Skip to content

Document SARIF integration guide for scanner authors #15

@rdwj

Description

@rdwj

Guide for authors of other SAST tools who want to embed STIG metadata in their SARIF output for optimal Stigcode consumption.

Acceptance Criteria:

  • Document the properties.stigIds convention
  • Document the properties.nist80053 convention
  • Provide example SARIF snippets showing enriched rule metadata
  • Explain how Stigcode uses explicit metadata vs. CWE fallback
  • Include validation command: stigcode validate-sarif <file> to check metadata completeness

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions