Skip to navigation

Submit a signed CI attestation manifest

Accepts a manifest signed by the tenant’s HMAC key. The signature is verified, the manifest stored as the latest for (tenant, repoId), and a drift analysis is computed vs the previous manifest. Drift includes new ungated sites, resolved sites, policy hash changes, and scanner version changes.

Request

This endpoint expects an object.
repoIdstringRequired
manifestobjectRequired
{repoId, commitSha, scannerVersion, findings, ungatedSites, policyFileHash, timestamp}
signaturestringRequired

HMAC-SHA256 hex signature

Response

Signature verification failed.
okbooleanOptional
reasonstringOptional