Skip to content

Reports and Integrations

Wakemeup edited this page Aug 25, 2026 · 2 revisions

Reports and Integrations

Report formats

The CLI accepts:

  • json
  • yaml
  • table
  • sarif
  • junit
  • html
  • cyclone-dx-vex
  • spdx
  • gitlab-code-quality
  • json-lines
  • csv
  • gitlab-sarif
  • gitlab-cyclonedx
  • gitlab-artifacts
hooray scan project . --format sarif --output hooray.sarif
hooray report 'run:UUID' --format html --output hooray.html

Canonical reports use format version 1.0.0 and embed the native scan schema version. Output is deterministic, UTF-8, redacted, validated, and capped at 64 MiB while rendering rather than after an unbounded allocation.

Interoperability

  • SARIF 2.1.0 for code-scanning ingestion.
  • JUnit XML for test-report surfaces.
  • Self-contained CSP-hardened HTML.
  • CycloneDX 1.6 VEX with applicability analysis.
  • SPDX 2.3 JSON with deterministic collision-resistant SPDX element IDs.
  • GitLab Code Quality JSON.
  • JSON Lines for streaming one canonical finding per line.
  • RFC 4180 CSV with fixed finding-row columns from stable_finding_id through first_location_path.

GitLab-specific values feed Code Quality, SARIF security ingestion, and CycloneDX dependency ingestion; gitlab-artifacts publishes all five GitLab artifacts as one atomic directory bundle.

Generated CI templates

hooray integrations generate pre-commit
hooray integrations generate github-actions
hooray integrations generate gitlab-ci

Generated templates invoke the current clean-cut CLI (hooray scan project .) and only supported format values. The pre-commit repository hook is declared in .pre-commit-hooks.yaml.

Programmatic payloads

The library can produce bounded payloads for GitHub checks, GitLab Code Quality, Slack, VS Code/LSP diagnostics, pull-request gates, and Jira create-issue payloads with escaped wiki markup and capped finding lists. New denied findings can block a PR without treating unchanged historical findings as new.

Signed webhooks require HTTPS destinations, bounded event names and payloads, and a secret between 16 and 4096 bytes. Signatures are deterministic and domain separated; comparison is constant time.

Sensitive output

Secret findings contain fingerprints and safe metadata, never raw secret values. SAST evidence omits raw matched expressions. Recursive metadata sanitization applies to all report formats and API-derived report data.

Clone this wiki locally