Repository navigation
Reports and Integrations
The CLI accepts:
jsonyamltablesarifjunithtmlcyclone-dx-vexspdxgitlab-code-qualityjson-linescsvgitlab-sarifgitlab-cyclonedxgitlab-artifacts
hooray scan project . --format sarif --output hooray.sarif
hooray report 'run:UUID' --format html --output hooray.htmlCanonical reports use format version 1.0.0 and embed the native scan schema version. Output is deterministic, UTF-8, redacted, validated, and capped at 64 MiB while rendering rather than after an unbounded allocation.
- SARIF 2.1.0 for code-scanning ingestion.
- JUnit XML for test-report surfaces.
- Self-contained CSP-hardened HTML.
- CycloneDX 1.6 VEX with applicability analysis.
- SPDX 2.3 JSON with deterministic collision-resistant SPDX element IDs.
- GitLab Code Quality JSON.
- JSON Lines for streaming one canonical finding per line.
- RFC 4180 CSV with fixed finding-row columns from
stable_finding_idthroughfirst_location_path.
GitLab-specific values feed Code Quality, SARIF security ingestion, and CycloneDX dependency ingestion; gitlab-artifacts publishes all five GitLab artifacts as one atomic directory bundle.
hooray integrations generate pre-commit
hooray integrations generate github-actions
hooray integrations generate gitlab-ciGenerated templates invoke the current clean-cut CLI (hooray scan project .) and only supported format values. The pre-commit repository hook is declared in .pre-commit-hooks.yaml.
The library can produce bounded payloads for GitHub checks, GitLab Code Quality, Slack, VS Code/LSP diagnostics, pull-request gates, and Jira create-issue payloads with escaped wiki markup and capped finding lists. New denied findings can block a PR without treating unchanged historical findings as new.
Signed webhooks require HTTPS destinations, bounded event names and payloads, and a secret between 16 and 4096 bytes. Signatures are deterministic and domain separated; comparison is constant time.
Secret findings contain fingerprints and safe metadata, never raw secret values. SAST evidence omits raw matched expressions. Recursive metadata sanitization applies to all report formats and API-derived report data.