Skip to content

Write findings as SARIF for code scanning - #1

Merged
tauanbinato merged 2 commits into
mainfrom
sarif-file
Sep 26, 2026
Merged

tauanbinato merged 2 commits into
mainfrom
sarif-file

Conversation

@tauanbinato

Copy link
Copy Markdown
Contributor

Merge after JevGate 0.18.0 is released, the first version with --format sarif; then release this as v1.1.0 and move v1.

  • New input sarif-file: after the check, the action runs it again with --cache-only --format sarif, replaying the answers it just cached (no request is sent), and writes the SARIF log to that path. A replay that fails (such as an older JevGate) is a warning, not a failed step; the check's own exit code is unchanged.
  • The two runs share one command, so --format is given once each.
  • README: a "Code scanning" section with github/codeql-action/upload-sarif@v4 (if: always(), category: jevgate, security-events: write), and the new formats in the inputs table.

Checked locally with a JevGate build that has --format sarif: the check's exit code and outputs are unchanged, and the file is a valid SARIF 2.1.0 log.

sarif-file replays the check from the answers it just cached with --format sarif, so it costs nothing, and the README shows uploading it with upload-sarif. Needs JevGate 0.18.0 or later.
@tauanbinato
tauanbinato merged commit 525472a into main Sep 26, 2026
4 checks passed
@tauanbinato
tauanbinato deleted the sarif-file branch September 26, 2026 02:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant