Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

Artifacts

An Artifact is one immutable content object addressed by digest: an image, or evidence about one (an SBOM, a provenance attestation, a…

This method is not served on the public API. api.sylphx.com does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

An Artifact is one immutable content object addressed by digest: an image, or evidence about one (an SBOM, a provenance attestation, a signature) that names it as its subject.

Service Sylphx Artifacts · Resource type artifacts.sylphx.com/Artifact · Name pattern orgs/{org}/projects/{project}/artifacts/{artifact} · Shape record

Not available yet. Sylphx Artifacts is declared in the registry but no backend serves it: every call answers 501 with the problem code UNIMPLEMENTED.

#Fields

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/artifacts/{artifact}, where {artifact} is the digest with - for :, for example sha256-4f1c….
uidstringart_<cell><ulid>. Output only.
metaResourceMetaResource metadata.
digeststringThe algorithm-qualified digest of the stored bytes, for example sha256:4f1c…. Required.
kindArtifactKindWhat the Artifact is. Required. One of image, sbom, provenance, signature, bundle.
media_typestringThe media type, for example application/vnd.oci.image.manifest.v1+json. Required.
size_bytesint64The size of the stored bytes. Required.
subjectstringThe Artifact this one describes, for an SBOM, provenance, or signature.
source_digestsstring[]Digests of the sources and inputs that produced it.
builderstringThe builder identity (a SPIFFE id) that produced it. Output only.
sbomstringThe newest SBOM whose subject is this Artifact. Output only.
provenancestringThe newest provenance attestation whose subject is this Artifact. Output only.
verification_stateVerificationStateWhether the signature and provenance verified. Evidence, never identity: a failure does not change the digest. Output only. One of unverified, pending, verified, failed.
verify_timetimestampWhen verification last ran. Output only.
retentionRetentionClassHow long the Artifact is kept. One of standard, referenced.
legal_holdboolA legal hold is active; Delete fails. Output only.
regionsstring[]The regions the bytes are replicated to. Output only.
referencestringThe OCI reference by digest to pull, for example registry.sylphx.com/<project>@sha256:4f1c…. Output only.

#Methods

Every method of the collection, in the registry's order, with the scope it needs. The full request, response and examples are one link away.

MethodCallWhat it does
GETgetGets an artifact.
GETlistLists a project's artifacts; filter by digest, kind, or subject.
POSTcreateRegisters an artifact whose bytes were pushed by digest; verification runs after.
DELETEdeleteDeletes an artifact; fails while a Release references it or a legal hold is active.

#get

Gets an artifact.

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/artifacts/artifact · scope artifacts:read · effect read · not available yet · Request, response and examples

#list

Lists a project's artifacts; filter by digest, kind, or subject.

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/artifacts · scope artifacts:read · effect read · not available yet · paginated · Request, response and examples

#create

Registers an artifact whose bytes were pushed by digest; verification runs after.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/artifacts · scope artifacts:write · effect write · not available yet · Request, response and examples

#delete

Deletes an artifact; fails while a Release references it or a legal hold is active.

DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/artifacts/artifact · scope artifacts:write · effect destructive · not available yet · Request, response and examples