> ## Documentation Index
> Fetch the complete documentation index at: https://kosli-docs-snapshot-deployment-diffs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# kosli attest artifact

> Attest an artifact creation to a Kosli flow.  

## Synopsis

```shell theme={null}
kosli attest artifact {IMAGE-NAME | FILE-PATH | DIR-PATH} [flags]
```

Attest an artifact creation to a Kosli flow.

The artifact fingerprint can be provided directly with the `--fingerprint` flag, or
calculated based on `--artifact-type` flag.

Artifact type can be one of: "file" for files, "dir" for directories, "oci" for container
images in registries or "docker" for local docker images.

Note: `--artifact-type=docker` reads the image's repo digest via the local Docker daemon.
The image must have been pushed to or pulled from a registry for a repo digest to exist;
a freshly built image (just `docker build`) will not have one. If the image is already in
a registry, prefer `--artifact-type=oci`, which fetches the digest directly from the
registry without needing a local Docker daemon.

For `--artifact-type=oci` (and for `--artifact-type=docker` when `--registry-username`
is set), registry credentials are resolved as follows:

1. If `--registry-username` (and optionally `--registry-password`) is set, it is used directly.
2. Otherwise, credentials are discovered automatically from:
   * the Docker config file (`~/.docker/config.json`, populated by `docker login`)
   * the Podman/containers auth file (`~/.config/containers/auth.json`, or `$REGISTRY_AUTH_FILE`)
   * any Docker credential helper configured in that config (e.g. `docker-credential-ecr-login`
     for AWS ECR, `docker-credential-gcloud` for GCR/Artifact Registry, an ACR helper for Azure,
     or a local keychain helper), invoked as an external binary on `$PATH`
   * if none of the above yield credentials, the registry is accessed anonymously, which works
     for public images
     `--registry-provider` is deprecated and no longer used.

To specify paths in a directory artifact that should always be excluded from the SHA256 calculation, you can add a `.kosli_ignore` file to the root of the artifact.
Each line should specify a relative path or path glob to be ignored. You can include comments in this file, using `#`.
The `.kosli_ignore` file is always treated as part of the artifact: its own entries cannot exclude it, so the exclusion list cannot be changed without changing the fingerprint.
Paths the list already matches stay excluded whatever is later added there, so keep its entries as narrow as possible.
Excluding the file with `--exclude` keeps it out of the fingerprint but still applies the paths it lists, which lets a writable directory change the list again.
To drop the file from the fingerprint safely, move its entries to `--exclude` and delete it.
This command requires access to a git repo to associate the artifact to the git commit it is originating from.
You can optionally redact some of the git commit data sent to Kosli using `--redact-commit-info`.
To record repository information, all three of `--repo-id`, `--repo-url`, and `--repository` must be set together.
These are automatically set in GitHub Actions, GitLab CI, Bitbucket Pipelines, and Azure DevOps.
In other CI systems, set them explicitly to capture repository metadata.

