Reports and CI gates #
Read findings in your terminal, send structured reports to another tool, or make instruction checks part of CI. Choose the report format and failure threshold separately.
Understand the result #
A finding includes a rule code, severity, source location when available, and repair guidance. Start with the most severe findings, then inspect the surrounding instructions before making a change.
| Verdict | Meaning |
|---|---|
| FAIL | HIGH or CRITICAL findings remain. |
| REVIEW | MEDIUM findings remain, with no HIGH/CRITICAL findings. |
| PASS | No MEDIUM-or-higher findings remain; LOW/INFO can still appear. |
| SKIPPED | The file was readable but contained no recognized content to inspect. |
| ERROR | An input could not be inspected. |
The Inspected line tells you what the result covers. See coverage and limitations for interpretation.
Set a CI threshold #
lintlang scan --discover . --fail-on fail
--fail-on fail returns exit 1 for HIGH/CRITICAL findings. --fail-on review also includes MEDIUM. Without either threshold, findings are advisory. Input errors are nonzero even in advisory mode; invalid arguments return 2.
The first-party GitHub Action uses fail by default. Follow the GitHub or GitLab guide for a complete job.
Choose a report format #
| Format | Best for | Option |
|---|---|---|
| Terminal | Local review, with a concise finding list | Default |
| Markdown | Readable reports and artifacts | --format markdown |
| JSON | Scripts and custom tooling | --format json |
| SARIF 2.1.0 | Code-scanning tools | --format sarif |
| GitLab Code Quality | Merge-request findings | --format gitlab |
lintlang scan --discover . --format json
lintlang scan --discover . --format sarif > lintlang.sarif
Terminal and Markdown show up to five findings per code by default; use --show-all to expand them. JSON and SARIF retain all findings. GitLab reports require source-backed locations; unsupported findings can be omitted while causing a nonzero exit. Read the GitLab reporting guide before adding that output to CI.
Work with source locations #
Locations may point to an instruction, tool, schema, or enclosing construct. Parsed YAML/JSON values and transformed multiline strings do not always map to an exact token. Use the finding’s evidence and source context together.
JSON and SARIF field reference · Input extraction details.
Share reports deliberately #
Reports can contain text from the scanned source. Review an artifact before uploading it. --no-suggestions changes supported presentation output; it does not redact source evidence or remove JSON suggestion fields.