Skip to content

[Security audit] Enrich finding records with triage, evidence, and supply-chain metadata #595

@cssbruno

Description

@cssbruno

Problem

Audit finding records currently carry the core fields needed for pass/fail output, but they do not include enough stable metadata for long-term triage, suppression auditing, code-scanning correlation, or supply-chain-style evidence tracking.

Current Shape

Findings include fields such as code, severity, target, policy, rule, message, source, and remediation. They do not yet consistently include stable fingerprints, schema/tool version, policy/posture digest, build mode, target, confidence, evidence classification, CWE/OWASP mapping, suppression/waiver details, or first/last-seen information.

Expected Fix

Extend audit finding records and report output with explicit triage and evidence metadata while keeping redaction guarantees for secrets and sensitive response data.

Acceptance Criteria

Related: #558 tracks JSON Schema/SARIF/fingerprint/diff mode, #556 tracks evidence classification, and #555 tracks explicit waivers.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestopsOperations, release, deployment, and CI hardeningsecuritySecurity hardening and security-sensitive behavior

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions