{
  "type": "object",
  "properties": {
    "schema_version": {
      "enum": [
        "1.1.0",
        "1.2.0",
        "1.3.0",
        "1.4.0",
        "1.5.0"
      ]
    },
    "id": {
      "type": "string",
      "pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$"
    },
    "name": {
      "type": "string",
      "minLength": 1
    },
    "operator": {
      "type": "string",
      "minLength": 1
    },
    "platform": {
      "type": "string",
      "minLength": 1
    },
    "program_type": {
      "type": "object",
      "description": "Optional evidence-backed classification for record versions 1.3.0 and later, independent of submission status. Missing means unclassified, not unpaid. Vulnerability disclosure means an explicitly no-bounty program; exceptional discretionary payments are explained in the summary.",
      "properties": {
        "value": {
          "enum": [
            "paid_bounty",
            "vulnerability_disclosure",
            "unknown"
          ]
        },
        "summary": {
          "type": "string",
          "minLength": 1
        },
        "source_ids": {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 1
          },
          "uniqueItems": true
        }
      },
      "required": [
        "value",
        "summary",
        "source_ids"
      ],
      "additionalProperties": false
    },
    "program_url": {
      "type": "string",
      "format": "uri"
    },
    "policy_url": {
      "type": "string",
      "format": "uri"
    },
    "announcement_urls": {
      "type": "array",
      "items": {
        "type": "string",
        "format": "uri"
      },
      "uniqueItems": true
    },
    "change_log_url": {
      "type": [
        "string",
        "null"
      ],
      "format": "uri"
    },
    "rewards": {
      "type": "object",
      "properties": {
        "currency": {
          "type": [
            "string",
            "null"
          ],
          "pattern": "^[A-Z]{3}$"
        },
        "minimum": {
          "type": [
            "number",
            "null"
          ],
          "minimum": 0
        },
        "maximum": {
          "type": [
            "number",
            "null"
          ],
          "minimum": 0
        },
        "basis": {
          "const": "advertised_not_individual_award"
        },
        "summary": {
          "type": "string",
          "minLength": 1
        },
        "source_ids": {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 1
          },
          "minItems": 1,
          "uniqueItems": true
        }
      },
      "required": [
        "currency",
        "minimum",
        "maximum",
        "basis",
        "summary",
        "source_ids"
      ],
      "additionalProperties": false
    },
    "eligibility": {
      "type": "object",
      "properties": {
        "summary": {
          "type": "string",
          "minLength": 1
        },
        "source_ids": {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 1
          },
          "minItems": 1,
          "uniqueItems": true
        }
      },
      "required": [
        "summary",
        "source_ids"
      ],
      "additionalProperties": false
    },
    "restrictions": {
      "type": "object",
      "properties": {
        "summary": {
          "type": "string",
          "minLength": 1
        },
        "source_ids": {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 1
          },
          "minItems": 1,
          "uniqueItems": true
        }
      },
      "required": [
        "summary",
        "source_ids"
      ],
      "additionalProperties": false
    },
    "last_verified_at": {
      "type": "string",
      "format": "date-time"
    },
    "limitations": {
      "type": "array",
      "items": {
        "type": "string",
        "minLength": 1
      },
      "minItems": 1,
      "uniqueItems": true
    },
    "sources": {
      "type": "array",
      "minItems": 1,
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "minLength": 1
          },
          "title": {
            "type": "string",
            "minLength": 1
          },
          "url": {
            "type": "string",
            "format": "uri"
          },
          "publisher": {
            "type": "string",
            "minLength": 1
          },
          "retrieved_at": {
            "type": "string",
            "format": "date-time"
          },
          "provenance": {
            "const": "official_primary"
          },
          "access_method": {
            "enum": [
              "text",
              "browser",
              "text_and_browser"
            ]
          }
        },
        "required": [
          "id",
          "title",
          "url",
          "publisher",
          "retrieved_at",
          "provenance",
          "access_method"
        ],
        "additionalProperties": false
      }
    },
    "content_scope": {
      "const": "public_program_policy_summary"
    },
    "rights": {
      "const": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights."
