apiome lint
Global options such as --base-url, --tenant and --json go before the command — see CLI reference. Exit codes are listed in Exit codes.
apiome lint
Score schema quality, list lint findings, and run the CI lint gate.
apiome lint [OPTIONS] COMMAND [ARGS]...
Subcommands: evidence, gate, verify-attestation.
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--project | text | Project UUID or slug. | ||
--version | text | Version UUID, slug, or label. | ||
--base-version | text | Optional base version (UUID, slug, or label) to flag breaking changes against. | ||
--min-grade | text | Exit non-zero when the grade is worse than this (A best, F worst). | ||
--fail-on-policy | flag | Fetch lint policy evaluation and exit non-zero when policy gates fail. |
apiome lint evidence
List the immutable lint evidence runs for a version (GET .../lint/evidence).
Emits the full JSON evidence payload: one run per scanner execution with provenance fingerprints, outcome, coverage, and normalized findings.
apiome lint evidence [OPTIONS]
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--project | text | yes | Project UUID or slug. | |
--version | text | yes | Version UUID, slug, or label. |
apiome lint gate
Run the lint CI gate for a version (GET .../lint/gate) and emit an artifact.
Exits non-zero ONLY when a configured policy gate failed (gate.passed false in the verdict) — findings without policy failures, or failures of gates the pack disabled, exit 0. The verdict is always fetched as JSON; a non-json --format additionally fetches that artifact and writes it to --output (or stdout, with the human summary moved to stderr so the artifact stays clean).
apiome lint gate [OPTIONS]
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--project | text | yes | Project UUID or slug. | |
--version | text | yes | Version UUID, slug, or label. | |
--base-version | text | Optional baseline version (UUID, slug, or label) to diff regressions against; without it, each scanner's latest run is compared to its own previous run. | ||
--policy-version | text | Optional historical policy pack id (defaults to the latest for the assigned guide). | ||
--new-only | flag | Gate only newly introduced violations: pre-existing unwaived errors do not fail; coverage and axis gates still evaluate the full revision. | ||
--format | text | json | Artifact format: json | sarif | junit | markdown | attestation. | |
--output, -o | path | Write the artifact to this file (non-json formats print to stdout otherwise). |
apiome lint verify-attestation
Verify a lint gate attestation offline (no server round-trip).
Recomputes the DSSE PAEv1 HMAC-SHA256 signature with the shared secret and compares it against the envelope's signatures. Exits 0 when verified, non-zero otherwise.
apiome lint verify-attestation [OPTIONS]
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--file, -f | path | yes | Path to the attestation envelope JSON (from --format attestation). | |
--secret, -s | text | yes | Shared HMAC secret (server: APIOME_LINT_ATTESTATION_SIGNING_SECRET). Env: APIOME_LINT_ATTESTATION_SECRET. |