Skip to content

feat(cli): use repository config for attestations - #3502

Draft
waveywaves wants to merge 1 commit into
chainloop-dev:mainfrom
waveywaves:feat/attestation-repo-config
Draft

waveywaves wants to merge 1 commit into
chainloop-dev:mainfrom
waveywaves:feat/attestation-repo-config

Conversation

@waveywaves

@waveywaves waveywaves commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

This PR starts the implementation of Spec 001: Project and Organization from .chainloop.yml in Attestations. It covers R-007 and R-008. The complete implementation is tracked in #3504.

Summary

  • The attestation and trace commands now use one repository-config reader. It searches from the current directory to the Git repository root, prefers .chainloop.yml over .chainloop.yaml, accepts files without projectName, and returns the selected path (R-007).
  • The existing trace config helpers use the shared reader instead of implementing their own file selection.
  • attestation init reads projectVersion through the shared reader and continues normal flag validation when the config is missing or cannot be read (R-008).

Requirements covered

  • R-007: One way to find the file
  • R-008: Flag checks without a file

The remaining requirements and every implementation PR are tracked in #3504.

Refs #3063

AI assistance

pi helped to write this change. The commit carries an Assisted-by: pi trailer.

Use the existing Chainloop Trace config reader for attestation version loading
and keep init flag validation running when the config is unavailable.

Refs: chainloop-dev#3063

Assisted-by: pi
Signed-off-by: Vibhav Bobade <[email protected]>
@chainloop-platform

Copy link
Copy Markdown
Contributor

AI Session Checks — ⚠️ no AI session found

Missing AI Coding Sessions

This organization requires every PR to be backed by a Chainloop Trace AI coding session, and none was found for this one.

Please make sure the AI coding session evidence has been sent by the Chainloop CLI, or add the skip-ai-session label to this PR to bypass this check.

Learn more about Chainloop Trace.


Powered by Chainloop and Chainloop Trace

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant