report

package
v0.22.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: MIT Imports: 17 Imported by: 0

Documentation

Overview

Package report writes findings in the formats forges read: SARIF 2.1.0, for GitHub code scanning (and GitLab Ultimate), and GitLab's Code Quality report, which every GitLab tier shows on a merge request. Both place a finding on a file and a line, so a finding whose `where` names no file of the repository (a commit's subject, a gate, a folder) is left out: it stays in the verdict and in --json.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func AppendSummary added in v0.17.0

func AppendSummary(files []string, s Summary) error

AppendSummary adds the summary to each file, as GitHub's $GITHUB_STEP_SUMMARY is added to: a job that judges, then one that applies, write one page. A file named .html gets HTML, any other Markdown.

func CodeQuality

func CodeQuality(repo string, items []Item) ([]byte, error)

CodeQuality writes the findings as a GitLab Code Quality report.

func SARIF

func SARIF(repo string, items []Item) ([]byte, error)

SARIF writes the findings as one SARIF 2.1.0 run of the tool "workline", each rule named <role>/<rule>.

func Write

func Write(repo string, items []Item, sarifFile, codeQualityFile string) error

Write writes the reports asked for; an empty file name skips that one.

Types

type Item

type Item struct {
	Role, Status string
	verdict.Finding
}

Item is a finding with the role that made it and how its run ended.

func FromLine

func FromLine(r *line.Result) []Item

FromLine lists the findings of every step of a line.

func FromRole

func FromRole(role string, r *engine.Result) []Item

FromRole lists the findings of one role's run.

type Step added in v0.17.0

type Step struct {
	Name, Status, Text string
	Findings           []verdict.Finding
}

Step is one step of a line: its verdict, and the findings it made.

type Summary added in v0.17.0

type Summary struct {
	Title          string // the command: "route merge-request", "apply"
	Status, Text   string
	Steps          []Step // a line's steps
	Findings       []verdict.Finding
	Calls          []stepCall
	Notes          [][2]string // the step, the agent's note
	Reads          [][2]string // the sample: each doc read, and its verdict
	Map            []string    // an import's map: each item to its issue or its reason
	Applied        []string
	Refused        []string
	Pending        int // runs judged and not applied yet
	NothingToApply bool
}

Summary is what a CI job's page shows a person, in Markdown: what ran, each step's verdict and findings, what the agent was asked, and what waits to be applied, with no log nor JSON to read. Every finding is there, those that name no file too.

func LineSummary added in v0.17.0

func LineSummary(title string, r *line.Result) Summary

LineSummary is the summary of a line's run: each step with its findings, then the line's own (a routing that could not run).

func RoleSummary added in v0.17.0

func RoleSummary(title, role string, r *engine.Result) Summary

RoleSummary is the summary of one role's run, or of runs applied.

func SampleSummary added in v0.17.0

func SampleSummary(title string, r *sample.Result) Summary

SampleSummary is the summary of the weekly sample's read or write.

func (Summary) HTML added in v0.17.0

func (s Summary) HTML() string

HTML renders the summary's Markdown as a page a browser shows, for a CI that shows an HTML file and no Markdown one: GitLab previews a job's HTML artifact (with Pages), not its Markdown. Every text is escaped first.

func (Summary) Markdown added in v0.17.0

func (s Summary) Markdown() string

Markdown renders the summary as GitHub's job summary and GitLab's Markdown both show it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL