ProdgatorDocs
SecurityUpload reports

How SARIF results are categorized

How Prodgator decides whether a SARIF result is a dependency, code or secret finding.

How SARIF results are categorized

SARIF has no field that says whether a result is a dependency vulnerability, a code finding or a secret, so Prodgator decides for each result. Code scanning is the default. A result becomes a dependency finding only when the report shows it is one.

Prodgator checks, in this order:

  1. Secret: the result comes from a secret scanner (gitleaks, TruffleHog, detect-secrets, ggshield, GitHub secret scanning), its rule is tagged , or ASH marks it . The message is never stored, because it can quote the secret.
  2. Code, by the scanner's own label: ASH marks it or , or Trivy tags it .
  3. Dependency, when any of these is true:
    • The result comes from a dependency scanner: Grype, OSV-Scanner, OWASP Dependency-Check, Snyk Open Source, npm, yarn, pnpm or pip audit, cargo-audit, bundler-audit or govulncheck (read from or , or ASH's per-result scanner name), or ASH marks it .
    • The result or rule has package properties: , , , , or a package name with , or .
    • The message names a package, as Trivy ( / ), Grype and OSV-Scanner write it.
    • The rule ID names a package and version, as Checkov's SCA results do ().
    • The result has a CVE, GHSA or other advisory ID and points at a lockfile or manifest (, , , , , , , , , , , , and others), at an image package database, or comes from an image scan.
    • The rule is tagged , , or and has an advisory ID.
  4. Code scanning for everything else.

A rule named after a CVE (for example ) from a tool Prodgator does not know, with no package, lockfile or tag, stays a code finding. Prodgator still keeps the CVE on it.

Infrastructure as code results (Checkov, cfn-nag, cdk-nag, tfsec, KICS, Terrascan and Trivy misconfigurations) are code findings, grouped by file and line like other code findings.

For dependency results, Prodgator reads the package name, installed version, fixed version and ecosystem (from the purl, the scanner's package type or the lockfile name) and builds a purl, so the finding carries the same package identity as a Dependabot alert or a CycloneDX report.

Each scan result records why it got its category, for example , , or . The expanded finding row shows it as Why this category, and the findings API and the export return it as .

Once categorized, results from several scanners that describe the same problem are grouped into one finding. See How deduplication works.

On this page