ProdgatorDocs
SecurityUpload reports

Upload a report

Send SARIF, CycloneDX or SPDX reports to the Security page, and what happens when a newer report arrives.

Availability

Team plan and above. Uploading needs the or role, or a custom role with .

Send security reports to Prodgator from the Security page, the API, or the Prodgator report action in GitHub Actions.

Supported formats

FormatWhat Prodgator readsNotes
SARIF 2.1.0Results with , CWE tags, , locations and fingerprintsOther versions are read as 2.1.0, with a warning on the upload
CycloneDX JSONVulnerabilities with ratings, affected components and VEX analysisXML is not supported
SPDX 2.x JSONComponents only (no findings)Tag-value and SPDX 3 are not supported

Prodgator reads these common formats only, not each scanner's own JSON. Almost every scanner can write SARIF: see Set up a scanner for examples with ASH, Grype, Trivy, Semgrep, Checkov and Syft. Grype JSON and Trivy JSON uploads fail with a message that names the SARIF flag to use instead (, ).

Reports must be JSON. Prodgator never runs anything in a report. It reads the JSON and refuses a file that is larger than your plan allows, nested more than 64 levels deep, or has more than 5 million values.

Secret scanner results (for example gitleaks) keep the rule, file and line but not the result message, since scanners often quote the secret there. Common credential patterns in other messages are replaced with .

Scanner-specific JSON

Prodgator does not read Grype JSON () or Trivy JSON (). An upload of either fails with a message such as "Grype JSON reports are not supported. Prodgator reads SARIF 2.1.0, CycloneDX JSON and SPDX JSON. Run Grype with -o sarif and upload that file."

The report action still accepts and on a attestation, so existing workflows keep working. The file is attached to the run report for download, but Prodgator reads no findings from it. Use for findings.

From the Security page

  1. On the Security page, click Upload report.
  2. Pick the repository, or type its name () if Prodgator has not seen it yet. If a repository with that name is on more than one of your providers (for example on GitHub and GitLab), also pick the provider.
  3. (Optional) Enter a category. Reports for the same repository can use different categories, for example one per container image or per scanner configuration.
  4. (Optional) Pick or type a branch. Leave it empty to use the repository's tracked branch (see Tracked branches). Check Tracked to open findings for this upload whatever its branch.
  5. (Optional) Enter a commit SHA. Without one, the upload counts against the repository for the UTC day.
  6. Choose the report file and click Upload.

The upload list shows each report's status: queued, reading, done, or failed with the reason.

Uploading a newer report

A newer report from the same scanner, repository, category and branch marks findings from the previous report that it no longer lists as fixed, unless the new report was truncated. Findings both reports list are updated in place.

Branches

Only scan results on the repository's tracked branch (by default its default branch on GitHub) open findings. Scan results from other branches stay in the Scan results view. Leave branch empty to use the tracked branch, or set Tracked ( in the API) to open findings whatever the branch. See Tracked branches. Findings from a pull request scan can also reach the tracked branch when the pull request merges: see Findings from pull requests.

Limits

FreeTeamBusinessEnterprise
Security report uploads per pipeline runNone310Unlimited
Security report file sizeNone10 MB50 MB100 MB
Findings kept per reportNone5,00020,00050,000
Uploads outside a run, per organization per hourNone603001,000

Uploads from the report action count against their pipeline run. Uploads from the Security page or the API count against the repository and commit, with the same number as the per-run limit:

  • With a commit SHA: counted against the repository and commit. The count expires 30 days after the last upload to that commit.
  • Without a commit SHA: counted against the repository for the UTC day.
  • The same file again (same repository, category and branch): returns the existing upload and is not counted.

The hourly limit is a safety net against scripts that upload in a loop.

When a report has more findings than your plan keeps, Prodgator keeps the most severe ones and marks the upload truncated.

On this page