## Flags

| Flag                     | Type           | Description                                                                                                                                                                                                                                                                                                                                     |
| :----------------------- | :------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--annotate`             | stringToString | \[optional] Annotate the attestation with data using key=value.                                                                                                                                                                                                                                                                                 |
| `-t`, `--artifact-type`  | string         | The type of the artifact to calculate its SHA256 fingerprint. One of: \[oci, docker, file, dir]. Only required if you want Kosli to calculate the fingerprint for you (i.e. when you don't specify '`--fingerprint`' on commands that allow it).                                                                                                |
| `-b`, `--build-url`      | string         | The url of CI pipeline that built the artifact. (defaulted in some CIs: [docs](/integrations/ci_cd) ).                                                                                                                                                                                                                                          |
| `-g`, `--commit`         | string         | \[defaulted] The git commit from which the artifact was created. (defaulted in some CIs: [docs](/integrations/ci_cd), otherwise defaults to HEAD ). (default "HEAD")                                                                                                                                                                            |
| `-u`, `--commit-url`     | string         | The url for the git commit that created the artifact. (defaulted in some CIs: [docs](/integrations/ci_cd) ).                                                                                                                                                                                                                                    |
| `-N`, `--display-name`   | string         | \[optional] Artifact display name, if different from file, image or directory name.                                                                                                                                                                                                                                                             |
| `-D`, `--dry-run`        | bool           | \[optional] Run in dry-run mode. When enabled, no data is sent to Kosli and the CLI exits with 0 exit code regardless of any errors.                                                                                                                                                                                                            |
| `-x`, `--exclude`        | strings        | \[optional] The comma separated list of directories and files to exclude from fingerprinting. Can take glob patterns. Only applicable for `--artifact-type` dir.                                                                                                                                                                                |
| `--external-fingerprint` | stringToString | \[optional] A SHA256 fingerprint of an external attachment represented by `--external-url`. The format is label=fingerprint (labels cannot contain '.' or '='). This flag can be set multiple times. There must be an external url with a matching label for each external fingerprint.                                                         |
| `--external-url`         | stringToString | \[optional] Add labeled reference URL for an external resource. The format is label=url (labels cannot contain '.' or '='). This flag can be set multiple times. If the resource is a file or dir, you can optionally add its fingerprint via `--external-fingerprint`                                                                          |
| `-F`, `--fingerprint`    | string         | \[conditional] The SHA256 fingerprint of the artifact. Only required if you don't specify '`--artifact-type`'.                                                                                                                                                                                                                                  |
| `-f`, `--flow`           | string         | The Kosli flow name.                                                                                                                                                                                                                                                                                                                            |
| `-h`, `--help`           | bool           | help for artifact                                                                                                                                                                                                                                                                                                                               |
| `-n`, `--name`           | string         | The name of the artifact in the yml template file.                                                                                                                                                                                                                                                                                              |
| `--redact-commit-info`   | strings        | \[optional] The list of commit info to be redacted before sending to Kosli. Allowed values are one or more of \[author, message, branch].                                                                                                                                                                                                       |
| `--registry-password`    | string         | \[conditional] The container registry password or access token. Only required if you want to read container image SHA256 digest from a remote container registry and it is not already accessible via Docker/Podman auth files or a credential helper.                                                                                          |
| `--registry-provider`    | string         | \[deprecated] The docker registry provider or url. Only required if you want to read docker image SHA256 digest from a remote docker registry. (DEPRECATED: no longer used)                                                                                                                                                                     |
| `--registry-username`    | string         | \[conditional] The container registry username. Only required if you want to read container image SHA256 digest from a remote container registry and it is not already accessible via Docker/Podman auth files or a credential helper.                                                                                                          |
| `--repo-id`              | string         | \[conditional] The stable, unique identifier for the repository in your VCS provider (e.g. a numeric ID). Do not use the repository name as it can change if the repo is renamed. All three of `--repo-id`, `--repo-url` and `--repository` must be set to record repository information (defaulted in some CIs: [docs](/integrations/ci_cd) ). |
| `--repo-provider`        | string         | \[optional] The source code hosting provider. One of: github, gitlab, bitbucket, bitbucket\_cloud, bitbucket\_dc, azure-devops, azure\_devops\_services, azure\_devops\_server, git, subversion (defaulted in some CIs: [docs](/integrations/ci_cd) ).                                                                                          |
| `--repo-root`            | string         | \[defaulted] The directory where the source git repository is available. (default ".")                                                                                                                                                                                                                                                          |
| `--repo-url`             | string         | \[conditional] The URL of the repository. Must be a valid URL. All three of `--repo-id`, `--repo-url` and `--repository` must be set to record repository information (defaulted in some CIs: [docs](/integrations/ci_cd) ).                                                                                                                    |
| `--repository`           | string         | \[conditional] The name of the repository (e.g. owner/repo-name). All three of `--repo-id`, `--repo-url` and `--repository` must be set to record repository information (defaulted in some CIs: [docs](/integrations/ci_cd) ).                                                                                                                 |
| `-T`, `--trail`          | string         | The Kosli trail name.                                                                                                                                                                                                                                                                                                                           |

