Skip to content

aegis inspect: CI/output integrations — SARIF, suppression allowlist, CI exit codes, attestation+SBOM #82

Description

@quantifylabs

Static-analyzer integration increments so inspect plugs into CI and code-scanning.

Items

  • SARIF output — emit findings as SARIF so they drop into code-scanning / CI annotations.
  • Suppression / allowlist# aegis: ignore inline + a config allowlist for accepted sinks.
  • CI exit codes — non-zero exit on new critical flows, for gating.
  • Signed, no-egress attestation + SBOM — for the local/keyless run, to back the "local & keyless" claim.

These can ship independently; grouped here as the CI/output theme.

Source: docs/issues/inspect-followups.md (Static analyzer — next increments)

Metadata

Metadata

Assignees

No one assigned

    Labels

    deferredTracked, intentionally not yet scheduledenhancementNew feature or requestinspectaegis inspect static analyzer

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions