Upload a report
Send SARIF, CycloneDX or SPDX reports to the Security page, and what happens when a newer report arrives.
Availability
Send security reports to Prodgator from the Security page, the API, or the Prodgator report action in GitHub Actions.
Supported formats
| Format | What Prodgator reads | Notes |
|---|---|---|
| SARIF 2.1.0 | Results with , CWE tags, , locations and fingerprints | Other versions are read as 2.1.0, with a warning on the upload |
| CycloneDX JSON | Vulnerabilities with ratings, affected components and VEX analysis | XML is not supported |
| SPDX 2.x JSON | Components only (no findings) | Tag-value and SPDX 3 are not supported |
Prodgator reads these common formats only, not each scanner's own JSON. Almost every scanner can write SARIF: see Set up a scanner for examples with ASH, Grype, Trivy, Semgrep, Checkov and Syft. Grype JSON and Trivy JSON uploads fail with a message that names the SARIF flag to use instead (, ).
Reports must be JSON. Prodgator never runs anything in a report. It reads the JSON and refuses a file that is larger than your plan allows, nested more than 64 levels deep, or has more than 5 million values.
Secret scanner results (for example gitleaks) keep the rule, file and line but not the result message, since scanners often quote the secret there. Common credential patterns in other messages are replaced with .
Scanner-specific JSON
Prodgator does not read Grype JSON () or Trivy JSON (). An upload of either fails with a message such as "Grype JSON reports are not supported. Prodgator reads SARIF 2.1.0, CycloneDX JSON and SPDX JSON. Run Grype with -o sarif and upload that file."
The report action still accepts and on a attestation, so existing workflows keep working. The file is attached to the run report for download, but Prodgator reads no findings from it. Use for findings.
From the Security page
- On the Security page, click Upload report.
- Pick the repository, or type its name () if Prodgator has not seen it yet. If a repository with that name is on more than one of your providers (for example on GitHub and GitLab), also pick the provider.
- (Optional) Enter a category. Reports for the same repository can use different categories, for example one per container image or per scanner configuration.
- (Optional) Pick or type a branch. Leave it empty to use the repository's tracked branch (see Tracked branches). Check Tracked to open findings for this upload whatever its branch.
- (Optional) Enter a commit SHA. Without one, the upload counts against the repository for the UTC day.
- Choose the report file and click Upload.
The upload list shows each report's status: queued, reading, done, or failed with the reason.
Uploading a newer report
A newer report from the same scanner, repository, category and branch marks findings from the previous report that it no longer lists as fixed, unless the new report was truncated. Findings both reports list are updated in place.
Branches
Only scan results on the repository's tracked branch (by default its default branch on GitHub) open findings. Scan results from other branches stay in the Scan results view. Leave branch empty to use the tracked branch, or set Tracked ( in the API) to open findings whatever the branch. See Tracked branches. Findings from a pull request scan can also reach the tracked branch when the pull request merges: see Findings from pull requests.
Limits
| Free | Team | Business | Enterprise | |
|---|---|---|---|---|
| Security report uploads per pipeline run | None | 3 | 10 | Unlimited |
| Security report file size | None | 10 MB | 50 MB | 100 MB |
| Findings kept per report | None | 5,000 | 20,000 | 50,000 |
| Uploads outside a run, per organization per hour | None | 60 | 300 | 1,000 |
Uploads from the report action count against their pipeline run. Uploads from the Security page or the API count against the repository and commit, with the same number as the per-run limit:
- With a commit SHA: counted against the repository and commit. The count expires 30 days after the last upload to that commit.
- Without a commit SHA: counted against the repository for the UTC day.
- The same file again (same repository, category and branch): returns the existing upload and is not counted.
The hourly limit is a safety net against scripts that upload in a loop.
When a report has more findings than your plan keeps, Prodgator keeps the most severe ones and marks the upload truncated.
Related
Set up a scanner
Workflow examples for ASH, Grype, Trivy, Semgrep, Checkov and Syft.
Upload from GitHub Actions
Attach scanner output to a run report, with no API key.
Upload with the API
Create the upload, PUT the file, complete it.
How SARIF results are categorized
How a SARIF result becomes a dependency, code or secret finding.
Upload errors
Each error message and what to do.