Synopsis
It checks if a pull request exists for the artifact (based on its git commit) and reports the pull-request attestation to the artifact in Kosli. The attestation can be bound to a trail using the trail name.
The attestation can be bound to an artifact in two ways:
- using the artifact’s SHA256 fingerprint which is calculated (based on the
--artifact-typeflag and the artifact name/path argument) or can be provided directly (with the--fingerprintflag). - using the artifact’s name in the flow yaml template and the git commit from which the artifact is/will be created. Useful when reporting an attestation before creating/reporting the artifact.
Flags
Flags inherited from parent commands
Examples Use Cases
These examples all assume that the flags--api-token, --org, --host, (and --flow, --trail when required), are set/provided.
report an Azure Devops pull request attestation about a pre-built docker artifact (kosli calculates the fingerprint)
report an Azure Devops pull request attestation about a pre-built docker artifact (kosli calculates the fingerprint)
report an Azure Devops pull request attestation about a pre-built docker artifact (you provide the fingerprint)
report an Azure Devops pull request attestation about a pre-built docker artifact (you provide the fingerprint)
report an Azure Devops pull request attestation about a trail
report an Azure Devops pull request attestation about a trail
report an Azure Devops pull request attestation about an artifact which has not been reported yet in a trail
report an Azure Devops pull request attestation about an artifact which has not been reported yet in a trail
report an Azure Devops pull request attestation about a trail with an attachment
report an Azure Devops pull request attestation about a trail with an attachment
fail if a pull request does not exist for your artifact
fail if a pull request does not exist for your artifact