Documentation
¶
Overview ¶
Package report writes findings in the formats forges read: SARIF 2.1.0, for GitHub code scanning (and GitLab Ultimate), and GitLab's Code Quality report, which every GitLab tier shows on a merge request. Both place a finding on a file and a line, so a finding whose `where` names no file of the repository (a commit's subject, a gate, a folder) is left out: it stays in the verdict and in --json.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func AppendSummary ¶ added in v0.17.0
AppendSummary adds the summary to each file, as GitHub's $GITHUB_STEP_SUMMARY is added to: a job that judges, then one that applies, write one page. A file named .html gets HTML, any other Markdown.
func CodeQuality ¶
CodeQuality writes the findings as a GitLab Code Quality report.
Types ¶
type Item ¶
Item is a finding with the role that made it and how its run ended.
type Summary ¶ added in v0.17.0
type Summary struct {
Title string // the command: "route merge-request", "apply"
Status, Text string
Steps []Step // a line's steps
Findings []verdict.Finding
Calls []stepCall
Notes [][2]string // the step, the agent's note
Reads [][2]string // the sample: each doc read, and its verdict
Map []string // an import's map: each item to its issue or its reason
Applied []string
Refused []string
Pending int // runs judged and not applied yet
NothingToApply bool
}
Summary is what a CI job's page shows a person, in Markdown: what ran, each step's verdict and findings, what the agent was asked, and what waits to be applied, with no log nor JSON to read. Every finding is there, those that name no file too.
func LineSummary ¶ added in v0.17.0
LineSummary is the summary of a line's run: each step with its findings, then the line's own (a routing that could not run).
func RoleSummary ¶ added in v0.17.0
RoleSummary is the summary of one role's run, or of runs applied.
func SampleSummary ¶ added in v0.17.0
SampleSummary is the summary of the weekly sample's read or write.