Skip to content

fix(scan): stable SARIF partialFingerprints for drift findings - #398

Merged
vibgrate-team merged 4 commits into
mainfrom
cursor/sarif-stable-fingerprints-9325
Oct 8, 2026
Merged

vibgrate-team merged 4 commits into
mainfrom
cursor/sarif-stable-fingerprints-9325

Conversation

@vibgrate-team

@vibgrate-team vibgrate-team commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

SARIF results now carry a stable partialFingerprints["vg/finding-id/v1"] so code-scanning tools can track the same finding across runs:

  • Drift findings identified by rule and location reuse the baseline-suppression content id, so message wording changes don't break the fingerprint.
  • Package, advisory, and package-URL details are added only when they identify the finding.
  • Major-lag results key on the package or framework name, so a newer version count doesn't change the id.
  • Baseline suppressions and infrastructure findings keep the ids they already used.

DOCS.md, README.md, and CHANGELOG.md describe the fingerprint contract.

Related issues

Closes #275

Checklist

  • Tests added or updated
  • Docs updated where behavior is described
  • No proprietary or internal references
  • Commits use Conventional Commits and are signed off

How to verify

pnpm lint && pnpm typecheck && pnpm test

cursoragent and others added 4 commits October 7, 2026 12:09
Drift results from vg scan --format sarif omitted partialFingerprints
unless a baseline suppression was attached, so code scanning could not
match unchanged alerts across runs. Every result now sets
vg/finding-id/v1 from finding content.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: Crowers <crowers@users.noreply.github.com>
Co-authored-by: Crowers <crowers@users.noreply.github.com>
Drift fingerprints reuse the baseline-suppression content id when a
finding is identified by its rule and location. Vulnerability results
add ecosystem, package, advisory id, and a package URL when the finding
has one. Major-lag results use the package or framework name, so a
newer count does not change the id. Message text is unchanged.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: Crowers <crowers@users.noreply.github.com>
Signed-off-by: Cursor Agent <cursoragent@cursor.com>

# Conflicts:
#	CHANGELOG.md

Co-authored-by: Crowers <crowers@users.noreply.github.com>
@vibgrate-team
vibgrate-team marked this pull request as ready for review October 8, 2026 21:28
@vibgrate-team
vibgrate-team merged commit ee282ce into main Oct 8, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enhancement: stable SARIF partialFingerprints across identical vg scan runs

2 participants