question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Output Results in SARIF Format

See original GitHub issue

Is your feature request related to a problem? Please describe. It would be great, given Github and potential Gitlab integration amongst other tools, it would be great if, aside checkov’s JSON support, it outputted SARIF.

Describe the solution you’d like An additional output parameter supporting SARIF.

Describe alternatives you’ve considered The alternative is continuing to use the JSON output of checkov and other tools. This is acceptable, but in the long-term standard output formats improve the chances of adoption, especially if Github and other source code repositories are accepting this format. As checkov supports static analysis of many different IaC formats, this would alleviate a lot of repeat busywork on data-mapping utilities, probably not just among my colleagues. 😃

Additional context My colleagues increasingly integrate with a variety of tools supporting SARIF import, not just Gitlab, and many other tools in this space are adopting this format for re-usability of exported findings. I feel this would further justify the value of your already amazing tool and reduce friction, thanks!

Issue Analytics

  • State:closed
  • Created 3 years ago
  • Reactions:4
  • Comments:6 (1 by maintainers)

github_iconTop GitHub Comments

2reactions
schosterbarakcommented, Jul 29, 2021

done thanks to @ne0z 😃

2reactions
fabasoadcommented, Feb 1, 2021

+1 for this feature.

Read more comments on GitHub >

github_iconTop Results From Across the Web

SARIF output - CodeQL - GitHub
CodeQL supports SARIF as an output format for sharing static analysis results. SARIF is designed to represent the output of a broad range...
Read more >
SARIF output | Qodana Documentation
Qodana reports are formatted according to the SARIF specification and are contained in a JSON file. The Qodana implementation of SARIF ...
Read more >
SARIF Home
The Static Analysis Results Interchange Format (SARIF) is an industry standard format for the output of static analysis tools.
Read more >
Outputting the test results to a JSON or SARIF format in ...
You can output the CLI Code test results to a JSON or SARIF format in the terminal, instead of displaying the results in...
Read more >
Static Analysis Results Interchange Format (SARIF ...
This document defines a standard format for the output of static analysis tools, called the Static Analysis Results Interchange Format, or “SARIF”[1]. The...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found