reportingDescriptor object
A reportingDescriptor
object contains information that describes a "reporting item" generated by a tool.
Example
{
"$schema": "https:\/\/json.schemastore.org\/sarif-2.1.0.json",
"version": "2.1.0",
"runs": [
{
"tool": {
"driver": {
"name": "CodeScanner",
"semanticVersion": "1.1.2-beta.12",
"informationUri": "https:\/\/codeScanner.dev",
"rules": [
{
"id": "CA1001",
"deprecatedIds": [
"CA1000"
]
},
{
"id": "CA1002",
"deprecatedIds": [
"CA1000"
]
}
]
}
},
"results": [
{
"message": {
"text": "..."
},
"ruleId": "CA1001",
"suppressions": [
{
"kind": "inSource"
}
],
"baselineState": "unchanged"
},
{
"message": {
"text": "..."
},
"ruleId": "CA1002",
"suppressions": [
{
"kind": "inSource"
}
],
"baselineState": "updated"
}
]
}
]
}
How to generate
See examples/reportingDescriptor.php
script.
<?php declare(strict_types=1);
use Bartlett\Sarif\Definition\Message;
use Bartlett\Sarif\Definition\ReportingDescriptor;
use Bartlett\Sarif\Definition\Result;
use Bartlett\Sarif\Definition\Run;
use Bartlett\Sarif\Definition\Suppression;
use Bartlett\Sarif\Definition\Tool;
use Bartlett\Sarif\Definition\ToolComponent;
use Bartlett\Sarif\SarifLog;
require_once dirname(__DIR__) . '/vendor/autoload.php';
$driver = new ToolComponent('CodeScanner');
$driver->setInformationUri('https://codeScanner.dev');
$driver->setSemanticVersion('1.1.2-beta.12');
$rule1 = new ReportingDescriptor('CA1001');
$rule1->addDeprecatedIds(['CA1000']);
$rule2 = new ReportingDescriptor('CA1002');
$rule2->addDeprecatedIds(['CA1000']);
$driver->addRules([$rule1, $rule2]);
$tool = new Tool($driver);
$results = [];
$results[0] = new Result(new Message('...'));
$results[0]->setRuleId('CA1001');
$results[0]->setBaselineState('unchanged');
$suppression = new Suppression('inSource');
$results[0]->addSuppressions([$suppression]);
$results[1] = new Result(new Message('...'));
$results[1]->setRuleId('CA1002');
$results[1]->setBaselineState('updated');
$suppression = new Suppression('inSource');
$results[1]->addSuppressions([$suppression]);
$run = new Run($tool);
$run->addResults($results);
$log = new SarifLog([$run]);
try {
echo $log, PHP_EOL;
} catch (Exception $e) {
echo "Unable to produce SARIF report due to following error: " . $e->getMessage(), PHP_EOL;
}