Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Include fingerprint in SARIF output #6865

Open
pvickery-ParamountCommerce opened this issue Nov 21, 2024 · 0 comments
Open

Include fingerprint in SARIF output #6865

pvickery-ParamountCommerce opened this issue Nov 21, 2024 · 0 comments
Labels
contribution requested This is a great feature idea, but we will need a contribution to get it added to Checkov.

Comments

@pvickery-ParamountCommerce

Describe the feature

Adding support for fingerprints in SARIF (Static Analysis Results Interchange Format) allows for the de-duplication of results across multiple scans or runs. This would be very helpful to track all the findings without the additional noise of duplicate findings.

Examples

For any type of findings, I want to be able to run checkov -d . -o sarif and see fingerprints or partialFingerprints. This way I can compare previous SARIF outputs to see if specific findings were already reported

Additional context

OASIS documentation for fingerprints

@pvickery-ParamountCommerce pvickery-ParamountCommerce added the contribution requested This is a great feature idea, but we will need a contribution to get it added to Checkov. label Nov 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
contribution requested This is a great feature idea, but we will need a contribution to get it added to Checkov.
Projects
None yet
Development

No branches or pull requests

1 participant