Skip to content

Latest commit

 

History

History
160 lines (138 loc) · 10.9 KB

File metadata and controls

160 lines (138 loc) · 10.9 KB
title kosli attest pullrequest gitlab
description Report a Gitlab merge request attestation to an artifact or a trail in a Kosli flow.

Synopsis

kosli attest pullrequest gitlab [IMAGE-NAME | FILE-PATH | DIR-PATH] [flags]

Report a Gitlab merge request attestation to an artifact or a trail in a Kosli flow.
It checks if a merge request exists for a given merge commit and reports the merge request attestation to Kosli.

The attestation can be bound to a trail using the trail name. The attestation can be bound to an artifact in two ways:

  • using the artifact's SHA256 fingerprint which is calculated (based on the --artifact-type flag and the artifact name/path argument) or can be provided directly (with the --fingerprint flag).
  • using the artifact's name in the flow yaml template and the git commit from which the artifact is/will be created. Useful when reporting an attestation before creating/reporting the artifact.

To specify paths in a directory artifact that should always be excluded from the SHA256 calculation, you can add a .kosli_ignore file to the root of the artifact. Each line should specify a relative path or path glob to be ignored. You can include comments in this file, using #. The .kosli_ignore file is always treated as part of the artifact: its own entries cannot exclude it, so the exclusion list cannot be changed without changing the fingerprint. Paths the list already matches stay excluded whatever is later added there, so keep its entries as narrow as possible. Excluding the file with --exclude keeps it out of the fingerprint but still applies the paths it lists, which lets a writable directory change the list again. To drop the file from the fingerprint safely, move its entries to --exclude and delete it.

Flags

Flag Type Description
--annotate stringToString [optional] Annotate the attestation with data using key=value.
-t, --artifact-type string The type of the artifact to calculate its SHA256 fingerprint. One of: [oci, docker, file, dir]. Only required if you want Kosli to calculate the fingerprint for you (i.e. when you don't specify '--fingerprint' on commands that allow it).
--assert bool [optional] Exit with non-zero code if no pull requests found for the given commit.
--attachments strings [optional] The comma-separated list of paths of attachments for the reported attestation. Attachments can be files or directories. All attachments are compressed and uploaded to Kosli's evidence vault.
-g, --commit string the git merge commit to be checked for associated pull requests.
--description string [optional] attestation description
-D, --dry-run bool [optional] Run in dry-run mode. When enabled, no data is sent to Kosli and the CLI exits with 0 exit code regardless of any errors.
-x, --exclude strings [optional] The comma separated list of directories and files to exclude from fingerprinting. Can take glob patterns. Only applicable for --artifact-type dir.
--external-fingerprint stringToString [optional] A SHA256 fingerprint of an external attachment represented by --external-url. The format is label=fingerprint (labels cannot contain '.' or '='). This flag can be set multiple times. There must be an external url with a matching label for each external fingerprint.
--external-url stringToString [optional] Add labeled reference URL for an external resource. The format is label=url (labels cannot contain '.' or '='). This flag can be set multiple times. If the resource is a file or dir, you can optionally add its fingerprint via --external-fingerprint
-F, --fingerprint string [conditional] The SHA256 fingerprint of the artifact to attach the attestation to. Only required if the attestation is for an artifact and --artifact-type and artifact name/path are not used.
-f, --flow string The Kosli flow name.
--gitlab-base-url string [optional] Gitlab base URL (only needed for on-prem Gitlab installations).
--gitlab-org string Gitlab organization. (defaulted if you are running in Gitlab Pipelines: docs ).
--gitlab-token string Gitlab token.
-h, --help bool help for gitlab
-n, --name string The name of the attestation as declared in the flow or trail yaml template.
-o, --origin-url string [optional] The url pointing to where the attestation came from or is related. (defaulted to the CI url in some CIs: docs ).
--redact-commit-info strings [optional] The list of commit info to be redacted before sending to Kosli. Allowed values are one or more of [author, message, branch].
--registry-password string [conditional] The container registry password or access token. Only required if you want to read container image SHA256 digest from a remote container registry and it is not already accessible via Docker/Podman auth files or a credential helper.
--registry-provider string [deprecated] The docker registry provider or url. Only required if you want to read docker image SHA256 digest from a remote docker registry. (DEPRECATED: no longer used)
--registry-username string [conditional] The container registry username. Only required if you want to read container image SHA256 digest from a remote container registry and it is not already accessible via Docker/Podman auth files or a credential helper.
--repo-id string [conditional] The stable, unique identifier for the repository in your VCS provider (e.g. a numeric ID). Do not use the repository name as it can change if the repo is renamed. All three of --repo-id, --repo-url and --repository must be set to record repository information (defaulted in some CIs: docs ).
--repo-provider string [optional] The source code hosting provider. One of: github, gitlab, bitbucket, bitbucket_cloud, bitbucket_dc, azure-devops, azure_devops_services, azure_devops_server, git, subversion (defaulted in some CIs: docs ).
--repo-root string [defaulted] The directory where the source git repository is available. Only used if --commit is used or defaulted in CI, see docs . (default ".")
--repo-url string [conditional] The URL of the repository. Must be a valid URL. All three of --repo-id, --repo-url and --repository must be set to record repository information (defaulted in some CIs: docs ).
--repository string [conditional] The name of the repository (e.g. owner/repo-name). All three of --repo-id, --repo-url and --repository must be set to record repository information (defaulted in some CIs: docs ).
-T, --trail string The Kosli trail name.
-u, --user-data string [optional] The path to a JSON file containing additional data you would like to attach to the attestation. The maximum JSON payload size is 1MB.

Flags inherited from parent commands

Flag Type Description
-a, --api-token string The Kosli API token.
-c, --config-file string [optional] The Kosli config file path. Config is read from this path or the default only, never implicitly from the current directory. (default "$HOME/.kosli.yml")
--debug bool [optional] Print debug logs to stdout.
-H, --host string [defaulted] The Kosli endpoint. (default "https://app.kosli.com")
--http-proxy string [optional] The HTTP proxy URL including protocol and port number. e.g. http://proxy-server-ip:proxy-port
-r, --max-api-retries int [defaulted] How many times should API calls be retried when the API host is not reachable. (default 3)
--org string The Kosli organization.
-q, --quiet bool [optional] Suppress non-critical warning messages. Errors and normal output are not affected. If both --quiet and --debug are set, --debug wins.

Live Examples in different CI systems

View an example of the `kosli attest pullrequest gitlab` command in GitLab.
In [this YAML file](https://gitlab.com/cyber-dojo/creator/-/blob/65fd2bfa2478534ea4bc5ccf30f6bfc6aab7550c/.gitlab/workflows/main.yml#L75), which created [this Kosli Event](https://app.kosli.com/cyber-dojo/flows/creator-ci/trails/99d7b74f39e311d492902ad48dbe97da63f2c687?attestation_id=a70287f4-c9fa-4072-9221-34faa89d).
</Tab>

Examples Use Cases

These examples all assume that the flags --api-token, --org, --host, (and --flow, --trail when required), are set/provided.

```shell kosli attest pullrequest gitlab yourDockerImageName --artifact-type docker --name yourAttestationName --gitlab-token yourGitlabToken --gitlab-org yourGitlabOrg --commit yourArtifactGitCommit --repository yourGithubGitRepository
</Accordion>
<Accordion title="report a Gitlab merge request attestation about a pre-built docker artifact (you provide the fingerprint)">
```shell
kosli attest pullrequest gitlab 
	--fingerprint yourDockerImageFingerprint 
	--name yourAttestationName 
	--gitlab-token yourGitlabToken 
	--gitlab-org yourGitlabOrg 
	--commit yourArtifactGitCommit 
	--repository yourGithubGitRepository 

```shell kosli attest pullrequest gitlab --name yourAttestationName --gitlab-token yourGitlabToken --gitlab-org yourGitlabOrg --commit yourArtifactGitCommit --repository yourGithubGitRepository
</Accordion>
<Accordion title="report a Gitlab merge request attestation about an artifact which has not been reported yet in a trail">
```shell
kosli attest pullrequest gitlab 
	--name yourTemplateArtifactName.yourAttestationName 
	--gitlab-token yourGitlabToken 
	--gitlab-org yourGitlabOrg 
	--commit yourArtifactGitCommit 
	--repository yourGithubGitRepository 

```shell kosli attest pullrequest gitlab --name yourAttestationName --gitlab-token yourGitlabToken --gitlab-org yourGitlabOrg --commit yourArtifactGitCommit --repository yourGithubGitRepository --attachments=yourAttachmentPathName
</Accordion>
<Accordion title="fail if a merge request does not exist for your artifact">
```shell
kosli attest pullrequest gitlab 
	--name yourTemplateArtifactName.yourAttestationName 
	--gitlab-token yourGitlabToken 
	--gitlab-org yourGitlabOrg 
	--commit yourArtifactGitCommit 
	--repository yourGithubGitRepository 
	--assert