoThe outcome query value for an outcome selector, and null for every other selector.
post_mergeFindingOutcomesPostMergeOutcome or nullnoThe post_merge query value for a post_merge selector, and null for every other selector.
selectorFindingOutcomesSelectoryesThe selector query value that lists the series behind this count.

FindingOutcomesExportRow#

Exact shared aggregate counts for one admitted group and requested window.

FieldTypeRequiredDescription
code_changedFindingOutcomesCountyesPublished series whose series disposition is RESOLVED_BY_PUSH.
dataset_versioninteger (uint16)yesThe row contract version, always 1.
external_validation_denominatorinteger (int64)yesHuman-validated series; excludes automatic coverage and unrecorded outcomes.
fromstring (date-time)yesThe inclusive start of the requested first-publication window.
group_byFindingOutcomesGroupByyesThe dimension that defines this row's group.
keystringyesThe grouping value: a repository or environment ID, a risk domain, a severity or a review kind, as group_by selects.
limitationsarray of stringyesGaps in publication history that keep findings outside these counts; they mean missing history, not zero findings.
namestringyesThe group's display name: the repository's full name (or Repository and its ID when no name is recorded), the environment's display name, or otherwise key.
organization_idstring (uuid)yesThe organization whose findings are counted.
outcomesarray of FindingOutcomesOutcomeCountyesOne count per outcome, always all six FindingOutcomesOutcome values in a fixed order.
post_mergeFindingOutcomesPostMergeCountsyesPublished series counted by their latest post-merge comment-address evaluation.
publishedinteger (int64)yesFinding series in the group whose first publication falls inside the window.
tostring (date-time)yesThe exclusive end of the requested first-publication window.

FindingOutcomesGroupBy#

Type: repository, environment, risk_domain, severity, subject_kind

FindingOutcomesOutcome#

Type: FIXED, CONFIRMED, ACCEPTED_RISK, DISMISSED, ALREADY_COVERED, NO_RECORDED_OUTCOME

FindingOutcomesOutcomeCount#

FieldTypeRequiredDescription
countinteger (int64)yesPublished finding series in the group whose latest qualifying outcome is outcome.
drilldownFindingOutcomesDrilldownyesThe query that lists the series behind count.
outcomeFindingOutcomesOutcomeyesThe outcome counted, where NO_RECORDED_OUTCOME means the series has no qualifying validation.
validation_sourcesFindingOutcomesValidationSourcesyescount split by where the outcome was recorded; a NO_RECORDED_OUTCOME count has no source.

FindingOutcomesPostMergeCount#

FieldTypeRequiredDescription
countinteger (int64)yesPublished finding series in the group whose latest evaluation recorded outcome.
drilldownFindingOutcomesDrilldownyesThe query that lists the series behind count.
outcomeFindingOutcomesPostMergeOutcomeyesThe outcome of the series' latest comment-address evaluation.

FindingOutcomesPostMergeCounts#

FieldTypeRequiredDescription
judgedinteger (int64)yesSeries with a retained evaluation, rather than all published series.
outcomesarray of FindingOutcomesPostMergeCountyesOne count per post-merge outcome, always ADDRESSED, NOT_ADDRESSED and INCOMPLETE in that order.

FindingOutcomesPostMergeOutcome#

Type: ADDRESSED, NOT_ADDRESSED, INCOMPLETE

FindingOutcomesSelector#

Type: outcome, code_changed, post_merge

FindingOutcomesValidationSources#

FieldTypeRequiredDescription
consoleinteger (int64)yesSeries whose outcome comes from a validation recorded in the console.
github_replyinteger (int64)yesSeries whose outcome comes from a validation recorded by a GitHub comment reply.
prooflineinteger (int64)yesSeries whose outcome is ALREADY_COVERED, recorded by Proofline itself.

FindingSupport#

FieldTypeRequiredDescription
evidence_refsarray of CustomerEvidenceRefyesThe references the hypothesis cites for its verdict.
explanationUntrustedText or nullnoWhy the hypothesis reached its verdict, as recorded at resolution. Null when no explanation is recorded.

FindingValidationsExportRow#

One append-only validation, including its recorded actor display metadata. Missing historical actors stay absent; the export does not infer identity.

FieldTypeRequiredDescription
actor_github_user_idinteger (int64) or nullnoThe GitHub user ID captured as the actor, null when none was captured.
actor_loginstring or nullnoThe GitHub login captured as display metadata at validation time, null when none was captured.
actor_user_idstring (uuid) or nullnoThe Proofline user captured as the actor, null when none was captured.
created_atstring (date-time)yesWhen the validation was recorded; the export window filters on this time.
dataset_versioninteger (uint16)yesThe row contract version, always 1.
environment_idstring (uuid)yesThe environment of the assessment that recorded the finding.
expires_atstring (date-time) or nullnoWhen the decision expires, null when it records no expiry.
finding_idstring (uuid)yesThe finding occurrence the validation applies to.
organization_idstring (uuid)yesThe organization that owns the finding.
repository_idstring (uuid) or nullnoThe review's primary repository, null when the review records none.
review_idstring (uuid)yesThe review whose assessment recorded the finding.
sourceExportValidationSourceyesWhere the decision was recorded: ui or github_comment for a person, proofline for automatic coverage.
validationExportValidationyesThe recorded decision, including legacy UNKNOWN values.
validation_idstring (uuid)yesThe stable ID of this validation record.

FindingsExportRow#

One immutable finding occurrence. Reference payloads and evidence values stay private.

FieldTypeRequiredDescription
assessment_idstring (uuid)yesThe environment assessment that recorded the finding.
claimstringyesThe finding's claim, with supported credential shapes masked as <REDACTED:kind>.
created_atstring (date-time)yesWhen the finding was recorded; the export window filters on this time.
dataset_versioninteger (uint16)yesThe row contract version, always 1.
environment_idstring (uuid)yesThe environment the assessment covers.
evidence_refsarray of ExportEvidenceRefyesThe finding's evidence references in recorded order, each reduced to a kind and an opaque ID; an empty list means the finding records none.
finding_idstring (uuid)yesThe stable ID of this finding occurrence.
impactstringyesThe finding's stated impact, with supported credential shapes masked.
lifecycle_stateExportFindingLifecycleyesThe occurrence's recorded lifecycle state relative to earlier occurrences.
organization_idstring (uuid)yesThe organization that owns the finding.
remediationstring or nullnoThe suggested remediation with credential shapes masked, null when none is recorded.
repository_idstring (uuid) or nullnoThe review's primary repository, null when the review records none.
review_idstring (uuid)yesThe review whose assessment recorded the finding.
risk_domainstringyesThe risk domain the finding is recorded under.
series_idstring (uuid) or nullnoThe finding series this occurrence belongs to, null when it belongs to none.
severityExportFindingSeverityyesThe finding's recorded severity.

GateState#

FieldTypeRequiredDescription
override_recordOverride or nullnoRecorded override authorization, not confirmation of provider delivery.
statusstringyesLocal gate state. ALLOWED/BLOCKED can precede provider delivery. This field does not confirm that GitHub released or blocked a run.

GateStatus#

Type: REQUESTED, EVALUATING, ALLOWED, BLOCKED, BYPASSED, SUPERSEDED

NotAssessedView#

FieldTypeRequiredDescription
environment_display_namestringyesThe display name of the environment whose assessment is not COMPLETED.
incompleteness_kindstring or nullnoThe assessment's recorded gap class. Absent is an unclassified gap, never a complete assessment.

OpenFindingCounts#

FieldTypeRequiredDescription
seriousinteger (uint64)yesFinding series with SERIOUS severity that are unresolved and not under an unexpired dismissal or risk acceptance.
warninginteger (uint64)yesFinding series with WARNING severity that are unresolved and not under an unexpired dismissal or risk acceptance.

OpenItemEnvironment#

FieldTypeRequiredDescription
display_namestringyesThe environment's display name.
environment_idstring (uuid)yesThe environment whose assessment is not complete.
reasonOpenItemsGapReasonyesWhy the assessment is not complete, derived from its status and recorded gap class; UNKNOWN when neither names a cause.
statusOpenItemsReviewStatusyesThe assessment's recorded status.

