Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

typisttech/comsarif

Open more actions menu

Repository files navigation

ComSARIF

Go Reference GitHub Release Test codecov License Follow @TangRufus on X Follow @TangRufus.com on Bluesky Sponsor @TangRufus via GitHub Hire Typist Tech

Convert Composer audit reports to SARIF files.

Built with ♥ by Typist Tech


Tip

Hire Tang Rufus!

I am looking for my next role, freelance or full-time. If you find this tool useful, I can build you more weird stuff like this. Let's talk if you are hiring PHP / Ruby / Go developers.

Contact me at https://typist.tech/contact/


Goal

Convert Composer audit reports to SARIF files, so that they can be uploaded to GitHub as code scanning alerts.

CLI Usage

USAGE:
  comsarif [<flags>...] --audit <audit.json> --lock <composer.lock>

FLAGS:
  -audit string
        path to Composer audit JSON
  -lock string
        path to composer.lock
  -root string
        path to repository root. Default to current directory
  -v    Print version
  -version
        Print version

EXAMPLES:
  # Generate SARIF based on composer.lock
  $ composer audit --locked --format json > audit.json
  $ comsarif --audit audit.json --lock composer.lock

  # Generate SARIF based on installed packages
  $ composer install
  $ composer audit --format json > audit.json
  $ comsarif --audit audit.json --lock composer.lock

GitHub Actions Usage

Refer to composer-audit-to-sarif-action.

Library Usage

Go Reference

Refer to Go Reference on pkg.go.dev.

Tip

Hire Tang Rufus!

There is no need to understand any of these quirks. Let me handle them for you. I am seeking my next job, freelance or full-time.

If you are hiring PHP / Ruby / Go developers, contact me at https://typist.tech/contact/

CLI Installation

Homebrew (macOS / Linux) (Recommended)

brew install typisttech/tap/comsarif

Build from Source

go install github.com/typisttech/comsarif/cmd/comsarif@latest

Linux (Debian & Alpine)

Follow the instructions on https://broadcasts.cloudsmith.com/typisttech/oss

Cloudsmith

Package repository hosting is graciously provided by Cloudsmith. Cloudsmith is the only fully hosted, cloud-native, universal package management solution, that enables your organization to create, store and share packages in any format, to any place, with total confidence.

People Also Use

Credits

ComSARIF is a Typist Tech project and maintained by Tang Rufus, freelance developer for hire.

Full list of contributors can be found here.

Copyright and License

This project is a free software distributed under the terms of the MIT license. For the full license, see LICENSE.

Contribute

Feedbacks / bug reports / pull requests are welcome.

About

Convert Composer audit reports to SARIF files

Topics

Resources

Stars

Watchers

Forks

Releases

Used by

Contributors

Languages

Morty Proxy This is a proxified and sanitized view of the page, visit original site.