2026-08-21 23:53:27 +02:00
|
|
|
# Reporting contract
|
|
|
|
|
|
|
|
|
|
Every target run—pass, finding, inconclusive or abort—uses
|
|
|
|
|
`schemas/run-report.schema.json`. Reports include authorization and engagement
|
|
|
|
|
ids, target revision, posture/model, timestamps, sanitized observations,
|
|
|
|
|
cleanup and credential disposition. They never include response bodies,
|
|
|
|
|
credentials or severity.
|
|
|
|
|
|
|
|
|
|
A finding is routed to `risk-nexus` with supported facts and provenance. A
|
|
|
|
|
passing report is routed too because its date and target revision define the
|
|
|
|
|
freshness of the limited assurance. Generate the message body with:
|
|
|
|
|
|
|
|
|
|
```sh
|
|
|
|
|
PYTHONPATH=src python3 -m whitehat_security.cli risk-message evidence/<run>.json
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
The reporter does not edit risk-nexus grading fields. `risk-nexus` decides
|
|
|
|
|
whether an observation is a finding or note, and owns severity, disclosure,
|
|
|
|
|
review cadence and escalation.
|
|
|
|
|
|
2026-08-22 00:44:21 +02:00
|
|
|
Queue a target report without assigning severity:
|
|
|
|
|
|
|
|
|
|
```sh
|
|
|
|
|
PYTHONPATH=src python3 -m whitehat_security.cli deliver evidence/<run>.json --outbox outbox
|
|
|
|
|
```
|
|
|
|
|
|
2026-08-21 23:53:27 +02:00
|
|
|
Offline calibration stays in this repository and is plainly labeled
|
2026-08-22 00:44:21 +02:00
|
|
|
`evidence_class: fixture`; it is not sent as if it were a target result. The
|
|
|
|
|
deliver command refuses fixture evidence.
|
2026-08-21 23:53:27 +02:00
|
|
|
|