Skip to main content

apiome lint

Global options such as --base-url, --tenant and --json go before the command — see CLI reference. Exit codes are listed in Exit codes.

apiome lint​

Score schema quality, list lint findings, and run the CI lint gate.

apiome lint [OPTIONS] COMMAND [ARGS]...

Subcommands: evidence, gate, verify-attestation.

Options

OptionTypeDefaultRequiredDescription
--projecttextProject UUID or slug.
--versiontextVersion UUID, slug, or label.
--base-versiontextOptional base version (UUID, slug, or label) to flag breaking changes against.
--min-gradetextExit non-zero when the grade is worse than this (A best, F worst).
--fail-on-policyflagFetch lint policy evaluation and exit non-zero when policy gates fail.

apiome lint evidence​

List the immutable lint evidence runs for a version (GET .../lint/evidence).

Emits the full JSON evidence payload: one run per scanner execution with provenance fingerprints, outcome, coverage, and normalized findings.

apiome lint evidence [OPTIONS]

Options

OptionTypeDefaultRequiredDescription
--projecttextyesProject UUID or slug.
--versiontextyesVersion UUID, slug, or label.

apiome lint gate​

Run the lint CI gate for a version (GET .../lint/gate) and emit an artifact.

Exits non-zero ONLY when a configured policy gate failed (gate.passed false in the verdict) — findings without policy failures, or failures of gates the pack disabled, exit 0. The verdict is always fetched as JSON; a non-json --format additionally fetches that artifact and writes it to --output (or stdout, with the human summary moved to stderr so the artifact stays clean).

apiome lint gate [OPTIONS]

Options

OptionTypeDefaultRequiredDescription
--projecttextyesProject UUID or slug.
--versiontextyesVersion UUID, slug, or label.
--base-versiontextOptional baseline version (UUID, slug, or label) to diff regressions against; without it, each scanner's latest run is compared to its own previous run.
--policy-versiontextOptional historical policy pack id (defaults to the latest for the assigned guide).
--new-onlyflagGate only newly introduced violations: pre-existing unwaived errors do not fail; coverage and axis gates still evaluate the full revision.
--formattextjsonArtifact format: json | sarif | junit | markdown | attestation.
--output, -opathWrite the artifact to this file (non-json formats print to stdout otherwise).

apiome lint verify-attestation​

Verify a lint gate attestation offline (no server round-trip).

Recomputes the DSSE PAEv1 HMAC-SHA256 signature with the shared secret and compares it against the envelope's signatures. Exits 0 when verified, non-zero otherwise.

apiome lint verify-attestation [OPTIONS]

Options

OptionTypeDefaultRequiredDescription
--file, -fpathyesPath to the attestation envelope JSON (from --format attestation).
--secret, -stextyesShared HMAC secret (server: APIOME_LINT_ATTESTATION_SIGNING_SECRET). Env: APIOME_LINT_ATTESTATION_SECRET.