Sign inSign up

tomasbjerre/violations-command-line

By tomasbjerre

•Updated 14 days ago

Find report files from static code analysis, present and optionally fail the command.

Image
0

50K+

tomasbjerre/violations-command-line repository overview

Documented here: https://github.com/tomasbjerre/violations-command-line⁠

⁠Formats

Example of supported reports are available here⁠.

A number of parsers have been implemented. Some parsers can parse output from several reporters.

ReporterParserNotes
ARM-GCC⁠CLANG
AndroidLint⁠ANDROIDLINT
Ansible-Later⁠ANSIBLELATERWith json format
AnsibleLint⁠FLAKE8With -p
Bandit⁠CLANGWith bandit -r examples/ -f custom -o bandit.out --msg-template "{abspath}:{line}: {severity}: {test_id}: {msg}"
CLang⁠CLANG
CPD⁠CPD
CPPCheck⁠CPPCHECKWith cppcheck test.cpp --output-file=cppcheck.xml --xml
CPPLint⁠CPPLINT
CSSLint⁠CSSLINT
Checkstyle⁠CHECKSTYLE
CloudFormation Linter⁠JUNITcfn-lint . -f junit --output-file report-junit.xml
CodeClimate⁠CODECLIMATE
CodeNarc⁠CODENARC
Coverity⁠COVERITY
Dart⁠MACHINEWith dart analyze --format=machine
Dependency Check⁠SARIFUsing --format SARIF
Detekt⁠CHECKSTYLEWith --output-format xml.
DocFX⁠DOCFX
Doxygen⁠CLANG
ERB⁠CLANGWith erb -P -x -T '-' "${it}" | ruby -c 2>&1 >/dev/null | grep '^-' | sed -E 's/^-([a-zA-Z0-9:]+)/${filename}\1 ERROR:/p' > erbfiles.out.
ESLint⁠CHECKSTYLEWith format: 'checkstyle'.
Findbugs⁠FINDBUGS
Flake8⁠FLAKE8
FxCop⁠FXCOP
GCC⁠CLANG
GHS⁠GHS
Gendarme⁠GENDARME
Generic reporter⁠GENERICWill create one single violation with all the content as message.
GoLint⁠GOLINT
GoVet⁠GOLINTSame format as GoLint.
GolangCI-Lint⁠CHECKSTYLEWith --out-format=checkstyle.
GoogleErrorProne⁠GOOGLEERRORPRONE
HadoLint⁠CHECKSTYLEWith -f checkstyle
IAR⁠IARWith --no_wrap_diagnostics
Infer⁠PMDFacebook Infer. With --pmd-xml.
JACOCO⁠JACOCO
JCReport⁠JCREPORT
JSHint⁠JSLINTWith --reporter=jslint or the CHECKSTYLE parser with --reporter=checkstyle
JUnit⁠JUNITIt only contains the failures.
KTLint⁠CHECKSTYLE
Klocwork⁠KLOCWORK
KotlinGradle⁠KOTLINGRADLEOutput from Kotlin Gradle Plugin.
KotlinMaven⁠KOTLINMAVENOutput from Kotlin Maven Plugin.
Lint⁠LINTA common XML format, used by different linters.
MSBuildLog⁠MSBULDLOGWith -fileLogger use .*msbuild\\.log$ as pattern or -fl -flp:logfile=MyProjectOutput.log;verbosity=diagnostic for a custom output filename
MSCpp⁠MSCPP
Mccabe⁠FLAKE8
MyPy⁠MYPY
NullAway⁠GOOGLEERRORPRONESame format as Google Error Prone.
PCLint⁠PCLINTPC-Lint using the same output format as the Jenkins warnings plugin, details here⁠
PHPCS⁠CHECKSTYLEWith phpcs api.php --report=checkstyle.
PHPPMD⁠PMDWith phpmd api.php xml ruleset.xml.
PMD⁠PMD
Pep8⁠FLAKE8
PerlCritic⁠PERLCRITIC
PiTest⁠PITEST
ProtoLint⁠PROTOLINT
Puppet-Lint⁠CLANGWith -log-format %{fullpath}:%{line}:%{column}: %{kind}: %{message}
PyDocStyle⁠PYDOCSTYLE
PyFlakes⁠FLAKE8
PyLint⁠PYLINTWith pylint --output-format=parseable.
ReSharper⁠RESHARPER
RubyCop⁠CLANGWith rubycop -f clang file.rb
SARIF⁠SARIFv2.x. Microsoft Visual C# can generate it with ErrorLog="BuildErrors.sarif,version=2".
SbtScalac⁠SBTSCALAC
Scalastyle⁠CHECKSTYLE
Semgrep⁠SEMGREPWith --json.
Simian⁠SIMIAN
Sonar⁠SONARWith mvn sonar:sonar -Dsonar.analysis.mode=preview -Dsonar.report.export.path=sonar-report.json. Removed in 7.7, see SONAR-11670⁠ but can be retrieved with: curl --silent 'http://sonar-server/api/issues/search?componentKeys=unique-key&resolved=false' | jq -f sonar-report-builder.jq > sonar-report.json.
Spotbugs⁠FINDBUGS
StyleCop⁠STYLECOP
SwiftLint⁠CHECKSTYLEWith --reporter checkstyle.
TSLint⁠CHECKSTYLEWith -t checkstyle
Valgrind⁠VALGRINDWith --xml=yes.
XMLLint⁠XMLLINT
XUnit⁠XUNITIt only contains the failures.
YAMLLint⁠YAMLLINTWith -f parsable
ZPTLint⁠ZPTLINT

52 parsers and 79 reporters.

Missing a format? Open an issue here⁠!

Tag summary

Content type

Image

Digest

sha256:86883a01a…

Size

79.4 MB

Last updated

14 days ago

docker pull tomasbjerre/violations-command-line:4.0.5