fix(report): emit SARIF by default for exploit runs (#431)

* fix(report): emit SARIF by default for exploit runs, opt out with report.sarif: false

* docs: describe SARIF as on-by-default for exploit runs
This commit is contained in:
ezl-keygraph authored and GitHub committed 2026-08-26 19:25:16 +05:30
1 parent f64a30040e
commit ed5659e2e2
12 files changed
+35 -30

No files matched your search

+1 -1
View File
@@ -29,7 +29,7 @@ export function getAgentGitPaths(agentName: AgentName): string[] {
paths.push(queueFilename);
}
// The report agent also emits the structured findings the markdown is rendered from, and the
// SARIF log when enabled. Listing the log unconditionally is harmless when it was not written,
// SARIF log when produced. Listing the log unconditionally is harmless when it was not written,
// and keeps a stale one from surviving the rollback of a failed attempt.
if (agentName === 'report') {
paths.push(REPORT_JSON_FILENAME);