Skip to content

Report format ​

dagsec scan --format json prints the report as JSON. Dashboard scans store the same structure.

json
{
  "secrets": [
    {
      "rule_id": "aws-access-key-id",
      "description": "AWS access key ID",
      "commit": "3f2a9c1d7e04b1c2d3e4f5a6b7c8d9e0f1a2b3c4",
      "author": "Jane Doe",
      "date": "2026-09-28T16:05:12Z",
      "path": "config/deploy.env",
      "line": 1,
      "secret_redacted": "AKIA********",
      "fingerprint": "aws-access-key-id:3f2a9c1d7e04:config/deploy.env:1",
      "location": "code",
      "active": true
    }
  ],
  "dependencies": [
    { "name": "lodash", "ecosystem": "npm", "score": 85, "license": "MIT" }
  ],
  "vulnerabilities": [
    {
      "ecosystem": "npm",
      "package": "lodash",
      "version": "4.17.4",
      "id": "GHSA-jf85-cpcp-j695",
      "cve": "CVE-2019-10744",
      "summary": "Prototype Pollution in lodash",
      "severity": "critical",
      "fixed": "4.17.12",
      "url": "https://osv.dev/vulnerability/GHSA-jf85-cpcp-j695"
    }
  ],
  "vulnerabilities_checked": true,
  "fail_under": 40,
  "packages": [
    { "ecosystem": "npm", "name": "lodash", "version": "4.17.4" }
  ],
  "blocked_licenses": ["GPL-3.0"]
}

Fields ​

secrets[] ​

FieldTypeMeaning
rule_idstringOne of the rules
descriptionstringHuman-readable secret type
commitstringFull SHA of the commit that added it
authorstringCommit author name
datestringCommit time, RFC 3339 UTC
path, linestring, numberWhere it was added
secret_redactedstringMasked value; the full secret is never included
fingerprintstringID for .dagsecignore
locationstringcode, test, docs or example
activeboolean, optionalWhether the provider still accepts it; absent when not checked

dependencies[] ​

Direct dependencies with a health score: name, ecosystem (npm, pypi, crates), score (0 to 100) and license when the registry reports one.

vulnerabilities[] ​

Sorted most severe first. severity is critical, high, moderate, low or unknown. cve and fixed are null when unknown.

Other fields ​

FieldMeaning
vulnerabilities_checkedfalse when OSV.dev couldn't be reached; an empty vulnerabilities then means unknown
fail_underHealth score threshold used
packagesEvery pinned package version, direct and transitive; ecosystem is npm, pypi, crates, go, maven or nuget
blocked_licensesFrom .dagsec.toml; absent when there is no policy

Markdown ​

--format markdown gives the pull request comment: a verdict line, then Leaked secrets (with fixtures in a collapsed section), Licenses (when there's a policy), Known vulnerabilities grouped per package with an All advisories section, and Dependencies.