Skip to content

feat(cli): use repository config for attestations - #3502

Open
waveywaves wants to merge 1 commit into
chainloop-dev:mainfrom
waveywaves:feat/attestation-repo-config
Open

waveywaves wants to merge 1 commit into
chainloop-dev:mainfrom
waveywaves:feat/attestation-repo-config

Conversation

@waveywaves

@waveywaves waveywaves commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

This PR starts the implementation of Spec 001: Project and Organization from .chainloop.yml in Attestations. It covers R-007 and R-008. The complete implementation is tracked in #3504.

Summary

  • The attestation and trace commands now use one repository-config reader. It searches from the current directory to the Git repository root, prefers .chainloop.yml over .chainloop.yaml, accepts files without projectName, and returns the selected path (R-007).
  • The existing trace config helpers use the shared reader instead of implementing their own file selection.
  • attestation init reads projectVersion through the shared reader and continues normal flag validation when the config is missing or cannot be read (R-008).

Requirements covered

  • R-007: One way to find the file
  • R-008: Flag checks without a file

The remaining requirements and every implementation PR are tracked in #3504.

Refs #3063

AI assistance

pi helped to write this change. The commit carries an Assisted-by: pi trailer.

Use the existing Chainloop Trace config reader for attestation version loading
and keep init flag validation running when the config is unavailable.

Refs: chainloop-dev#3063

Assisted-by: pi
Signed-off-by: Vibhav Bobade <vibhav.bobde@gmail.com>
@chainloop-platform

chainloop-platform Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

AI Session Checks — ⏭️ bypassed by label

AI Coding Session Check Bypassed

This PR carries the skip-ai-session label, so the AI coding session check was bypassed.

Learn more about Chainloop Trace.


Security Checks — ✅ 5 passing

✅ secret-scan

Status Policy Messages
✅ Passed secrets-detection -

✅ sast-scan

Status Policy Messages
✅ Passed owasp-top10-2025 -
✅ Passed sast -
✅ Passed cwe-top25 -
✅ Passed cwe-top26-40-cusp -

✅ security-context — no advisories

Nothing this change touches has a recorded security-fix history.

View security context ↗ · Security context documentation ↗

⏭️ 3 scans not applied

Scan Reason
vulnerability-scan no manifest/lockfile changed
github-actions-scan no workflow files changed
iac-scan no IaC files changed

View attestation ↗


PR validation — ✅ 3 passing

Status Policy Material Messages
✅ Passed pr-min-approvals pr-info -
✅ Passed pr-description-required pr-info -
✅ Passed pr-user-story-linked pr-info -

View attestation ↗


Powered by Chainloop and Chainloop Trace

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 5 files

Re-trigger cubic

@migmartri
migmartri requested a review from a team October 1, 2026 17:07

@migmartri migmartri left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awesome, added a comment about the location of the function. It looks strange that a general purpose function is in a specific trace package.

// LoadChainloopYML loads the nearest .chainloop.yml (or .chainloop.yaml),
// walking from dir to the git repository root. In each directory, .yml takes
// precedence over .yaml. A config without projectName is still valid.
func LoadChainloopYML(dir string) (*ChainloopYML, string, error) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd personally would have put this function in cmd/config instead

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants