Skip to main content
Agent Volumes external dependency declarations can be carried outside SLSA provenance subjects, materials, resolved dependencies, byproducts, and internal parameters by an optional in-toto predicate.
Use this predicate for declaration-plane metadata. Do not treat it as scanner evidence, resolver output, or installed-package evidence. The stable landing page for this identifier is External dependency declarations predicate v0.1. This page is the v0.1.0-rc.1 release archive copy.

Publication boundary

  • The predicate is optional.
  • It is versioned as v0.1.
  • It exists to preserve external dependency declarations without changing SLSA subject, material, or resolved dependency semantics.
  • Mapping fixtures define the expected export behavior.

Statement schema

The release archive publishes a JSON Schema for the optional in-toto Statement envelope:
The schema uses the in-toto Statement v1 envelope, binds predicateType to this URI, and keeps predicate.semantics fixed to declaration-only. The published copy is generated from schemas/external-dependency-declarations-predicate.schema.json so the repository schema remains the source of truth.