OpenItemsGapReason#

Type: NOT_STARTED, IN_PROGRESS, NOT_CONFIGURED, POLICY_EXCLUDED, EVIDENCE_UNAVAILABLE, HYPOTHESES_UNRESOLVED, MODEL_BUDGET_EXHAUSTED, FAILED, STOPPED, UNKNOWN

OpenItemsHeadState#

Type: CURRENT, OUTDATED, UNKNOWN

OpenItemsReviewStatus#

Type: PENDING, RUNNING, COMPLETED, INCOMPLETE, FAILED, SUPERSEDED, STOPPED, EXCLUDED, UNKNOWN

OpenItemsThreadUnknown#

Type: GITHUB_UNAVAILABLE, READ_LIMIT_EXCEEDED, TRUNCATED, RECORDED_THREAD_MISSING, REPOSITORY_UNAVAILABLE

OpenItemsThreads#

Type: object or object

OpenItemsView#

Recorded unresolved findings, accepted risks and assessment gaps. Coverage and notification suppression do not resolve a finding. These scalar counts make no claim about current heads, evaluated scope or threads.

FieldTypeRequiredDescription
accepted_risksinteger (uint)yesFinding series whose current decision is an unexpired ACCEPTED_RISK.
not_assessedarray of NotAssessedViewyesRecorded assessment gaps, including explicit policy exclusions.
open_findingsinteger (uint)yesUnresolved recorded finding series, including notification-suppressed findings, decisions whose dismissal or risk acceptance expired, and earlier published series of the pull request that this review did not find again.
serious_findingsinteger (uint)yesThe SERIOUS findings among open_findings.

Outcome#

Type: ALLOW, BLOCK

Override#

FieldTypeRequiredDescription
commentstring or nullnoThe comment recorded with the approval, truncated past 8000 characters.
github_environment_idinteger (int64)yesThe GitHub environment ID the approval applied to.
github_user_idinteger (int64)yesThe GitHub user ID of the person whose GitHub deployment approval overrode the gate.
github_user_loginstringyesThat person's GitHub login as recorded with the approval, a display label truncated past 128 characters.

PassProjection#

FieldTypeRequiredDescription
model_bindingstringyesSymbolic configuration binding, not a historical model identity.
namestringyesPass name from the closed routing schema.

PatchReviewRequest#

Local changes to review: a unified diff against a commit GitHub has.

FieldTypeRequiredDescription
base_commit_shastringyesThe full 40-character commit the patch applies to. GitHub must have it in this repository.
patchstringyesThe changes as git diff --no-ext-diff --no-color <base> prints them, at most 5 MiB and 3000 files. Text changes only: binary changes, symbolic links and submodules are refused.

PatchReviewResponse#

What a patch review request produced.

FieldTypeRequiredDescription
existingbooleanyesTrue when this patch on this base already had a review and that one is returned. Sending the same patch twice reviews it once.
patch_digeststringyesSHA-256 of the canonical patch, the identity the review pins with the repository and base commit.
review_idstring (uuid)yesThe review of this patch on this base, readable through the review and findings routes.

PermissionView#

Type: PERMIT, BLOCK

PlanProjection#

FieldTypeRequiredDescription
assessmentsarray of AssessmentProjectionyesEnvironment assessment bindings recorded in the plan.
base_shastringyesBase commit pinned by the change digest.
change_digest_sha256stringyesDigest of the exact retained change input.
fallback_causesarray of stringyesSafe codes for fallback causes. Unrecognized values are never echoed.
filesarray of FileProjectionyesFile routing facts recorded in the plan.
head_shastringyesHead commit pinned by the change digest.
repository_idstring (uuid)yesRepository named by the validated immutable plan.

Problem#

RFC 9457 problem-details body. type is omitted and therefore about:blank: the title/detail pair carries the meaning.

FieldTypeRequiredDescription
detailstring or nullnoA caller-safe explanation of this occurrence, absent when the cause is an internal error that is logged rather than returned.
statusinteger (uint16)yesThe HTTP status code of the response that carries this body.
titlestringyesA short, stable summary of the problem class, such as not found or conflict.

PullRequestMergeGate#

FieldTypeRequiredDescription
assessment_countinteger (int32) or nullnoThe number of environment assessments counted by the recorded decision. Null before a decision.
blocking_severitystringyesThe frozen blocking threshold, either SERIOUS or WARNING; later settings do not restamp it.
bypassed_atstring (date-time) or nullnoWhen the bypass receipt was recorded. Null when this gate has no recorded bypass.
coverage_digeststring or nullnoThe digest of the deterministic coverage used by the decision, or null when no digest was recorded.
decided_atstring (date-time) or nullnoWhen the immutable decision was recorded. Null before a decision.
decisionOutcome or nullnoThe immutable ALLOW or BLOCK decision. Null until a decision is recorded.
finding_countinteger (int32) or nullnoThe number of blocking findings counted by the recorded decision. Null before a decision.
head_shastringyesThe exact lowercase commit SHA whose captured policy this gate evaluates.
idstring (uuid)yesThe immutable identity of the gate captured for this tenant, repository and head.
merge_commit_shastring or nullnoThe exact merge commit reported by GitHub for the bypass, or null when none was reported.
merged_by_github_user_idinteger (int64) or nullnoThe stable GitHub user ID reported by a merged-close bypass, or null when none was reported.
merged_pull_request_numberinteger (int64) or nullnoThe actual pull request merged in the recorded bypass, which may differ from the captured PR.
policy_versionstringyesThe deterministic policy version frozen when this gate was captured.
pull_request_numberinteger (int64)yesThe first pull request that captured this head's gate; a shared-head merge may name another PR.
reason_codestring or nullnoThe recorded deterministic decision or refusal reason. Null until a decision is recorded.
review_idstring (uuid) or nullnoThe first review captured for this gate. Null when its trigger was refused before a review existed.
statusGateStatusyesThe current gate projection, including a recorded bypass or supersession by a newer head.

RefusedEnvironment#

An environment a refusal names. external_key is how its pages are addressed.

FieldTypeRequiredDescription
display_namestringyesThe environment's display name. Tenant free text: render as text.
external_keystringyesThe environment's stable machine key, unique within the organization.
idstring (uuid)yesThe environment's identifier.
statusstringyesThe environment's lifecycle status, such as READY.

RelatedReview#

FieldTypeRequiredDescription
created_atstring (date-time)yesWhen the related review was created.
head_commit_shastring or nullnoThe head commit the related review is pinned to. Absent when it recorded none.
public_keystringyesThe related review's stable public address.
relationstringyesA direct lineage relation, or EARLIER_RUN / LATER_RUN when the two reviews share a pull request without a direct lineage edge.
review_idstring (uuid)yesThe related review's identifier.
run_numberinteger (int64) or nullnoThe related review's one-based ordinal within its pull request. Absent for a review that is not of a pull request.
statusstringyesThe related review's lifecycle status.

RepositoryGuidance#

FieldTypeRequiredDescription
additional_promptstring or nullnoThe repository-specific reviewer guidance new reviews snapshot, null when none is set.
repository_idstring (uuid)yesThe repository's stable Proofline ID.

RepositoryName#

FieldTypeRequiredDescription
full_namestringyesThe provider's owner/name. Display metadata: it can change on a rename, so callers keep id.
idstring (uuid)yesThe repository's stable Proofline ID.

RepositoryNames#

FieldTypeRequiredDescription
repositoriesarray of RepositoryNameyesThe organization's repositories that are not deleted, ordered by name; a repository-restricted token sees only its allowlist.

RerunResponse#

Manual rerun: a new review of the same immutable subjects, under a fresh trigger key so history accumulates instead of overwriting.

FieldTypeRequiredDescription
public_keystringyesThe new review's stable public address.
pull_request_numberinteger (int64) or nullnoThe pull request number. Absent for a deployment review.
repository_namestring or nullnoThe repository's name within its owner. Absent when the original review names no repository.
review_idstring (uuid)yesThe new review's identifier.
run_numberinteger (int64) or nullnoThe new review's one-based ordinal within its pull request. Absent for a deployment review.

ReviewActions#

FieldTypeRequiredDescription
publishbooleanyesWhether the caller may publish this pull request review's withheld results, which requires a browser session and repository write access.
rerunbooleanyesWhether the caller may rerun this review.
stopbooleanyesWhether the caller may stop this review from a browser session.
unavailable_reasonActionUnavailability or nullnoWhy an action is unavailable, when a permission or repository check denied it. Null when no check denied one, which does not mean every action is allowed.
validate_findingsbooleanyesWhether the caller may record decisions on findings from a browser session.

