Skip to content

feat(scan): record baselined findings in machine-readable output - #339

Closed
vibgrate-team wants to merge 1 commit into
mainfrom
cursor/baseline-scan-audit-7919
Closed

vibgrate-team wants to merge 1 commit into
mainfrom
cursor/baseline-scan-audit-7919

Conversation

@vibgrate-team

@vibgrate-team vibgrate-team commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Superseded by #338.

vg scan --baseline used the baseline only for the numeric drift delta,
so matched findings left no trace in JSON or SARIF.

The artifact now includes a baseline block (compared, file,
suppressedCount, suppressed) sorted by ruleId, location, and id.
Findings stay in the primary array. Text and Markdown reports include
the count, and SARIF attaches the same ids as suppressions.

Fixes #161

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants