feat(cli): use repository organization for attestations - #3518
Open
waveywaves wants to merge 1 commit into
Open
waveywaves wants to merge 1 commit into
waveywaves wants to merge 1 commit into
Conversation
Contributor
AI Session Checks —
|
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | secrets-detection |
- |
✅ sast-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | owasp-top10-2025 |
- |
| ✅ Passed | sast |
- |
| ✅ Passed | cwe-top25 |
- |
| ✅ Passed | cwe-top26-40-cusp |
- |
✅ security-context — no advisories
Nothing this change touches has a recorded security-fix history.
View security context ↗ · Security context documentation ↗
⏭️ 3 scans not applied
| Scan | Reason |
|---|---|
vulnerability-scan |
no manifest/lockfile changed |
github-actions-scan |
no workflow files changed |
iac-scan |
no IaC files changed |
PR validation — ⚠️ 1 failing
| Status | Policy | Material | Messages |
|---|---|---|---|
pr-min-approvals |
pr-info |
PR/MR #3518 has 0 approving reviews, 1 required. | |
| ✅ Passed | pr-description-required |
pr-info |
- |
| ✅ Passed | pr-user-story-linked |
pr-info |
- |
Powered by Chainloop and Chainloop Trace
3 of 12 tasks
waveywaves
force-pushed
the
feat/attestation-repo-organization
branch
2 times, most recently
from
October 5, 2026 15:02
a176137 to
e3df37f
Compare
waveywaves
marked this pull request as ready for review
October 6, 2026 05:56
Contributor
There was a problem hiding this comment.
All reported issues were addressed across 10 files
Tip: cubic used a learning from your PR history. Let your coding agent read cubic learnings directly with the cubic MCP.
Re-trigger cubic
Apply repository organization selection to attestation commands before connecting, preserve explicit and saved choices, and reject mismatched API tokens without changing the saved default. Implements R-003, R-005, R-006, R-009, and the organization portion of R-004. Refs: chainloop-dev#3504 Assisted-by: pi Signed-off-by: Vibhav Bobade <vibhav.bobde@gmail.com>
waveywaves
force-pushed
the
feat/attestation-repo-organization
branch
from
October 6, 2026 06:45
e3df37f to
94c7bd4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR continues Spec 001: Project and Organization from
.chainloop.ymlin Attestations. It covers R-003, R-005, R-006, R-009, and the organization portion of R-004. The complete implementation is tracked in #3504.Summary
attestation init,add,push,status, andresetselect the repository organization before opening the control-plane connection.verifyis unchanged.--org,CHAINLOOP_ORGANIZATION, repository config, local attestation state, then the saved default.Requirements covered
Verification
env -u CHAINLOOP_TOKEN -u CHAINLOOP_ORGANIZATION go test ./app/cli/internal/token ./app/cli/cmd ./app/cli/pkg/action ./app/climainPart of #3504
Refs #3063
AI assistance
pi helped to write this change. The commit carries an
Assisted-by: pitrailer.