Add SARIF (Static Analysis Results Interchange Format) output support
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 52/100
Hướng nghiên cứu
Bắt đầu trong mypy/error_formatter.py bằng cách đọc ErrorFormatter, MypyError, đường dẫn đầu ra JSON hiện có và OUTPUT_CHOICES. Sau đó xem xét đặc tả SARIF v2.1.0 và xác định cách tổng hợp đầu ra của formatter thành một tài liệu duy nhất. Hoàn thành khi mypy chấp nhận --output=sarif và xuất một báo cáo tương thích với SARIF chứa các dữ liệu chẩn đoán hiện có.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Feature
Add support for SARIF (Static Analysis Results Interchange Format) output format to mypy, similar to the existing --output=json option.
Pitch
SARIF is an OASIS standard format for static analysis results that is widely supported by modern CI/CD platforms and security tools:
- GitHub Advanced Security natively ingests SARIF files for code scanning alerts
- Azure DevOps supports SARIF for displaying security and code quality results
- GitLab can process SARIF reports for vulnerability tracking
- Many other security and code quality platforms (SonarQube, CodeQL, etc.) support SARIF
Other Python type checkers like Pyre already support SARIF output. Adding this to mypy would:
- Improve integration with GitHub/Azure/GitLab security features
- Make it easier to use mypy in enterprise CI/CD pipelines
- Provide a standardized foundation for richer diagnostics supported by SARIF
- Enable consumption by security tools that require standardized formats
Example Usage
# Generate SARIF output
mypy myproject/ --output=sarif > results.sarif
# Upload to GitHub Code Scanning (requires gzip + base64 encoding)
gzip -c results.sarif | base64 -w0 > results.sarif.gz.b64
gh api /repos/owner/repo/code-scanning/sarifs --method POST \
--field commit_sha="$(git rev-parse HEAD)" \
--field ref="refs/heads/main" \
--field sarif="@results.sarif.gz.b64"
Implementation Notes
The implementation could likely build on the existing output formatter infrastructure:
- Add a new
SARIFFormatterclass inmypy/error_formatter.pyextendingErrorFormatter - Add "sarif" to the
OUTPUT_CHOICESdictionary - Implement the SARIF v2.1.0 JSON schema
The MypyError class already provides the necessary diagnostic data (file path, line, column, error code, message, severity). Note that SARIF requires aggregating results into a single document structure rather than line-by-line output like JSON, which may require some adjustments to the formatter interface.
Related Issues
- #10816 (closed) - discussed multiple output formats including SARIF in comments
- #17612 - GitHub Actions workflow commands format (similar motivation)
- #20212 - Include summary in JSON output
References
- Ngôn ngữ chính
- Python
- Star
- 20.6k
- Fork
- 3.3k
- Merge trung bình
- 1 ngày 9 giờ
- Pull request đã merge (30 ngày)
- 56
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của python/mypy
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
-
documentation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
-
bug topic-configuration topic-error-reporting
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Issue tương tự
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
use-agent-os/agent-os#3314 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
BasedHardware/omi#15662 · 1 bình luận ·
-
documentation help wanted
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 90/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
AiursoftWeb/AnduinOS-2#19 ·