Submit a signed CI attestation manifest
Accepts a manifest signed by the tenant’s HMAC key. The signature is verified, the manifest stored as the latest for (tenant, repoId), and a drift analysis is computed vs the previous manifest. Drift includes new ungated sites, resolved sites, policy hash changes, and scanner version changes.
Request
This endpoint expects an object.
repoId
manifest
{repoId, commitSha, scannerVersion, findings, ungatedSites, policyFileHash, timestamp}
signature
HMAC-SHA256 hex signature
Response
Signature verification failed.
ok
reason