Add SARIF (Static Analysis Results Interchange Format) output support
Nadie ha tomado este issue todavía.
- Lenguaje dominante
- Python
- Estrellas
- 20.6k
- Forks
- 3.3k
- Métricas de merge de PR
- Métricas de PR pendientes
Descripción
Feature
Add support for SARIF (Static Analysis Results Interchange Format) output format to mypy, similar to the existing --output=json option.
Pitch
SARIF is an OASIS standard format for static analysis results that is widely supported by modern CI/CD platforms and security tools:
- GitHub Advanced Security natively ingests SARIF files for code scanning alerts
- Azure DevOps supports SARIF for displaying security and code quality results
- GitLab can process SARIF reports for vulnerability tracking
- Many other security and code quality platforms (SonarQube, CodeQL, etc.) support SARIF
Other Python type checkers like Pyre already support SARIF output. Adding this to mypy would:
- Improve integration with GitHub/Azure/GitLab security features
- Make it easier to use mypy in enterprise CI/CD pipelines
- Provide a standardized foundation for richer diagnostics supported by SARIF
- Enable consumption by security tools that require standardized formats
Example Usage
# Generate SARIF output
mypy myproject/ --output=sarif > results.sarif
# Upload to GitHub Code Scanning (requires gzip + base64 encoding)
gzip -c results.sarif | base64 -w0 > results.sarif.gz.b64
gh api /repos/owner/repo/code-scanning/sarifs --method POST \
--field commit_sha="$(git rev-parse HEAD)" \
--field ref="refs/heads/main" \
--field sarif="@results.sarif.gz.b64"
Implementation Notes
The implementation could likely build on the existing output formatter infrastructure:
- Add a new
SARIFFormatterclass inmypy/error_formatter.pyextendingErrorFormatter - Add "sarif" to the
OUTPUT_CHOICESdictionary - Implement the SARIF v2.1.0 JSON schema
The MypyError class already provides the necessary diagnostic data (file path, line, column, error code, message, severity). Note that SARIF requires aggregating results into a single document structure rather than line-by-line output like JSON, which may require some adjustments to the formatter interface.
Related Issues
- #10816 (closed) - discussed multiple output formats including SARIF in comments
- #17612 - GitHub Actions workflow commands format (similar motivation)
- #20212 - Include summary in JSON output
References
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Línea de trabajo
Comienza en mypy/error_formatter.py leyendo ErrorFormatter, MypyError, la ruta de salida JSON existente y OUTPUT_CHOICES. Después, revisa la especificación SARIF v2.1.0 y determina cómo se puede agregar la salida del formateador en un único documento. La tarea estará terminada cuando mypy acepte --output=sarif y emita un informe compatible con SARIF que contenga los datos de diagnóstico disponibles.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- python
- Área
- tooling
- Tipo de issue
- Nueva funcionalidad
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Estado de actividad
- Tranquilo
- Claridad
- Bastante claro
- Aptitud para principiantes
- 52/100