Skip to main content
This is a beta feature. Beta features provide early access to product functionality. These features may change between releases without warning, or can be removed in a future release. Please contact us to enable this feature for your organization.

Synopsis

Report a software bill of materials to an artifact or a trail in a Kosli flow.
The SBOM file is given with the --sbom-file flag. CycloneDX (JSON and XML) and SPDX (JSON and tag-value) are supported.
The file is uploaded as it is, so the recorded checksum is the checksum of the file you supplied and you can verify it by hand. It must be a single file: it is not compressed, and a gzipped file is rejected, because the format and the summary below are read from it. Kosli reads the format, the creation time, the tools that produced it, the subject it describes and how many packages it lists. Nothing is checked against the artifact; the SBOM is recorded as reported. The SBOM file is the only attachment: this command does not accept additional attachments, because two or more would be compressed together. The format and the file checksum are also added as the sbom_format and sbom_sha256 annotations. The attestation can be bound to a trail using the trail name. The attestation can be bound to an artifact in two ways:
  • using the artifact’s SHA256 fingerprint which is calculated (based on the --artifact-type flag and the artifact name/path argument) or can be provided directly (with the --fingerprint flag).
  • using the artifact’s name in the flow yaml template and the git commit from which the artifact is/will be created. Useful when reporting an attestation before creating/reporting the artifact.
To specify paths in a directory artifact that should always be excluded from the SHA256 calculation, you can add a .kosli_ignore file to the root of the artifact. Each line should specify a relative path or path glob to be ignored. You can include comments in this file, using #. The .kosli_ignore file is always treated as part of the artifact: its own entries cannot exclude it, so the exclusion list cannot be changed without changing the fingerprint. Paths the list already matches stay excluded whatever is later added there, so keep its entries as narrow as possible. Excluding the file with --exclude keeps it out of the fingerprint but still applies the paths it lists, which lets a writable directory change the list again. To drop the file from the fingerprint safely, move its entries to --exclude and delete it. You can optionally associate the attestation to a git commit using --commit (requires access to a git repo). You can optionally redact some of the git commit data sent to Kosli using --redact-commit-info. Note that when the attestation is reported for an artifact that does not yet exist in Kosli, --commit is required to facilitate binding the attestation to the right artifact. To record repository information, all three of --repo-id, --repo-url, and --repository must be set together. These are automatically set in GitHub Actions, GitLab CI, Bitbucket Pipelines, and Azure DevOps. In other CI systems, set them explicitly to capture repository metadata.

Flags

Flags inherited from parent commands

Examples Use Cases

These examples all assume that the flags --api-token, --org, --host, (and --flow, --trail when required), are set/provided.
Last modified on September 15, 2026