Synopsis
It checks if a merge request exists for a given merge commit and reports the merge request attestation to Kosli. The attestation can be bound to a trail using the trail name. The attestation can be bound to an artifact in two ways:
- using the artifact’s SHA256 fingerprint which is calculated (based on the
--artifact-typeflag and the artifact name/path argument) or can be provided directly (with the--fingerprintflag). - using the artifact’s name in the flow yaml template and the git commit from which the artifact is/will be created. Useful when reporting an attestation before creating/reporting the artifact.
.kosli_ignore file to the root of the artifact.
Each line should specify a relative path or path glob to be ignored. You can include comments in this file, using #.
The .kosli_ignore file is always treated as part of the artifact: its own entries cannot exclude it, so the exclusion list cannot be changed without changing the fingerprint.
Paths the list already matches stay excluded whatever is later added there, so keep its entries as narrow as possible.
Excluding the file with --exclude keeps it out of the fingerprint but still applies the paths it lists, which lets a writable directory change the list again.
To drop the file from the fingerprint safely, move its entries to --exclude and delete it.
Flags
Flags inherited from parent commands
Live Examples in different CI systems
- GitLab
View an example of the
kosli attest pullrequest gitlab command in GitLab.In this YAML file, which created this Kosli Event.Examples Use Cases
These examples all assume that the flags--api-token, --org, --host, (and --flow, --trail when required), are set/provided.
report a Gitlab merge request attestation about a pre-built docker artifact (kosli calculates the fingerprint)
report a Gitlab merge request attestation about a pre-built docker artifact (kosli calculates the fingerprint)
report a Gitlab merge request attestation about a pre-built docker artifact (you provide the fingerprint)
report a Gitlab merge request attestation about a pre-built docker artifact (you provide the fingerprint)
report a Gitlab merge request attestation about a trail
report a Gitlab merge request attestation about a trail
report a Gitlab merge request attestation about an artifact which has not been reported yet in a trail
report a Gitlab merge request attestation about an artifact which has not been reported yet in a trail
report a Gitlab merge request attestation about a trail with an attachment
report a Gitlab merge request attestation about a trail with an attachment
fail if a merge request does not exist for your artifact
fail if a merge request does not exist for your artifact