Synopsis
It checks if a pull request exists for a given merge commit and reports the pull-request attestation to Kosli. Authentication to Bitbucket can be done with an access token (recommended) or an Atlassian API token, passed via —bitbucket-username (your Atlassian account email) and —bitbucket-password. Bitbucket app passwords are no longer supported as of 28 July 2026; replace any app passwords with API tokens. Credentials need to have read access for both repos and pull requests. The attestation can be bound to a trail using the trail name. The attestation can be bound to an artifact in two ways:
- using the artifact’s SHA256 fingerprint which is calculated (based on the
--artifact-typeflag and the artifact name/path argument) or can be provided directly (with the--fingerprintflag). - using the artifact’s name in the flow yaml template and the git commit from which the artifact is/will be created. Useful when reporting an attestation before creating/reporting the artifact.
.kosli_ignore file to the root of the artifact.
Each line should specify a relative path or path glob to be ignored. You can include comments in this file, using #.
The .kosli_ignore will be treated as part of the artifact like any other file, unless it is explicitly ignored itself.
Flags
Flags inherited from parent commands
Examples Use Cases
These examples all assume that the flags--api-token, --org, --host, (and --flow, --trail when required), are set/provided.
report a Bitbucket pull request attestation about a pre-built docker artifact (kosli calculates the fingerprint)
report a Bitbucket pull request attestation about a pre-built docker artifact (kosli calculates the fingerprint)
report a Bitbucket pull request attestation about a pre-built docker artifact (you provide the fingerprint)
report a Bitbucket pull request attestation about a pre-built docker artifact (you provide the fingerprint)
report a Bitbucket pull request attestation about a trail
report a Bitbucket pull request attestation about a trail
report a Bitbucket pull request attestation about an artifact which has not been reported yet in a trail
report a Bitbucket pull request attestation about an artifact which has not been reported yet in a trail
report a Bitbucket pull request attestation about a trail with an attachment
report a Bitbucket pull request attestation about a trail with an attachment
fail if a pull request does not exist for your artifact
fail if a pull request does not exist for your artifact