spec: 001 Project and Organization from .chainloop.yml in Attestations - #3496
Conversation
Add a design spec for reading projectName and organization from .chainloop.yml in the attestation commands, and initialize docs/specs. Refs #3063 Assisted-by: Claude Code Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev> Chainloop-Trace-Sessions: d332cce4-e405-417d-b4de-1fbb0730319a
AI Session Checks — 🟢 90% ·
|
| Avg score | Sessions | Failing policies | Attribution | Files | Lines | Total Duration |
|---|---|---|---|---|---|---|
| 🟢 90% | 1 | 100% AI / 0% Human | 3 | +149 / -9 | 23m22s |
🟢 90% — 100% AI — ⚠️ 1 policies failing
-
Sep 29, 2026 21:54 UTC · 23m22s · $6.46 · 228 in / 77.0k out · claude-code 2.1.285 (claude-opus-5-5)
Change Summary
-
- Adds
docs/specs/001-attestation-repo-config.mdfor attestation init to readprojectNameandorganizationfrom.chainloop.yml. - Initializes
docs/specs/README.mdand repo guidance inCLAUDE.mdfor future spec work. - Revises the spec to define
--orgprecedence and API-token organization mismatch handling.
- Adds
AI Session Overall Score
-
🟢 90% — Well-framed spec session stayed aligned and tightly scoped; runtime checks were not applicable.
AI Session Analysis Breakdown
-
🟢 93% · scope-discipline
-
🟢 The recorded commits stayed on the spec and its expected init files. · High Impact
🟢 91% · alignment
-
🟢 The AI folded the later
--orgrequirement into the same spec. · High Impact
🟢 88% · context-and-planning
-
🟢 Detailed eng-spec instructions grounded the drafting before edits began. · High Impact
🟢 86% · user-trust-signal
-
No notes.
abstained · solution-quality
-
🟡 Solution quality was not assessed because the PR is spec-only and ships no implementation. · Low Severity
abstained · verification
-
🟡 Verification was not assessed because the PR changes docs and guidance, not runtime behavior. · Low Severity
-
File Attribution
████████████████████100% AI / 0% HumanStatus Attribution File Lines modified ai docs/specs/001-attestation-repo-config.md+144 / -9 modified ai CLAUDE.md+4 / -0 created ai docs/specs/README.md+1 / -0
Policies (4, 1 failing)
Status Policy Material Messages ✅ Passed ai-config-no-dangerous-commandsai-coding-session-d332cc- ✅ Passed ai-config-ai-agents-allowedai-coding-session-d332cc- ⚠️ Failedai-config-no-secretsai-coding-session-d332ccSecret (generic-password) detected in session content [turn=347, source=tool_result, line=6]: INF redacted secrets from the AI coding session before upload count=10 rules=["generic-[REDACTED:generic-password]"] ✅ Passed ai-config-mcp-servers-allowedai-coding-session-d332cc- -
Security Checks — ✅ 5 passing
✅ secret-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | secrets-detection |
- |
✅ sast-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | owasp-top10-2025 |
- |
| ✅ Passed | sast |
- |
| ✅ Passed | cwe-top25 |
- |
| ✅ Passed | cwe-top26-40-cusp |
- |
✅ security-context — no advisories
Nothing this change touches has a recorded security-fix history.
View security context ↗ · Security context documentation ↗
⏭️ 3 scans not applied
| Scan | Reason |
|---|---|
vulnerability-scan |
no manifest/lockfile changed |
github-actions-scan |
no workflow files changed |
iac-scan |
no IaC files changed |
PR validation — ✅ 3 passing
| Status | Policy | Material | Messages |
|---|---|---|---|
| ✅ Passed | pr-min-approvals |
pr-info |
- |
| ✅ Passed | pr-description-required |
pr-info |
- |
| ✅ Passed | pr-user-story-linked |
pr-info |
- |
Powered by Chainloop and Chainloop Trace
There was a problem hiding this comment.
All reported issues were addressed across 3 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
The organization in .chainloop.yml now has the same effect as --org, plus the mismatch check for API tokens. Refs #3063 Assisted-by: Claude Code Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev> Chainloop-Trace-Sessions: d332cce4-e405-417d-b4de-1fbb0730319a
There was a problem hiding this comment.
All reported issues were addressed across 1 file (changes from recent commits).
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com> Signed-off-by: Miguel Martinez Trivino <migmartri@gmail.com>
Summary
This PR adds a design spec. It adds no code. The spec proposes that the attestation commands read
projectNameandorganizationfrom.chainloop.yml. These are the keys thatchainloop trace initalready writes. Today the attestation commands read onlyprojectVersionfrom the file. With this change, a repository owner can pin the project and the organization for all attestations from the repository. Flags and environment variables continue to take precedence over the file.The spec also defines one way to find and read the file for the attestation and trace commands. It also fixes a gap:
attestation initskips some flag checks when the file is missing.This PR also initializes
docs/specs/and adds a short section about specs toCLAUDE.md.The spec takes a different approach from PR #3065. It keeps the key name
projectNamefrom trace, and it keeps the project required (decisions D-001 and D-003).Questions for reviewers
The spec has no open questions. Please challenge the decisions in the Decision Record, mainly these:
init.Refs #3063
AI disclosure: Claude Code helped to write this spec.
🤖 Posted by Maximus bot (Claude Code) on behalf of @migmartri