Skip to content
ocx
install

AttestationOutcome

AttestationOutcomeclassdataclass#

Re-exported from ocx_sdk._resultsView source
class AttestationOutcome(status: str, referrer_digest: str | None = None, sidecar_digest: str | None = None, predicate_type: str | None = None, signed: bool | None = None, kind: str | None = None, message: str | None = None)

The attestation outcome of one push(..., sign=True) call (C-019).

push.rs:161, internally tagged on status. A bare str (the usual D8 treatment for a scalar enum) would silently drop predicate_type and signed, so this carries every field instead, all but status optional: succeeded populates predicate_type/signed and at least one of referrer_digest/sidecar_digest; failed populates kind/message.

Attributes

NameTypeDescription
statusstr"succeeded" or "failed".
referrer_digeststr | NoneThe attestation’s referrer-API digest, on success.
sidecar_digeststr | NoneThe attestation’s sidecar-tag digest, on success. --signature-format both populates both digest fields.
predicate_typestr | NoneThe resolved predicate type URI, on success.
signedbool | NoneWhether the attestation was itself signed, on success.
kindstr | NoneThe machine-branchable failure slug, on failure.
messagestr | NoneSanitized prose describing the failure, on failure.

kindattributeclass attributeinstance attribute#

kind: str | None = None

messageattributeclass attributeinstance attribute#

message: str | None = None

predicate_typeattributeclass attributeinstance attribute#

predicate_type: str | None = None

referrer_digestattributeclass attributeinstance attribute#

referrer_digest: str | None = None

sidecar_digestattributeclass attributeinstance attribute#

sidecar_digest: str | None = None

signedattributeclass attributeinstance attribute#

signed: bool | None = None

statusattributeinstance attribute#

status: str

from_dictmethodclassmethod#

def from_dict(data: Mapping[str, Any]) -> AttestationOutcome

Build from the decoded PushResult.attestation object.

status selects the variant, and each variant’s own fields carry no skip_serializing_if — so they are read with _need under the status that emits them. signed matters most: reading it with .get failed open, turning “nothing vouches for this document” into None.