## Flags inherited from parent commands

| Flag                      | Type   | Description                                                                                                                                                           |
| :------------------------ | :----- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `-a`, `--api-token`       | string | The Kosli API token.                                                                                                                                                  |
| `-c`, `--config-file`     | string | \[optional] The Kosli config file path. Config is read from this path or the default only, never implicitly from the current directory. (default "\$HOME/.kosli.yml") |
| `--debug`                 | bool   | \[optional] Print debug logs to stdout.                                                                                                                               |
| `-H`, `--host`            | string | \[defaulted] The Kosli endpoint. (default "[https://app.kosli.com](https://app.kosli.com)")                                                                           |
| `--http-proxy`            | string | \[optional] The HTTP proxy URL including protocol and port number. e.g. `http://proxy-server-ip:proxy-port`                                                           |
| `-r`, `--max-api-retries` | int    | \[defaulted] How many times should API calls be retried when the API host is not reachable. (default 3)                                                               |
| `--org`                   | string | The Kosli organization.                                                                                                                                               |
| `-q`, `--quiet`           | bool   | \[optional] Suppress non-critical warning messages. Errors and normal output are not affected. If both `--quiet` and `--debug` are set, `--debug` wins.               |

## Live Examples in different CI systems

<Tabs>
  <Tab title="GitHub">
    View an example of the `kosli attest artifact` command in GitHub.

    In [this YAML file](https://github.com/cyber-dojo/reusable-actions-workflows/blob/25f0b797c18403de1c8490a9a71bbe9789c809a9/.github/workflows/secure-docker-build.yml#L210), which created [this Kosli Event](https://app.kosli.com/cyber-dojo/flows/differ-ci/trails/2e9bd969b50fff6b86578d69b7139f2d688ef6e2?attestation_id=054eef05-3aee-49ae-9e4d-55f768b7).
  </Tab>

  <Tab title="GitLab">
    View an example of the `kosli attest artifact` command in GitLab.

    In [this YAML file](https://gitlab.com/cyber-dojo/creator/-/blob/65fd2bfa2478534ea4bc5ccf30f6bfc6aab7550c/.gitlab/workflows/main.yml#L111), which created [this Kosli Event](https://app.kosli.com/cyber-dojo/flows/creator-ci/trails/99d7b74f39e311d492902ad48dbe97da63f2c687?attestation_id=205424b6-5741-4071-bd36-c26e83f6).
  </Tab>
</Tabs>

## Examples Use Cases

These examples all assume that the flags  `--api-token`, `--org`, `--host`, (and `--flow`, `--trail` when required), are [set/provided](/getting_started/install/#assigning-flags-via-environment-variables).

<AccordionGroup>
  <Accordion title="Attest that a file type artifact has been created, and let Kosli calculate its fingerprint">
    ```shell theme={null}
    kosli attest artifact FILE.tgz 
    	--artifact-type file 
    	--build-url https://exampleci.com 
    	--commit-url https://github.com/YourOrg/YourProject/commit/yourCommitShaThatThisArtifactWasBuiltFrom 
    	--commit yourCommitShaThatThisArtifactWasBuiltFrom 
    	--name yourTemplateArtifactName 


    ```
  </Accordion>

  <Accordion title="Attest that an artifact has been created and provide its fingerprint (sha256)">
    ```shell theme={null}
    kosli attest artifact ANOTHER_FILE.txt 
    	--build-url https://exampleci.com 
    	--commit-url https://github.com/YourOrg/YourProject/commit/yourCommitShaThatThisArtifactWasBuiltFrom 
    	--commit yourCommitShaThatThisArtifactWasBuiltFrom 
    	--fingerprint yourArtifactFingerprint 
    	--name yourTemplateArtifactName 

    ```
  </Accordion>

  <Accordion title="Attest that an artifact has been created and provide external attachments">
    ```shell theme={null}
    kosli attest artifact ANOTHER_FILE.txt 
    	--build-url https://exampleci.com 
    	--commit-url https://github.com/YourOrg/YourProject/commit/yourCommitShaThatThisArtifactWasBuiltFrom 
    	--commit yourCommitShaThatThisArtifactWasBuiltFrom 
    	--fingerprint yourArtifactFingerprint 
    	--external-url label=https://example.com/attachment 
    	--external-fingerprint label=yourExternalAttachmentFingerprint 
    	--name yourTemplateArtifactName 
    ```
  </Accordion>
</AccordionGroup>
