Skip to content

feat(cli): resolve attestation project from repository config - #3517

Open
waveywaves wants to merge 1 commit into
chainloop-dev:mainfrom
waveywaves:feat/attestation-repo-project
Open

waveywaves wants to merge 1 commit into
chainloop-dev:mainfrom
waveywaves:feat/attestation-repo-project

Conversation

@waveywaves

@waveywaves waveywaves commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

This PR continues Spec 001: Project and Organization from .chainloop.yml in Attestations. It covers R-001, R-002, and the project portion of R-004. The complete implementation is tracked in #3504.

Summary

  • attestation init uses projectName from the repository config when --project is not set.
  • An explicit project or version continues to take precedence over repository values, and --latest-version continues to suppress the repository version.
  • When neither source provides a project, the command stops with an error that names both --project and projectName in .chainloop.yml.

Requirements covered

  • R-001: Project from the file
  • R-002: Project is still required
  • R-004: Flag precedence for project and version (project/version portion)

Verification

  • env -u CHAINLOOP_TOKEN -u CHAINLOOP_ORGANIZATION go test ./app/cli/cmd
  • Rebased on current main

Part of #3504
Refs #3063

AI assistance

pi helped to write this change. The commit carries an Assisted-by: pi trailer.

@chainloop-platform

chainloop-platform Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

AI Session Checks — ⏭️ bypassed by label

AI Coding Session Check Bypassed

This PR carries the skip-ai-session label, so the AI coding session check was bypassed.

Learn more about Chainloop Trace.


Security Checks — ✅ 5 passing

✅ secret-scan

Status Policy Messages
✅ Passed secrets-detection -

✅ sast-scan

Status Policy Messages
✅ Passed owasp-top10-2025 -
✅ Passed sast -
✅ Passed cwe-top25 -
✅ Passed cwe-top26-40-cusp -

✅ security-context — no advisories

Nothing this change touches has a recorded security-fix history.

View security context ↗ · Security context documentation ↗

⏭️ 3 scans not applied

Scan Reason
vulnerability-scan no manifest/lockfile changed
github-actions-scan no workflow files changed
iac-scan no IaC files changed

View attestation ↗


PR validation — ⚠️ 1 failing

Status Policy Material Messages
⚠️ Failed pr-min-approvals pr-info PR/MR #3517 has 0 approving reviews, 1 required.
✅ Passed pr-description-required pr-info -
✅ Passed pr-user-story-linked pr-info -

View attestation ↗


Powered by Chainloop and Chainloop Trace

Use projectName from repository config when --project is omitted, preserve explicit project and version choices, and report both accepted project sources when neither is set.

Implements R-001, R-002, and the project portion of R-004.
Refs: chainloop-dev#3504

Assisted-by: pi
Signed-off-by: Vibhav Bobade <vibhav.bobde@gmail.com>
@waveywaves
waveywaves force-pushed the feat/attestation-repo-project branch from 3edb5e6 to c531730 Compare October 5, 2026 15:02
@waveywaves
waveywaves marked this pull request as ready for review October 6, 2026 05:56

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Re-trigger cubic

@migmartri
migmartri requested a review from a team October 6, 2026 12:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants