Skip to content

feat(cli): use repository organization for attestations - #3518

Open
waveywaves wants to merge 1 commit into
chainloop-dev:mainfrom
waveywaves:feat/attestation-repo-organization
Open

waveywaves wants to merge 1 commit into
chainloop-dev:mainfrom
waveywaves:feat/attestation-repo-organization

Conversation

@waveywaves

@waveywaves waveywaves commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

This PR continues Spec 001: Project and Organization from .chainloop.yml in Attestations. It covers R-003, R-005, R-006, R-009, and the organization portion of R-004. The complete implementation is tracked in #3504.

Summary

  • attestation init, add, push, status, and reset select the repository organization before opening the control-plane connection. verify is unchanged.
  • Organization precedence is --org, CHAINLOOP_ORGANIZATION, repository config, local attestation state, then the saved default.
  • Repository selection is run-local. It neither overwrites nor clears the saved default; the final user-facing membership error identifies both the organization and repository file.
  • Organization-bound API tokens for a different organization fail before connecting and report both organizations with both supported remedies. Instance-admin tokens keep using the repository organization header.
  • A visible line identifies the organization and repository file when the file changes the saved default.
  • Trace and attestation commands share API-token parsing while existing Trace mismatch behavior stays unchanged.

Requirements covered

  • R-003: Organization from the file
  • R-004: Flag and environment precedence (organization portion)
  • R-005: API token for a different organization
  • R-006: Saved CLI default stays the same
  • R-009: Notice when the file changes the organization

Verification

  • env -u CHAINLOOP_TOKEN -u CHAINLOOP_ORGANIZATION go test ./app/cli/internal/token ./app/cli/cmd ./app/cli/pkg/action ./app/cli
  • Rebased on current main

Part of #3504
Refs #3063

AI assistance

pi helped to write this change. The commit carries an Assisted-by: pi trailer.

@chainloop-platform

chainloop-platform Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

AI Session Checks — ⚠️ no AI session found

Missing AI Coding Sessions

This organization requires every PR to be backed by a Chainloop Trace AI coding session, and none was found for this one.

Please make sure the AI coding session evidence has been sent by the Chainloop CLI, or add the skip-ai-session label to this PR to bypass this check.

Learn more about Chainloop Trace.


Security Checks — ✅ 5 passing

✅ secret-scan

Status Policy Messages
✅ Passed secrets-detection -

✅ sast-scan

Status Policy Messages
✅ Passed owasp-top10-2025 -
✅ Passed sast -
✅ Passed cwe-top25 -
✅ Passed cwe-top26-40-cusp -

✅ security-context — no advisories

Nothing this change touches has a recorded security-fix history.

View security context ↗ · Security context documentation ↗

⏭️ 3 scans not applied

Scan Reason
vulnerability-scan no manifest/lockfile changed
github-actions-scan no workflow files changed
iac-scan no IaC files changed

View attestation ↗


PR validation — ⚠️ 1 failing

Status Policy Material Messages
⚠️ Failed pr-min-approvals pr-info PR/MR #3518 has 0 approving reviews, 1 required.
✅ Passed pr-description-required pr-info -
✅ Passed pr-user-story-linked pr-info -

View attestation ↗


Powered by Chainloop and Chainloop Trace

@waveywaves
waveywaves force-pushed the feat/attestation-repo-organization branch 2 times, most recently from a176137 to e3df37f Compare October 5, 2026 15:02
@waveywaves
waveywaves marked this pull request as ready for review October 6, 2026 05:56

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 10 files

Tip: cubic used a learning from your PR history. Let your coding agent read cubic learnings directly with the cubic MCP.

Re-trigger cubic

Comment thread app/cli/cmd/attestation_test.go Outdated
Comment thread app/cli/cmd/root.go
Comment thread app/cli/internal/token/token.go Outdated
Apply repository organization selection to attestation commands before connecting, preserve explicit and saved choices, and reject mismatched API tokens without changing the saved default.

Implements R-003, R-005, R-006, R-009, and the organization portion of R-004.
Refs: chainloop-dev#3504

Assisted-by: pi
Signed-off-by: Vibhav Bobade <vibhav.bobde@gmail.com>
@waveywaves
waveywaves force-pushed the feat/attestation-repo-organization branch from e3df37f to 94c7bd4 Compare October 6, 2026 06:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant