Report formats¶
| Format | Flag | Use |
|---|---|---|
| table | -f table (default) |
terminal |
| JSON | -f json or --json PATH |
automation; schema below |
| SARIF 2.1.0 | -f sarif or --sarif PATH |
GitHub code scanning and other SARIF consumers |
| Markdown | -f markdown or --markdown PATH |
PR comments, job summaries |
Output is deterministic: findings are sorted by target, severity, check ID and fingerprint;
--no-timestamp drops the only time-dependent field.
JSON¶
The report is versioned (schema_version: "1.0"); the JSON Schema is published at
schema/report-v1.json and tested against the code. Every finding
carries a fingerprint (stable across runs for the same check, target and location) for
deduplication.
SARIF¶
- One rule per catalogue entry, with
security-severityfor GitHub's severity mapping and ahelpUrito this site. - Code scanning only displays results attached to a file in the repository, so each result is
anchored to the file and line that declares the target (targets file,
mcp-posture.toml,.mcp.json), or to--sarif-anchor. partialFingerprintscarry the finding fingerprint, so alerts are tracked across runs.- Suppressed findings are emitted with SARIF
suppressionsand their justification.
Neutralized text¶
Tool names, descriptions and error bodies come from the scanned server. Reports never contain
raw control, bidi or invisible characters: JSON and SARIF escape them (\u202e), table and
Markdown show <U+202E>.