Skip to content

Latest commit

 

History

History
274 lines (191 loc) · 7.22 KB

File metadata and controls

274 lines (191 loc) · 7.22 KB

codeant scans

Fetch and explore scan results from CodeAnt.

codeant scans <subcommand> [options]

Subcommands

scans orgs

List authenticated organizations.

codeant scans orgs

scans repos

List repositories for an organization.

codeant scans repos [options]

Options:

Option Description
--org <org> Organization name (auto-picked when only one is authenticated)

Examples:

# List repos (auto-selects org if only one)
codeant scans repos

# List repos for a specific org
codeant scans repos --org my-org

scans history

Show scan history for a repository.

codeant scans history --repo <owner/repo> [options]

Options:

Option Description
--repo <repo> (required) Repository in owner/repo format
--branch <name> Filter by branch name
--since <iso> Show scans since ISO date (e.g. 2024-01-01)
--limit <n> Max results (default: 20)

Examples:

# Show last 20 scans for a repo
codeant scans history --repo acme/backend

# Filter to a specific branch
codeant scans history --repo acme/backend --branch main

# Show scans since a date
codeant scans history --repo acme/backend --since 2024-06-01

# Show up to 50 results
codeant scans history --repo acme/backend --limit 50

scans get

Show scan metadata and a severity/category summary. Does not include individual findings.

codeant scans get --repo <owner/repo> [options]

Options:

Option Description
--repo <repo> (required) Repository in owner/repo format
--scan <sha> Specific commit SHA to use
--branch <name> Resolve latest scan on this branch
--types <list> Comma-separated scan types (default: all)
--quiet Suppress progress output

Examples:

# Get latest scan summary for a repo
codeant scans get --repo acme/backend

# Get scan for a specific commit
codeant scans get --repo acme/backend --scan abc1234

# Get latest scan on a branch
codeant scans get --repo acme/backend --branch main

# Only include SAST and secrets types
codeant scans get --repo acme/backend --types sast,secrets

# Suppress progress output
codeant scans get --repo acme/backend --quiet

scans results

Fetch full scan findings for a repository.

codeant scans results --repo <owner/repo> [options]

Options:

Option Description
--repo <repo> (required) Repository in owner/repo format
--scan <sha> Specific commit SHA to use
--branch <name> Resolve latest scan on this branch
--types <list> Comma-separated types: sast, sca, secrets, iac, dead_code, duplicate_code, sbom, anti_patterns, docstring, complex_functions, all (default: all)
--severity <list> Filter by severity (e.g. critical,high)
--path <glob> Filter by file path glob
--check <regex> Filter by check ID or name (regex)
--filter-dismissed Exclude dismissed findings (included by default, marked metadata.dismissed)
--no-false-positives Exclude false positives, including ones users marked in the app (included by default, marked metadata.false_positive)
--format <fmt> Output format: json, sarif, csv, md, table (default: json)
--output <path> Write output to file instead of stdout
--fields <list> Project findings to a subset of fields (comma-separated)
--limit <n> Max findings per page (default: 100)
--offset <n> Pagination offset (default: 0)
--fail-fast Exit 3 on first category fetch failure
--no-color Disable ANSI color (auto-disabled when not a TTY)
--quiet Suppress progress output on stderr

Examples:

# Fetch all findings (JSON)
codeant scans results --repo acme/backend

# Fetch only critical and high severity findings
codeant scans results --repo acme/backend --severity critical,high

# Fetch SAST findings only
codeant scans results --repo acme/backend --types sast

# Filter to a specific file path
codeant scans results --repo acme/backend --path 'src/**/*.ts'

# Filter by check name using regex
codeant scans results --repo acme/backend --check 'sql-injection'

# Output as a Markdown table
codeant scans results --repo acme/backend --format md

# Output as SARIF to a file
codeant scans results --repo acme/backend --format sarif --output results.sarif

# Only open findings: drop dismissed findings and false positives
codeant scans results --repo acme/backend --filter-dismissed --no-false-positives

# Paginate through results
codeant scans results --repo acme/backend --limit 50 --offset 100

# Project only specific fields
codeant scans results --repo acme/backend --fields id,severity,message,path

Exit codes:

Code Meaning
0 Success
1 General error
3 Category fetch failure (with --fail-fast)

scans dismissed

List dismissed alerts for a repository.

codeant scans dismissed --repo <owner/repo> [options]

Options:

Option Description
--repo <repo> (required) Repository in owner/repo format
--analysis-type <type> security, secrets, sca, iac, antipatterns, docstring, complex_functions, dead_code, or duplicate_code (default: security). Result-type names sast and anti_patterns are accepted too.

Examples:

# List dismissed security alerts
codeant scans dismissed --repo acme/backend

# List dismissed secrets alerts
codeant scans dismissed --repo acme/backend --analysis-type secrets

scans overrides

List the per-finding overrides users set in the CodeAnt app: Mark/Unmark false positive (security, iac), secrets confidence (secrets), and Change Severity (security, sca). scans results already applies them.

codeant scans overrides --repo <owner/repo> [--analysis-type security|secrets|iac|sca]

scans start-scan

Trigger a new analysis run for a repository.

codeant scans start-scan [options]

All options are optional — repo, branch, and commit are auto-detected from the local git context when not provided.

Options:

Option Description
--repo <repo> Repository in owner/repo format (auto-detected from git remote)
--branch <name> Branch to scan (auto-detected from current checkout)
--commit <sha> Commit SHA to scan (resolved from remote HEAD of branch if omitted)
--include <paths> Comma-separated file path glob patterns to include
--exclude <paths> Comma-separated file path glob patterns to exclude

Examples:

# Zero-config — auto-detects repo, branch, and latest commit
codeant scans start-scan

# Explicit repo and branch
codeant scans start-scan --repo your-org/your-repo --branch main

# Explicit commit SHA
codeant scans start-scan \
  --repo your-org/your-repo \
  --branch main \
  --commit b509bffa1721da442f35a7ccab969822711a67f0

# Scan only specific files
codeant scans start-scan \
  --branch main \
  --include "src/main.py,src/utils.py" \
  --exclude "tests/,*.md"