ReviewDiffStats#

FieldTypeRequiredDescription
additionsinteger (int64)yesLines added across every changed file in the pinned comparison.
deletionsinteger (int64)yesLines deleted across every changed file in the pinned comparison.

ReviewFilters#

FieldTypeRequiredDescription
authorsarray of AuthorChoiceyesAuthors of visible pull request reviews, one per GitHub user.
environmentsarray of FilterChoiceyesEnvironments assessed by at least one visible review, ordered by display name.
repositoriesarray of FilterChoiceyesRepositories that have at least one visible review, ordered by full name.

ReviewOpenItems#

FieldTypeRequiredDescription
accepted_risk_countinteger (uint64)yesFinding series whose current decision is an unexpired ACCEPTED_RISK.
current_head_provider_updated_atstring (date-time) or nullnoGitHub's update time for the recorded pull request state that current_head_sha comes from. Null when none is recorded.
current_head_shastring or nullnoThe pull request's head commit as Proofline last recorded it from GitHub. Null when no pull request state is recorded.
environmentsarray of OpenItemEnvironmentyesThis review's environment assessments that are not COMPLETED, ordered by environment key.
evaluated_scope_knownbooleanyesWhether the review recorded at least one environment assessment. False means the evaluated scope is unknown, so an empty environments proves nothing.
head_stateOpenItemsHeadStateyesWhether reviewed_head_sha matches current_head_sha; UNKNOWN when either is missing.
is_latest_reviewbooleanyesWhether this review is the newest review of its pull request the caller can see.
latest_review_head_shastring or nullnoThe head commit of the newest review of this pull request the caller can see. Null when that review recorded none.
latest_review_head_stateOpenItemsHeadStateyesWhether latest_review_head_sha matches current_head_sha; UNKNOWN when either is missing.
observed_atstring (date-time)yesWhen the database facts in this observation were read, all from one statement.
open_findingsOpenFindingCountsyesUnresolved finding series that still demand attention, by severity: this review's own, and earlier published series of the pull request that this review did not find again.
review_statusOpenItemsReviewStatusyesThis review's recorded status; UNKNOWN for a status this build does not recognize.
reviewed_head_shastring or nullnoThe head commit this review evaluated. Null when the review recorded none.
threadsOpenItemsThreadsyesThe count of unresolved Proofline review threads on GitHub, or why that count is unknown.

ReviewPage#

FieldTypeRequiredDescription
filtersReviewFiltersyesThe values the review list can be filtered by, drawn from reviews the caller can see and independent of the current filters.
itemsarray of ReviewSummaryyesThe reviews on this page, newest first.
next_cursorstring or nullnoThe cursor that requests the next page. Null when truncated is false.
truncatedbooleanyesWhether more reviews match the query beyond this page.

ReviewRoutingView#

Type: object or object or object

ReviewSummary#

FieldTypeRequiredDescription
assessment_countinteger (int64)yesHow many environment assessments this review has.
completed_atstring (date-time) or nullnoWhen the review reached a terminal status. Absent while it is still pending or running.
created_atstring (date-time)yesWhen the review was created.
current_head_commit_shastring or nullnoThe pull request's head commit as the latest provider projection reports it, which can differ from head_commit_sha. Set only on a single-review read, and absent for a deployment review or a pull request with no projection.
environment_display_namesarray of stringyesDisplay names of this review's assessed environments, not current repository links.
finding_countinteger (int64)yesHow many findings this review's assessments recorded, across all of them.
head_commit_shastring or nullnoThe head commit this review is pinned to. For a patch review, the revision ID Proofline derives from its base commit and patch digest, which is not a commit. Absent when the review recorded none.
head_commit_urlstring or nullnoThe exact revision reviewed. A commit URL, never a branch URL: the branch moves, the reviewed input does not. Absent for a patch review.
idstring (uuid)yesThe review's identifier.
kindstringyesPULL_REQUEST, DEPLOYMENT or PATCH, a review of local changes sent as a patch.
public_keystringyesThe review's stable public address: rev_ followed by its identifier without hyphens.
publicationstringyesWhether the review reached the pull request: PUBLISHED, WITHHELD, PUBLICATION_REQUESTED or PUBLICATION_REFUSED. A review run from Proofline is withheld until somebody publishes it.
publication_detailstring or nullnoWhy a publication was refused, or how one failed. Server text.
pull_request_author_avatar_urlstring or nullnoProvider-supplied avatar URL. Login-derived .png URLs do not work for GitHub App bot accounts and are not portable across GitHub hosts.
pull_request_author_github_user_idinteger (int64) or nullnoThe author's stable GitHub user id: identity for profile lookups, never display text. Absent when GitHub named no author.
pull_request_author_loginstring or nullnoProvider display metadata for the pull request author, not the rerun requester.
pull_request_author_urlstring or nullnoThe author's profile on the deployment's GitHub host. Absent when no author login is known.
pull_request_numberinteger (int64) or nullnoThe pull request number. Absent for a deployment or patch review.
pull_request_statestring or nullnoCurrent provider state of the pull request: OPEN, CLOSED, or MERGED. Absent for deployment reviews or a missing projection.
pull_request_titlestring or nullnoThe pull request's title as provider state last reported it, so it names the change rather than only numbering it. Untrusted text: renderers must treat it as text, never markup.
pull_request_urlstring or nullnoThe pull request on GitHub. Absent for a deployment review or when the repository is unknown.
repository_full_namestring or nullnoThe repository's owner/name. Absent when the review names no repository.
repository_idstring (uuid) or nullnoThe review's repository. Set only on a single-review read, and absent there when the review names no repository.
repository_namestring or nullnoThe repository's name within its owner. Absent when the review names no repository.
repository_urlstring or nullnoThe repository on GitHub. Absent when the deployment's web base cannot be joined with the stored name.
run_numberinteger (int64) or nullnoOne-based, append-only ordinal within one repository pull request.
statusstringyesThe review's lifecycle status: PENDING, RUNNING, COMPLETED, INCOMPLETE, FAILED, SUPERSEDED, STOPPED or EXCLUDED.
trigger_originstringyesWho asked for this review: AUTOMATIC, COMMAND, RERUN, MANUAL, or UNKNOWN for a trigger key this build does not recognise.

ReviewedTreeCitationView#

One member of a review's declared tree that World cited.

FieldTypeRequiredDescription
content_sha256string or nullnoThe member's content hash. Absent for a member a REJECTED population refused, because such a population keeps no members.
overlay_digeststringyesThe overlay World read the member from.
pathUntrustedTextyesThe member's path in the repository at that revision. Repository text, so it can hold bidirectional controls that reorder what the reader sees.
population_kindstringyesThe population the member belongs to, such as WORKFLOW_DEFINITIONS.
rolestringyesPROPOSED_CODE_REVISION (the reviewed commit) or BASE_CODE_REVISION (its merge base).

ReviewsExportRow#

The NDJSON row and CSV column contract. Repository names are display data; the stable repository ID and recorded commit identify the reviewed input.

FieldTypeRequiredDescription
base_commit_shastring or nullnoThe pinned base commit SHA, null when the review records none.
completed_atstring (date-time) or nullnoWhen the review finished, null while it has not.
created_atstring (date-time)yesWhen the review was created; the export window filters on this time.
dataset_versioninteger (uint16)yesThe row contract version, always 1.
github_repository_idinteger (int64) or nullnoGitHub's ID for the repository, null when the organization no longer owns it or the review records no repository.
head_commit_shastring or nullnoThe pinned head commit SHA, null when the review records none.
kindExportReviewKindyesWhether the review analyzes a pull request, a deployment or a local patch.
organization_idstring (uuid)yesThe organization that owns the review.
pull_request_numberinteger (int64) or nullnoThe pull request number, null when the review records none, as for a deployment.
repository_full_namestring or nullnoThe repository's current owner/name display name, null when the organization no longer owns it or the review records no repository.
repository_idstring (uuid) or nullnoThe stable ID of the review's primary repository, null when the review records none.
review_idstring (uuid)yesThe review's stable ID.
run_numberinteger (int64) or nullnoThe review's ordinal among the reviews of its pull request, null for a review without a repository and pull request.
statusExportReviewStatusyesThe review's recorded status.
trigger_originstringyesWhat started the review, derived from its trigger key: AUTOMATIC, COMMAND, RERUN, MANUAL, or UNKNOWN for a key this build does not recognize.

ReviewsMetadataStream#

UTF-8 metadata file. NDJSON contains one ExportRow per line; CSV contains that dataset's named columns and a header. This response is neither a JSON object nor a JSON array.

Type: string

RoutingFindingView#

FieldTypeRequiredDescription
fallback_causestring or nullnoRecognized safe fallback cause, when present.
finding_idstring (uuid)yesFinding whose retained placement is reported.
floor_reasonstring or nullnoRecognized safe floor reason, when present.
placementstringyesPublication channel recorded for this finding.
reason_codesarray of stringyesRecognized safe reason codes; unknown values are represented as UNRECOGNIZED.
rulestringyesRule that produced the recorded placement.

RunNowMode#

Whether an explicit request may reuse a settled review of the live head.

Type: EXISTING_OR_NEW, FULL

RunNowRefusalView#

Why a run-now request created nothing, each reason with what the page needs to link the setting to change.

Type: object or object or object or object or object or object or object or object or object or object

RunNowRefused#

A run-now request that created nothing, as the 400 it is answered with. The refusal is a configuration fact, not a failure, and it is still sent as an RFC 9457 problem: title, status and detail are what a client that knows only problems shows, and repository_name and refusal are the extension members a client that knows refusals links from. During a rollout a page loaded from the previous bundle keeps working against this server, because a refusal was a 400 with a detail before too.

FieldTypeRequiredDescription
detailstringyesOne sentence naming the condition and the setting to change, for a reader with no link to follow.
refusalRunNowRefusalViewyesWhy nothing was created, with what the page needs to link the setting to change.
repository_namestringyesThe repository's name within its owner, as its pages are addressed.
statusinteger (uint16)yesAlways 400.
titlestringyesAlways invalid request.

RunNowRequest#

An empty body keeps the run-now behavior existing clients request.

FieldTypeRequiredDescription
modeRunNowModenoEXISTING_OR_NEW, the default, returns any review that already owns the live head; FULL returns only a pending or running review of that head and otherwise starts a new one.

RunNowResponse#

What a run-now request produced: a review of the live head, created by this request or found already owning the head.

FieldTypeRequiredDescription
automatic_reviews_pausedbooleanyesTrue when automatic reviews are stopped on this pull request. The review ran anyway; the flag is why the page can say so.
existingbooleanyesTrue when this head already carried a review and that one is returned. Clicking twice does not run twice.
review_idstring (uuid)yesThe review that owns the live head, new or existing.
run_numberinteger (int64)yesThe review's one-based ordinal within its pull request, which completes the run's console address.

SpendAccountKind#

Type: DEPLOYMENT, TENANT_CREDENTIAL, UNATTRIBUTED

SpendExportRow#

UTC daily debit totals using only the account and transport recorded at charge time.

FieldTypeRequiredDescription
accountstring or nullnoRecorded attribution, not a current credential label or inferred account.
account_kindSpendAccountKindyesThe account kind recorded at charge time, UNATTRIBUTED when the debit records none.
dataset_versioninteger (uint16)yesThe row contract version, always 1.
daystring (date-time)yesUTC midnight. The requested window can cover only part of this day.
debitsinteger (int64)yesThe number of debits summed into this row.
microcreditsinteger (int64)yesExact integer charge units; one credit contains one million microcredits.
organization_idstring (uuid)yesThe organization charged.
transportstring or nullnoThe model transport recorded at charge time, null when the debit records none.

SubjectAuthorization#

One assessment's authorization of one subject, by identity. The display name is not the answer on its own: an environment's external key is unique within its organization and a display name is mutable metadata, so two environments of one review can carry the same one. Collapsing to it would leave a reader unable to tell which assessment authorized the subject and which one gapped, which is the confusion this field exists to remove.

FieldTypeRequiredDescription
assessment_idstring (uuid)yesThe assessment this authorization belongs to, as AssessmentView.id names it. A reader joins on this, never on the display name.
environment_display_namestringyesWhat a reader recognizes the environment by. Display metadata, and tenant free text: a consumer contains it before rendering.
environment_external_keystringyesThe environment's stable machine key, unique within the organization.
environment_idstring (uuid)yesThe environment the authorizing assessment belongs to.

