Synopsis
Use this command to record the outcome of evaluating a control as part of your delivery pipeline — whether it was satisfied or not — attached to a specific trail with an optional artifact. This decision is the evidence that a governance requirement was assessed. The attestation can be bound to a trail using the trail name. The attestation can be bound to an artifact in two ways:
- using the artifact’s SHA256 fingerprint which is calculated (based on the
--artifact-typeflag and the artifact name/path argument) or can be provided directly (with the--fingerprintflag). - using the artifact’s name in the flow yaml template and the git commit from which the artifact is/will be created. Useful when reporting an attestation before creating/reporting the artifact.
.kosli_ignore file to the root of the artifact.
Each line should specify a relative path or path glob to be ignored. You can include comments in this file, using #.
The .kosli_ignore will be treated as part of the artifact like any other file, unless it is explicitly ignored itself.
You can optionally associate the attestation to a git commit using --commit (requires access to a git repo).
You can optionally redact some of the git commit data sent to Kosli using --redact-commit-info.
Note that when the attestation is reported for an artifact that does not yet exist in Kosli, --commit is required to facilitate
binding the attestation to the right artifact.
To record repository information, all three of --repo-id, --repo-url, and --repository must be set together.
These are automatically set in GitHub Actions, GitLab CI, Bitbucket Pipelines, and Azure DevOps.
In other CI systems, set them explicitly to capture repository metadata.
Flags
Flags inherited from parent commands
Examples Use Cases
These examples all assume that the flags--api-token, --org, --host, (and --flow, --trail when required), are set/provided.
record a compliant decision against a trail
record a compliant decision against a trail
record a non-compliant decision against a trail
record a non-compliant decision against a trail
record a decision linked to a specific artifact (by fingerprint)
record a decision linked to a specific artifact (by fingerprint)
record a decision with an evidence attachment
record a decision with an evidence attachment