Skip to main content

Synopsis

Create or update a Kosli custom attestation type. You can specify attestation type parameters in flags. TYPE-NAME must start with a letter or number, and only contain letters, numbers, ., -, _, and ~. --schema is a path to a file containing a JSON schema which will be used to validate attestations made using this type.
The schema is used to specify the structure of the attestation data, e.g. any fields that are required or the expected type of the data. See an example schema file here.
--jq defines an evaluation rule, given in jq-format, for this attestation type. The flag can be repeated in order to add additional rules.
These rules specify acceptable values for attestation data, e.g. .age >= 21 or .failing_tests == 0.
When a custom attestation is reported, the provided data is evaluated according to the rules defined in its attestation-type. All rules must return true for the evaluation to pass and the attestation to be determined compliant.
--summary defines one entry of the summary shown for attestations of this type, given as 'NAME=EXPRESSION' where the expression is a jq expression evaluated against the attestation data. The flag can be repeated to add further entries, which are displayed in the order given, e.g. --summary "Critical=.critical_count" --summary "Tool=.scanner.name". Each value is split on its first = only, so jq expressions containing == are unaffected. --summary-json is an alternative to --summary for summaries that are easier to express as JSON, given as a JSON array of \{"name": ..., "expression": ...\} entries, e.g. '[\{"name":"Critical","expression":".critical_count"\}]'. The two summary flags cannot be combined. Attestation types created without a summary fall back to the jq evaluation rules checklist.

Flags

Flags inherited from parent commands

Live Examples in different CI systems

View an example of the kosli create attestation-type command in GitHub.In this YAML file

Examples Use Cases

These examples all assume that the flags --api-token, --org, --host, (and --flow, --trail when required), are set/provided.
Last modified on August 19, 2026