| Vendors this code calls whose retirement list nobody has checked. Zero findings for these is UNAUDITED, not clean. | |||||||||||||||||||
| Sub-dependencies the scan couldn't crawl — private or unreachable. | |||||||||||||||||||
| {{ row.repoLabel || row.repo }} | {{ actionLabel(row) }} | {{ targetText(row) }} | {{ row.finding_count }} | {{ row.worst }} | {{ row.repo }} | {{ row.domain }} | {{ row.vendor }} | {{ row.version || '?' }} | {{ row.file_count }} | {{ row.repo }} | {{ row.source }} {{ row.source }} | {{ row.kind }} | {{ row.via || '' }} | {{ row.vendor }} | {{ catalogWhy(row) }} | {{ row.callSites }} call-site(s) | {{ row.catalogEntries }} entr(y/ies) | {{ row.verdict }} | |
|
{{ row.command }}
{{ row.recommendation }}
Clears {{ row.finding_count }} advisor{{ row.finding_count === 1 ? 'y' : 'ies' }} ({{ row.critical_count }} critical)
Used at:
{{ f.loc }}
{{ f.loc }}
source ↗
{{ u }}
·
|
|||||||||||||||||||
|
{{ f }}
—
|
|||||||||||||||||||
Nothing found.
View / copy — the canonical drift.json every surface
projects from (read-only; the verified source of truth).
{{ driftJsonText }}
{{ sbomHeaderText }}
| Type | Component | Version | Used in | Vulns |
|---|---|---|---|---|
| {{ c.type }} | {{ c.purl }} | {{ c.version }} | {{ c.repoCount }} repo{{ c.repoCount === 1 ? '' : 's' }} | {{ c.vulnCount }} {{ c.vulnSeverity }} — |
CycloneDX 1.5 (sbom.json) → Dependency-Track,
GitHub · Open in Rancher SBOM viewer ↗
{{ sbomJsonText }}
SPDX 2.3 (sbom.spdx.json)
· Open in Rancher SBOM viewer ↗
{{ spdxJsonText }}
{{ sarifHeaderText }}
{{ g.ruleId }}{{ g.count }}
| Location | Message | Level |
|---|---|---|
| {{ r.where }} | {{ r.message }} | {{ r.level }} |
SARIF 2.1.0 (drift.sarif.json) — file:line
results → GitHub code scanning, VS Code · Open in SARIF web viewer ↗
{{ sarifJsonText }}