SARIF Support
- Dominant language
- Go
- Stars
- 595
- Forks
- 135
- PR merge metrics
- No merged PRs in 30d
Description
Hi folks!
I believe it would be very interesting if the project had support for SARIF [1]. SARIF is already a strong industry standard and I believe that all the tools that Husky uses already have this option.
With that, it would be a little simpler to integrate new SAST/SCA tools in Husky. We could also have a SARIF output to help make the information that Husky generates easy to migrate to other platforms. For example, with this we can drastically reduce the codes used to map the fields in the output for each tool.
Thanks!
[1] - https://docs.oasis-open.org/sarif/sarif/v2.1.0/sarif-v2.1.0.pdf
Contributor guide
Research direction
No files, tests, or entry points are named. Start by reviewing how Husky currently maps SAST/SCA tool fields and produces output, then compare those mappings with SARIF v2.1.0. Done means supported tools can be represented consistently and Husky can emit SARIF for downstream platforms.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100