aquasecurity / chain-bench

An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
Apache License 2.0
718 stars 62 forks source link

Sarif report for chain-bench #113

Open krol3 opened 1 year ago

krol3 commented 1 year ago

Hi! could be possible the output of chain-bench result deliver a sarif report to integrate with Github?

https://docs.github.com/en/code-security/code-scanning/integrating-with-code-scanning/uploading-a-sarif-file-to-github