generated: '2026-09-07' method: searched source: >- Dagger's published documentation and repository: the GraphQL SDL at graphql/dagger-schema.graphqls, the CHANGELOG header at https://github.com/dagger/dagger/blob/main/CHANGELOG.md, the HTTP/GraphQL guide at https://docs.dagger.io/0.21/getting-started/api/http/, the OIDC discovery document saved at well-known/dagger-openid-configuration.json, and the security page at https://docs.dagger.io/features/security/ provider: Dagger providerId: dagger note: >- Dagger is a build/automation engine, not a regulated-sector API, so the cross-cutting standards it conforms to are engineering standards, not compliance regimes. Recorded as asserted only where evidence points at a specific document, schema location or served endpoint. conformance: - id: graphql name: GraphQL (June 2018 / current spec) conforms: true evidence: >- The entire Dagger API is a GraphQL schema; the SDL is published first-party at https://github.com/dagger/dagger/blob/main/docs/docs-graphql/schema.graphqls (177,812 bytes, 84 object types, 18 enums, 3 interfaces, 4 input types, 4 custom scalars, 12 directives) and saved verbatim at graphql/dagger-schema.graphqls. - id: graphql-over-http name: GraphQL over HTTP conforms: true evidence: >- "the API endpoint can be reached at http://127.0.0.1:$DAGGER_SESSION_PORT/query" with a JSON body carrying query/variables, documented with a verbatim curl example at https://docs.dagger.io/0.21/getting-started/api/http/ . The spec's 200-on-error convention is captured in errors/dagger-problem-types.yml. - id: graphql-introspection name: GraphQL introspection conforms: true evidence: >- Every Dagger SDK is code-generated from the live schema by introspection; the Rust SDK vendors an introspection schema at sdk/rust/crates/dagger-sdk/src/core/graphql/introspection_schema.graphql. - id: oidc name: OpenID Connect Discovery 1.0 conforms: true partial: true evidence: >- https://api.dagger.cloud/.well-known/openid-configuration returns HTTP 200 application/json with issuer https://api.dagger.cloud, jwks_uri https://api.dagger.cloud/jwks (200, one RS256 RSA key), response_types_supported [id_token], id_token_signing_alg_values_supported [RS256], subject_types_supported [public]. Probed 2026-09-07; saved at well-known/dagger-openid-configuration.json. Marked partial because the document advertises id_token issuance only — no authorization_endpoint, token_endpoint, or scopes_supported — so it is an OIDC identity-token issuer for Dagger Cloud, not a full OP an application can run an auth code flow against. - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No securityScheme of type oauth2 in the OpenAPI, no scopes documented, and /.well-known/oauth-authorization-server returns 404 on every Dagger host probed (see well-known/dagger-well-known.yml). Engine auth is HTTP Basic with a per-session token; Dagger Cloud uses DAGGER_CLOUD_TOKEN. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- No application/problem+json response is declared anywhere in openapi/dagger-graphql-api-openapi.yml. Errors follow the GraphQL errors[] envelope instead, which is the correct convention for this transport. - id: semver name: Semantic Versioning 2.0.0 conforms: true evidence: >- CHANGELOG.md states the project "adheres to Semantic Versioning (https://semver.org/spec/v2.0.0.html)". Releases are tagged vMAJOR.MINOR.PATCH (v0.21.9, 2026-08-26) with per-SDK tags on the same train (sdk/go/v0.21.9, sdk/python/v0.21.9, ...). - id: keepachangelog name: Keep a Changelog 1.0.0 conforms: true evidence: >- CHANGELOG.md states "The format is based on Keep a Changelog (https://keepachangelog.com/en/1.0.0/) ... and is generated by Changie", and the file uses Added / Changed / Fixed sections per dated version heading. - id: oci name: OCI Image and Distribution specifications conforms: true evidence: >- The schema exposes Container.publish, Container.from, ImageMediaTypes and ImageLayerCompression enums, and RegistryProtocol — Dagger builds, pulls and publishes OCI images to OCI registries as a first-class operation. See graphql/dagger-schema.graphqls. - id: opentelemetry name: OpenTelemetry conforms: true evidence: >- The engine emits OTel traces (the org publishes github.com/dagger/otel-go, "Otel package for Dagger engine and Go SDK") and Dagger Cloud's product is the trace/telemetry view of those spans; the pricing page meters the product in "Monthly Events". - id: idempotency name: HTTP idempotency keys (Idempotency-Key header) conforms: false evidence: >- No Idempotency-Key header appears in the OpenAPI or the docs. Dagger's replay protection is architectural rather than header-based — see conventions/dagger-conventions.yml. - id: pagination name: Cursor or page-based pagination conforms: false evidence: >- Not applicable to this shape. There is one transport operation and a GraphQL schema with no Relay connection types in the SDL (no PageInfo, no *Connection type in graphql/dagger-schema.graphqls). domain_standards: - id: none-applicable name: No domain standard applies conforms: false evidence: >- Reward-only check, deliberately left empty. CI/CD and build automation has no interchange standard of the SCIM / OData / OpenRTB / HL7 / ISO-20022 kind that a contract could declare, and nothing in the SDL declares one. Recorded as an explicit "checked, none exists" rather than left absent.