| target | Target object name format=[<image:tag>, <dir path>, <git url>] (Optional) | yes | — |
| all-evidence | Run all evidence verification | — | — |
| attest-config | Attestation config path | — | — |
| attest-default | Attestation default config, options=[sigstore sigstore-github x509 x509-env kms pubkey] | — | — |
| attestation | Attestation for target | — | — |
| base-image | Base image for the target | — | — |
| beautify | Enhance the output using ANSI and Unicode characters | — | — |
| bom | Create target SBOM evidence | — | — |
| bundle | Policy bundle uri/path (early-availability) | — | — |
| bundle-auth | Bundle repository authentication info, [format: 'username:password'] | — | — |
| bundle-branch | Bundle branch in the repository | — | — |
| bundle-commit | Bundle commit hash in the repository | — | — |
| bundle-depth | Bundle clone depth | — | — |
| bundle-tag | Bundle tag in the repository | — | — |
| ca | x509 CA Chain path | — | — |
| cert | x509 Cert path | — | — |
| common-name | Default policy allowed common names | — | — |
| crl | x509 CRL path | — | — |
| crl-full-chain | Enable Full chain CRL verfication | — | — |
| depth | Git clone depth | — | — |
| disable-crl | Disable certificate revocation verificatoin | — | — |
| email | Default policy allowed emails | — | — |
| exit-code | Exit code to use when policy violations occur (-1 = ignore and keep original status, 0 = succeed regardless, 1-255 = fail with that code) | — | — |
| filter-purl | Filter out purls by regex | — | — |
| filter-regex | Filter out files by regex | — | — |
| filter-scope | Filter packages by scope | — | — |
| force | Force skip cache | — | — |
| format | Policy Result Evidence format, options=[statement-sarif attest-sarif sarif ] | — | — |
| git-auth | Git repository authentication info, [format: 'username:password'] | — | — |
| git-branch | Git branch in the repository | — | — |
| git-commit | Git commit hash in the repository | — | — |
| git-tag | Git tag in the repository | — | — |
| initiative | Initiative configuration file path (early-availability) | — | — |
| initiative-id | Initiative id | — | — |
| initiative-name | Initiative name | — | — |
| input-format | Input Evidence format, options=[attest-cyclonedx-json attest-slsa statement-slsa statement-cyclonedx-json statement-generic attest-generic ] | — | — |
| key | x509 Private key path | — | — |
| kms | Provide KMS key reference | — | — |
| md | Output Initiative result markdown report file | — | — |
| oci | Enable OCI store | — | — |
| oci-repo | Select OCI custom attestation repo | — | — |
| pass | Private key password | — | — |
| payload | path of the decoded payload | — | — |
| platform | Select target platform, examples=windows/armv6, arm64 ..) | — | — |
| provenance | Create target SLSA Provenance evidence | — | — |
| pubkey | Public key path | — | — |
| public-key | Public key path | — | — |
| rule | Rule configuration file path (early-availability) | — | — |
| rule-args | Policy arguments | — | — |
| rule-label | Run only rules with specified label | — | — |
| skip-bundle | Skip bundle download | — | — |
| skip-confirmation | Skip Sigstore Confirmation | — | — |
| skip-report | Skip Policy report stage | — | — |
| source | SLSA Git repository source for target | — | — |
| source-asset-id | Source asset id for SLSA Git repository source | — | — |
| source-asset-name | Source asset name for SLSA Git repository source | — | — |
| source-asset-platform | Source asset platform for SLSA Git repository source | — | — |
| uri | Default policy allowed uris | — | — |
| cache-enable | Enable local cache | — | — |
| config | Configuration file path | — | — |
| deliverable | Mark as deliverable, options=[true, false] | — | — |
| env | Environment keys to include in evidence | — | — |
| gate-name | Policy Gate name | — | — |
| gate-type | Policy Gate type | — | — |
| input | Input Evidence target, format (\<parser>:\<file> or \<scheme>:\<name>:\<tag>) | — | — |
| label | Add Custom labels | — | — |
| level | Log depth level, options=[panic fatal error warning info debug trace] | — | — |
| log-context | Attach context to all logs | — | — |
| log-file | Output log to file | — | — |
| output-directory | Output directory path | — | ./scribe/valint |
| output-file | Output file name | — | — |
| pipeline-name | Pipeline name | — | — |
| predicate-type | Custom Predicate type (generic evidence format) | — | — |
| product-key | Product Key | — | — |
| product-version | Product Version | — | — |
| scribe-client-id | Scribe Client ID (deprecated) | — | — |
| scribe-client-secret | Scribe Client Token | — | — |
| scribe-disable | Disable scribe client | — | — |
| scribe-enable | Enable scribe client (deprecated) | — | — |
| scribe-url | Scribe API Url | — | — |
| structured | Enable structured logger | — | — |
| timeout | Timeout duration | — | — |
| verbose | Log verbosity level [-v,--verbose=1] = info, [-vv,--verbose=2] = debug | — | — |