report

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 12 Imported by: 0

Documentation

Overview

Package report builds the scan report model and renders it as a terminal table, JSON or Markdown.

Index

Constants

View Source
const (
	ResultPass        = "pass"
	ResultFail        = "fail"
	ResultNoThreshold = "no_threshold"
)

Result values of a scan with respect to --fail-on.

View Source
const DefaultWidth = 100

DefaultWidth is the line width the table renderer wraps text to.

View Source
const SchemaVersion = "1.0.0"

SchemaVersion is the version of the JSON report schema. It follows semantic versioning: additive changes bump the minor version, breaking changes the major version.

Variables

This section is empty.

Functions

func EscapeMarkdown

func EscapeMarkdown(s string) string

EscapeMarkdown escapes characters that Markdown would interpret, so that free text renders literally.

func Redact

func Redact(r *Report, values []string, mask string)

Redact replaces every occurrence of the given sensitive values in all report text derived from the scanned configuration with mask. It is a defense in depth: rules are written never to include secret values in the first place. Constant rule texts (title, why it matters) are left intact.

func Render

func Render(w io.Writer, r *Report, opts RenderOptions) error

Render writes the report in the requested format.

func RenderJSON

func RenderJSON(w io.Writer, r *Report) error

RenderJSON writes the report as indented JSON followed by a newline. The structure is documented in docs/json-report.md and docs/report.schema.json.

func RenderMarkdown

func RenderMarkdown(w io.Writer, r *Report) error

RenderMarkdown writes a self-contained Markdown report suitable for issues, change requests and audit documentation.

func RenderTable

func RenderTable(w io.Writer, r *Report, opts TableOptions) error

RenderTable writes the human-readable terminal report.

func WriteFile

func WriteFile(path string, r *Report, opts RenderOptions) (err error)

WriteFile renders the report and writes it to path atomically: the content is written to a temporary file in the same directory and renamed into place, so readers never observe a partially written report. The file is created with mode 0600 because reports describe infrastructure details.

Types

type ComposeTarget

type ComposeTarget struct {
	Files        []string `json:"files"`
	ProjectName  string   `json:"project_name"`
	ServiceCount int      `json:"service_count"`
	Services     []string `json:"services"`
}

ComposeTarget holds metadata about a scanned Compose project.

type Format

type Format string

Format is an output format.

const (
	FormatTable    Format = "table"
	FormatJSON     Format = "json"
	FormatMarkdown Format = "markdown"
)

Supported formats.

func ParseFormat

func ParseFormat(s string) (Format, error)

ParseFormat validates a user supplied format name.

type HostTarget

type HostTarget struct {
	Endpoint          string `json:"endpoint"`
	ServerVersion     string `json:"server_version"`
	APIVersion        string `json:"api_version"`
	OperatingSystem   string `json:"operating_system"`
	OSType            string `json:"os_type"`
	Architecture      string `json:"architecture"`
	ContainersTotal   int    `json:"containers_total"`
	ContainersRunning int    `json:"containers_running"`
	Images            int    `json:"images"`
}

HostTarget holds metadata about a scanned Docker host.

type Input

type Input struct {
	Scanner      Scanner
	ScanType     ScanType
	StartedAt    time.Time
	FinishedAt   time.Time
	RulesTotal   int
	Result       engine.Result
	SkippedRules []engine.SkippedRule
	Target       Target
	Limitations  []string
	Warnings     []string
	MinSeverity  findings.Severity
	FailOn       *findings.Severity
	Only         []string
	Exclude      []string
}

Input collects everything needed to build a report.

type Options

type Options struct {
	MinSeverity findings.Severity  `json:"min_severity"`
	FailOn      *findings.Severity `json:"fail_on"`
	Only        []string           `json:"only"`
	Exclude     []string           `json:"exclude"`
}

Options records the user options that influenced the report.

type RenderOptions

type RenderOptions struct {
	Format Format
	Table  TableOptions
}

RenderOptions controls rendering for all formats.

type Report

type Report struct {
	SchemaVersion string                     `json:"schema_version"`
	Scanner       Scanner                    `json:"scanner"`
	Scan          Scan                       `json:"scan"`
	Target        Target                     `json:"target"`
	Summary       Summary                    `json:"summary"`
	Findings      []findings.Finding         `json:"findings"`
	Suppressed    []engine.SuppressedFinding `json:"suppressed_findings"`
	SkippedRules  []engine.SkippedRule       `json:"skipped_rules"`
	Limitations   []string                   `json:"limitations"`
	Warnings      []string                   `json:"warnings"`
}

Report is the complete, renderer-independent result of a scan.

func Build

func Build(in Input) *Report

Build assembles a report. --severity only affects which findings are displayed; --fail-on is evaluated against all findings so that the exit code does not depend on presentation options.

func (*Report) Failed

func (r *Report) Failed() bool

Failed reports whether the --fail-on threshold was met.

type Scan

type Scan struct {
	Type           ScanType  `json:"type"`
	StartedAt      time.Time `json:"started_at"`
	FinishedAt     time.Time `json:"finished_at"`
	RulesTotal     int       `json:"rules_total"`
	RulesEvaluated int       `json:"rules_evaluated"`
	Options        Options   `json:"options"`
}

Scan holds scan metadata.

type ScanType

type ScanType string

ScanType identifies the kind of scan.

const (
	ScanCompose ScanType = "compose"
	ScanHost    ScanType = "host"
)

Scan types.

type Scanner

type Scanner struct {
	Name    string `json:"name"`
	Version string `json:"version"`
	Commit  string `json:"commit,omitempty"`
}

Scanner identifies the tool that produced the report.

type Summary

type Summary struct {
	// Total counts all findings produced by the evaluated rules, including
	// findings hidden from the report by --severity.
	Total      int             `json:"total"`
	BySeverity findings.Counts `json:"by_severity"`
	Displayed  int             `json:"displayed"`
	// HiddenBelowMinSeverity counts findings omitted by --severity.
	HiddenBelowMinSeverity int `json:"hidden_below_min_severity"`
	// Suppressed counts findings matched by x-stacksentry exceptions; they
	// are not part of Total and never trigger --fail-on.
	Suppressed int `json:"suppressed"`
	// FailOn is the --fail-on threshold, if any.
	FailOn *findings.Severity `json:"fail_on"`
	// AtOrAboveFailOn counts findings that meet the threshold, including
	// findings hidden by --severity.
	AtOrAboveFailOn int    `json:"at_or_above_fail_on"`
	Result          string `json:"result"`
}

Summary aggregates the findings of a scan.

type TableOptions

type TableOptions struct {
	// Color enables ANSI colors. Callers enable it only for terminals.
	Color bool
	// Quiet prints only the findings, without header, notes or result.
	Quiet bool
	// Width is the wrapping width; DefaultWidth is used when zero.
	Width int
}

TableOptions controls terminal rendering.

type Target

type Target struct {
	Type    ScanType       `json:"type"`
	Name    string         `json:"name"`
	Compose *ComposeTarget `json:"compose,omitempty"`
	Host    *HostTarget    `json:"host,omitempty"`
}

Target describes what was scanned.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL