Artifact
A software deliverable (binary, container image, archive) reported to Kosli and identified by its SHA256 fingerprint. Kosli uses the fingerprint to link an artifact’s build-time origin to its runtime presence.Attestation
A record that a specific control or check was performed on an Artifact or Trail, along with its result. Built-in types includesnyk, junit, sonar, pullrequest, and generic. Custom types support jq-based compliance evaluation.