Test attestation Package

Conforma can verify test result attestations attached to images as in-toto statements. This package inspects the content of verified test-result predicates and produces violations for failed tests and warnings for warned tests. The package is a no-op when no test-result attestations are present.

Package Name

  • test_attestation

Rules Included

No erred test attestations

Produce a violation if any test result attestation has an erred result. The result type is configurable by the "erred_test_attestation_results" key in the rule data.

Solution: A test attestation has an erred result, indicating an infrastructure or execution failure. Review the test attestation and re-run the test.

  • Rule type: FAILURE

  • FAILURE message: Test attestation %q has an erred result

  • Code: test_attestation.no_erred_test_attestations

  • Effective from: 2026-01-15T00:00:00Z

  • Source

No failed informative test attestations

Produce a warning if any informative test attestation has a failed result. Informative tests produce warnings instead of violations, allowing teams to roll out new tests without blocking releases. The list of informative tests is configurable by the "informative_test_attestations" key, and the result type by the "failed_test_attestation_results" key in the rule data.

Solution: An informative test attestation has a failed result. While this does not block the release, review the test attestation output for details.

  • Rule type: WARNING

  • WARNING message: Informative test attestation %q has a failed result, failures: %s

  • Code: test_attestation.no_failed_informative_test_attestations

  • Effective from: 2026-01-15T00:00:00Z

  • Source

No failed test attestations

Produce a violation if any non-informative test result attestation has a failed result. Failed test names from the attestation predicate are included in the message when available. The result type is configurable by the "failed_test_attestation_results" key, and the list of informative tests by the "informative_test_attestations" key in the rule data.

Solution: Ensure all test attestations have a passing result. Review the test attestation output for details.

  • Rule type: FAILURE

  • FAILURE message: Test attestation %q has a failed result, failures: %s

  • Code: test_attestation.no_failed_tests

  • Effective from: 2026-01-15T00:00:00Z

  • Source

No skipped test attestations

Produce a violation if any test result attestation has a skipped result. A skipped result means a pre-requirement for executing the test was not met. The result type is configurable by the "skipped_test_attestation_results" key in the rule data.

Solution: A test attestation was skipped, indicating a missing prerequisite such as a scanner license. Ensure prerequisites are available and re-run the test.

  • Rule type: FAILURE

  • FAILURE message: Test attestation %q has a skipped result

  • Code: test_attestation.no_skipped_test_attestations

  • Effective from: 2026-01-15T00:00:00Z

  • Source

No test attestation warnings

Produce a warning if any test result attestation has a warned result. Warned test names from the attestation predicate are included in the message when available. The result type is configurable by the "warned_test_attestation_results" key in the rule data.

Solution: Review the test attestation output for warning details.

  • Rule type: WARNING

  • WARNING message: Test attestation %q has warnings, warnings: %s

  • Code: test_attestation.no_test_warnings

  • Effective from: 2026-01-15T00:00:00Z

  • Source

No unsupported test attestation result values

Ensure the result field of each test result attestation is a recognized value. Valid values are configurable by the "supported_test_attestation_results" key in the rule data. Defaults are PASSED, WARNED, FAILED, ERROR, and SKIPPED per the in-toto test-result predicate specification.

Solution: The test result attestation contains an unrecognized result value. Valid values are configurable via rule data.

  • Rule type: FAILURE

  • FAILURE message: Test attestation %q has an unsupported result value %q

  • Code: test_attestation.test_result_known

  • Effective from: 2026-01-15T00:00:00Z

  • Source

Rule data provided

Confirm the expected rule data keys have been provided in the expected format. The keys are "supported_test_attestation_results", "failed_test_attestation_results", "erred_test_attestation_results", "skipped_test_attestation_results", "warned_test_attestation_results", and "informative_test_attestations".

Solution: If provided, ensure the rule data is in the expected format.

  • Rule type: FAILURE

  • FAILURE message: %s

  • Code: test_attestation.rule_data_provided

  • Effective from: 2026-01-15T00:00:00Z

  • Source

Test attestation data includes result

Each test result attestation must include a result field in its predicate. Verify that the result field is present.

Solution: The test result attestation predicate must include a "result" field with a recognized value such as PASSED, WARNED, or FAILED.

  • Rule type: FAILURE

  • FAILURE message: Test attestation %q is missing the required result field

  • Code: test_attestation.test_data_found

  • Effective from: 2026-01-15T00:00:00Z

  • Source

Test attestation includes a valid timestamp

Ensure every signature-verified test-result attestation provides a valid RFC 3339 timestamp. The timestamp is required to select the latest retry deterministically.

Solution: Set predicate.timestamp to the RFC 3339 instant when the test result was produced.

  • Rule type: FAILURE

  • FAILURE message: Test attestation is missing a valid RFC 3339 timestamp

  • Code: test_attestation.test_timestamp_found

  • Effective from: 2027-01-15T00:00:00Z

  • Source

Test attestation includes an identity

Ensure every test-result attestation provides a non-empty string in predicate.configuration[0].name. The name identifies repeated executions of the same integration test when selecting its latest result.

Solution: Set predicate.configuration[0].name to the stable name of the integration test that produced the attestation.

  • Rule type: FAILURE

  • FAILURE message: Test attestation is missing a valid configuration name

  • Code: test_attestation.test_identity_found

  • Effective from: 2027-01-15T00:00:00Z

  • Source

Test attestation subject matches image

Verify that each test-result attestation’s subject includes the digest of the image being evaluated. An attestation produced for a different image should not satisfy this image’s test requirements.

Solution: The test result attestation was produced for a different image than the one being evaluated. Ensure the test pipeline produces attestations with the correct subject digest.

  • Rule type: FAILURE

  • FAILURE message: Test attestation %q subject does not match image digest %q

  • Code: test_attestation.subject_mismatch

  • Effective from: 2026-01-15T00:00:00Z

  • Source