Repository navigation
Installation and CLI
- Rust 1.90 or newer.
- A writable SQLite path when history, API, or monitoring is used.
- Network access to the configured OSV endpoint unless offline mode is enabled.
git clone https://github.com/openhoo/hooray.git
cd hooray
cargo build --release --locked
./target/release/hooray --helpEvery scan requires an explicit input kind and input path:
hooray scan project . --policy hooray-policy.yaml --format table
hooray scan sbom bom.json --format sarif --output hooray.sarif
hooray scan artifact release.zip --format json --output report.json
hooray scan container oci-layout/ --format cyclone-dx-vex --output vex.json
hooray scan auto input.tar --format yamlKinds:
-
project: supported manifests and lockfiles in a directory. -
sbom: CycloneDX JSON or SPDX 2.x JSON detected by itsspdxVersionkey. -
artifact: bounded ZIP or TAR input. -
container: OCI layout or OCI/Docker image archive. -
auto: bounded input detection.
Shared scan options include --config FILE, --policy FILE, --baseline RUN_ID, --new-findings-only, --format FORMAT, and --output FILE. - writes output to stdout.
hooray policy validate hooray-policy.yaml
hooray policy evaluate hooray-policy.yaml --run-id 'run:UUID' --format yamlhooray inventory --run-id 'run:UUID' --format json
hooray history list
hooray history show 'run:UUID'
hooray history diff 'run:new' 'run:baseline'
hooray report 'run:UUID' --format html --output report.htmlhooray serve
hooray serve --once
hooray monitor
hooray monitor --once
hooray monitor targets add webapp --source ./webapp --interval-seconds 300
hooray monitor targets list
hooray monitor targets remove webapp
hooray monitor --once --webhook-url https://hooks.example/hooray --webhook-secret-env HOORAY_WEBHOOK_SECRETserve uses the configured bind address, authentication, limits, database, policy, and OSV settings. monitor --once executes one due cycle; continuous mode keeps polling and applies bounded backoff after transient failures.
monitor targets add TARGET_ID --source SOURCE --interval-seconds SECONDS registers a target so future cycles watch it; list paginates registered targets; remove deletes a target together with its queued events. Passing --webhook-url together with --webhook-secret-env switches alert delivery from standard error to an HTTPS-only webhook signed with the shared integration HMAC scheme; the secret comes from the named environment variable and the two flags are required as a pair.
hooray integrations generate pre-commit
hooray integrations generate github-actions
hooray integrations generate gitlab-ci
hooray integrations generate gitlab-securityGenerated commands use hooray scan project .. The repository also publishes .pre-commit-hooks.yaml with hook ID hooray.
Command-line syntax and invalid configuration fail before scanning. Operational failures and policy-denial outcomes use distinct stable exit behavior so CI can distinguish scanner failure from an intentional release gate.