SubjectView#

FieldTypeRequiredDescription
artifact_digeststring or nullnoAn immutable OCI digest, never a mutable tag.
commit_shastring or nullnoThe pinned commit of a GIT_REVISION subject, or the base commit a GIT_PATCH subject applies to. Absent for other kinds.
deployment_external_idstring or nullnoThe GitHub deployment identifier a GITHUB_WORKFLOW_RUN subject ran for. Absent when the run was not for a deployment.
idstring (uuid)yesThe subject's stable identifier. It holds across a poll refresh even when a concurrently populated subject shifts this response's (kind, id) order: a client keying its own local UI state (an open disclosure, a focused control) by array index would otherwise lose that state to a reorder that changed nothing it owns.
kindstringyesGIT_REVISION, GIT_PATCH, GITHUB_WORKFLOW_RUN, ARTIFACT or DEPLOYMENT.
patch_digeststring or nullnoThe SHA-256 of a GIT_PATCH subject's canonical patch. Absent for other kinds.
release_authorizationsarray of SubjectAuthorizationyesThe assessments whose own verified release set authorized this subject. A review with several environments accumulates one subject list, but authorization is per assessment: an artifact one environment's read authenticated is not evidence for a neighbour whose own read gapped or refused. Naming the assessments keeps the union from reading as a shared fact. Empty for a subject no release-set read produced (the reviewed revision, the workflow run, a deployment), because those are the review's own coordinates rather than one environment's authenticated evidence, not because every environment refused them.
repository_full_namestring or nullnoAbsent only when the subject's repository record itself is gone.
repository_idstring (uuid) or nullnoThe immutable repository identity of this subject, including companions.
rolestringyesPRIMARY for the revision under review; COMPANION for context read from another authenticated repository.
urlstring or nullnoThe subject on GitHub: the commit for a revision, the run for a workflow run. Absent for kinds GitHub does not address (GIT_PATCH, ARTIFACT, DEPLOYMENT) or when the subject's repository is unknown.
workflow_attemptinteger (int32) or nullnoThe attempt number of a GITHUB_WORKFLOW_RUN subject. Absent for other kinds.
workflow_run_idinteger (int64) or nullnoThe GitHub Actions run of a GITHUB_WORKFLOW_RUN subject. Absent for other kinds.

ThreadObservationFreshness#

Type: FRESH, STALE

ThreadObservationView#

A read of GitHub's thread state. observed_at is when Proofline read it.

FieldTypeRequiredDescription
freshnessThreadObservationFreshnessyesSTALE when the pull request is open and this observation is more than 24 hours old, otherwise FRESH.
github_comment_urlstring or nullnoThe finding's root comment on GitHub. Absent when the repository is unknown.
observed_atstring (date-time)yesWhen Proofline read the thread state from GitHub.
provider_stateThreadProviderState or nullnoAbsent only when the provider read failed before GitHub returned state.
reply_evidenceThreadReplyEvidenceyesRECORDED when a human reply in the thread was recorded, NONE_CONFIRMED when the complete thread held none, and INCOMPLETE when the thread could not be read in full.
resolver_github_user_idinteger (int64) or nullnoThe stable GitHub identity of whoever resolved the thread. Absent when GitHub named no resolver.
resolver_loginstring or nullnoThe login of whoever resolved the thread, as GitHub reported it. Provider text, and absent when GitHub named no resolver.

ThreadProviderState#

Type: OPEN, RESOLVED

ThreadReplyEvidence#

Type: RECORDED, NONE_CONFIRMED, INCOMPLETE

UnresolvedReason#

World's reason an executed check did not settle. A gate weighs the three alike, and each asks the reader for a different response.

Type: string or string or string

UntrustedText#

Text that came out of the reviewer model, or out of a repository the model read. It is data, never markup, never a URL, never an instruction. The wrapper exists so the untrustedness cannot be lost on the way to a renderer: there is no field on a turn that carries this text under a name a client could mistake for something safe, and unwrapping it is a deliberate act in the client's own code.

FieldTypeRequiredDescription
untrusted_textstringyesThe text itself. Render it as plain text only.