Synopsis
--type flag.
The path to the JSON file the custom type will evaluate is specified using the --attestation-data flag.
The attestation can be bound to a trail using the trail name.The attestation can be bound to an artifact in two ways:
- using the artifact’s SHA256 fingerprint which is calculated (based on the
--artifact-typeflag and the artifact name/path argument) or can be provided directly (with the--fingerprintflag). - using the artifact’s name in the flow yaml template and the git commit from which the artifact is/will be created. Useful when reporting an attestation before creating/reporting the artifact.
--commit (requires access to a git repo).
You can optionally redact some of the git commit data sent to Kosli using --redact-commit-info.
Note that when the attestation is reported for an artifact that does not yet exist in Kosli, --commit is required to facilitate
binding the attestation to the right artifact.
Flags
Flags inherited from parent commands
Live Examples in different CI systems
- GitHub
View an example of the
kosli attest custom command in GitHub.In this YAML file, which created this Kosli Event.Examples Use Cases
These examples all assume that the flags--api-token, --org, --host, (and --flow, --trail when required), are set/provided.
report a custom attestation about a pre-built container image artifact (kosli finds the fingerprint)
report a custom attestation about a pre-built container image artifact (kosli finds the fingerprint)
report a custom attestation about a pre-built docker artifact (you provide the fingerprint)
report a custom attestation about a pre-built docker artifact (you provide the fingerprint)
report a custom attestation about a trail
report a custom attestation about a trail
report a custom attestation about an artifact which has not been reported yet in a trail
report a custom attestation about an artifact which has not been reported yet in a trail
report a custom attestation about a trail with an attachment
report a custom attestation about a trail with an attachment