Skip to content

Installation and CLI

Wakemeup edited this page Aug 25, 2026 · 2 revisions

Installation and CLI

Requirements

  • Rust 1.90 or newer.
  • A writable SQLite path when history, API, or monitoring is used.
  • Network access to the configured OSV endpoint unless offline mode is enabled.
git clone https://github.com/openhoo/hooray.git
cd hooray
cargo build --release --locked
./target/release/hooray --help

Scanning

Every scan requires an explicit input kind and input path:

hooray scan project . --policy hooray-policy.yaml --format table
hooray scan sbom bom.json --format sarif --output hooray.sarif
hooray scan artifact release.zip --format json --output report.json
hooray scan container oci-layout/ --format cyclone-dx-vex --output vex.json
hooray scan auto input.tar --format yaml

Kinds:

  • project: supported manifests and lockfiles in a directory.
  • sbom: CycloneDX JSON or SPDX 2.x JSON detected by its spdxVersion key.
  • artifact: bounded ZIP or TAR input.
  • container: OCI layout or OCI/Docker image archive.
  • auto: bounded input detection.

Shared scan options include --config FILE, --policy FILE, --baseline RUN_ID, --new-findings-only, --format FORMAT, and --output FILE. - writes output to stdout.

Policy

hooray policy validate hooray-policy.yaml
hooray policy evaluate hooray-policy.yaml --run-id 'run:UUID' --format yaml

Inventory and history

hooray inventory --run-id 'run:UUID' --format json
hooray history list
hooray history show 'run:UUID'
hooray history diff 'run:new' 'run:baseline'
hooray report 'run:UUID' --format html --output report.html

API and monitoring

hooray serve
hooray serve --once
hooray monitor
hooray monitor --once
hooray monitor targets add webapp --source ./webapp --interval-seconds 300
hooray monitor targets list
hooray monitor targets remove webapp
hooray monitor --once --webhook-url https://hooks.example/hooray --webhook-secret-env HOORAY_WEBHOOK_SECRET

serve uses the configured bind address, authentication, limits, database, policy, and OSV settings. monitor --once executes one due cycle; continuous mode keeps polling and applies bounded backoff after transient failures.

monitor targets add TARGET_ID --source SOURCE --interval-seconds SECONDS registers a target so future cycles watch it; list paginates registered targets; remove deletes a target together with its queued events. Passing --webhook-url together with --webhook-secret-env switches alert delivery from standard error to an HTTPS-only webhook signed with the shared integration HMAC scheme; the secret comes from the named environment variable and the two flags are required as a pair.

Integration templates

hooray integrations generate pre-commit
hooray integrations generate github-actions
hooray integrations generate gitlab-ci
hooray integrations generate gitlab-security

Generated commands use hooray scan project .. The repository also publishes .pre-commit-hooks.yaml with hook ID hooray.

Exit behavior

Command-line syntax and invalid configuration fail before scanning. Operational failures and policy-denial outcomes use distinct stable exit behavior so CI can distinguish scanner failure from an intentional release gate.

Clone this wiki locally