    },
    "submission_status": {
      "type": "object",
      "properties": {
        "value": {
          "enum": [
            "accepting_reports",
            "paused",
            "closed",
            "unknown"
          ]
        },
        "summary": {
          "type": "string",
          "minLength": 1
        },
        "source_ids": {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 1
          },
          "uniqueItems": true
        }
      },
      "required": [
        "value",
        "summary",
        "source_ids"
      ],
      "additionalProperties": false
    },
    "official_program_links": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "url": {
            "type": "string",
            "format": "uri"
          },
          "source_ids": {
            "type": "array",
            "minItems": 1,
            "uniqueItems": true,
            "items": {
              "type": "string",
              "minLength": 1
            }
          },
          "note": {
            "type": "string",
            "minLength": 1
          }
        },
        "required": [
          "url",
          "source_ids",
          "note"
        ],
        "additionalProperties": false
      }
    },
    "asset_scope": {
      "type": "object",
      "description": "Version 1.5.0 published scope snapshot. Lists official in-scope and out-of-scope assets or policy-defined categories with evidence and capture limits; never grants authorization. Empty out_of_scope means no explicit asset row was captured, not unrestricted scope.",
      "properties": {
        "capture_status": {
          "enum": ["published_list", "policy_defined", "partial"]
        },
        "collection_method": {
          "enum": ["official_platform_scope_table", "official_policy_page"]
        },
        "verified_at": {
          "type": "string",
          "format": "date-time"
        },
        "source_ids": {
          "type": "array",
          "minItems": 1,
          "uniqueItems": true,
          "items": {"type": "string", "minLength": 1}
        },
        "in_scope": {
          "type": "array",
          "items": {"$ref": "#/$defs/program_asset"}
        },
        "out_of_scope": {
          "type": "array",
          "items": {"$ref": "#/$defs/program_asset"}
        },
        "limitations": {
          "type": "array",
          "minItems": 1,
          "uniqueItems": true,
          "items": {"type": "string", "minLength": 1, "pattern": "\\S"}
        }
      },
      "required": ["capture_status", "collection_method", "verified_at", "source_ids", "in_scope", "out_of_scope", "limitations"],
      "additionalProperties": false
    },
    "scope_context": {
      "type": "object",
      "description": "Optional high-level coverage and exclusion context for version 1.4.0 or later. Original summaries of reviewed official policy only; no asset inventories, target lists, testing instructions or authorization claims in this field. Missing means not separately summarized. Every policy URL must match a cited source, and a section fragment must be recorded on that source URL.",
      "properties": {
        "included_summary": {
          "type": "string",
          "minLength": 1,
          "pattern": "\\S",
          "description": "High-level policy coverage with exceptions and uncertainty; not an asset list or permission to test."
        },
        "excluded_summary": {
          "type": "string",
          "minLength": 1,
          "pattern": "\\S",
          "description": "High-level exclusions and limitations. State uncertainty explicitly; never infer no exclusions from missing information."
        },
        "source_ids": {
          "type": "array",
          "items": {
            "type": "string",
            "minLength": 1
          },
          "minItems": 1,
          "uniqueItems": true
        },
        "policy_urls": {
          "type": "array",
          "items": {
            "type": "string",
            "format": "uri"
          },
          "minItems": 1,
          "uniqueItems": true,
          "description": "Reviewed official policy pages or verified section links, supported by the linked source IDs. Do not invent anchors."
        },
        "verified_at": {
          "type": "string",
          "format": "date-time",
          "description": "Scope-context review time: no earlier than each cited source retrieval and no later than the record last_verified_at."
        }
      },
      "required": [
        "included_summary",
        "excluded_summary",
        "source_ids",
        "policy_urls",
        "verified_at"
      ],
      "additionalProperties": false
    }
  },
  "required": [
    "schema_version",
    "id",
    "name",
    "operator",
    "platform",
    "program_url",
    "policy_url",
    "announcement_urls",
    "change_log_url",
    "rewards",
    "eligibility",
    "restrictions",
    "last_verified_at",
    "limitations",
    "sources",
    "content_scope",
    "rights",
    "submission_status"
  ],
  "additionalProperties": false,
  "$defs": {
    "program_asset": {
      "type": "object",
      "properties": {
        "name": {"type": "string", "minLength": 1, "pattern": "\\S"},
        "asset_type": {"type": "string", "minLength": 1, "pattern": "\\S"},
        "location": {"type": ["string", "null"], "minLength": 1},
        "group": {"type": ["string", "null"], "minLength": 1},
        "source_ids": {
          "type": "array",
          "minItems": 1,
          "uniqueItems": true,
          "items": {"type": "string", "minLength": 1}
        },
        "note": {"type": "string", "minLength": 1, "pattern": "\\S"},
        "bounty_eligible": {"type": "boolean"}
      },
      "required": ["name", "asset_type", "location", "group", "source_ids"],
      "additionalProperties": false
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "title": "Public program policy and sourced asset scope directory"
}
