Docs · v0.1.3

HTML reports

--format html writes the scorecard as one self-contained HTML page that makes no network requests. --format all --out writes every format at once. This page follows docs/packs.md at v0.1.3.

Write a report

sc analyze . --format html --out scorecard.html

With a single --format, the report goes to stdout and to the exact --out path. Open scorecard.html in any browser. Because the HTML is also printed, redirect stdout if you only want the file:

sc analyze . --format html --out scorecard.html > /dev/null

The exit code is the same as for any other format: 0 when the configured gates pass, 1 when one fails, 2 when the analyzer can't run.

Every format at once

sc analyze . --format all --out sc-report

With --out, --format all writes JSON, Markdown, SARIF and HTML as sibling files:

sc-report.html
sc-report.json
sc-report.md
sc-report.sarif

On stdout, --format all prints the JSON, then the Markdown. Without --out, sc analyze writes no report files.

The flow strip

Near the top of the report, the flow strip reads left to right, from what was analyzed to the verdict. These are unedited screenshots of the sc 0.1.3 reports for the two fixtures, cropped to the strip.

Flow strip for testdata/good_crate: scope tree, 1 skipped; pack rust; engines 9 run, 3 skipped; gates 6/6 pass; verdict pass.
testdata/good_crate, exit 0. Full report
Flow strip for testdata/failing_test: scope tree, 1 skipped; pack rust; engines 8 run, 4 skipped; gates 5/6 pass; verdict fail.
testdata/failing_test, exit 1. Full report
StepShows
scopeWhat was analyzed: the src tree by default, or the files from --paths or --diff
packThe language pack that was detected, or set with --pack
enginesHow many engines ran and how many were skipped. The header card lists them by name.
gatesGates passed out of gates reported
verdictpass or fail

At narrow widths the report wraps the strip onto several rows. On a phone, this page shows that layout.

What's in the report

  • Header card: the verdict, the analyzed path, pack, scope and run id, then git commit and state, test selection, engines run and skipped, and the paths in scope.
  • Flow: the strip above.
  • Scores: correctness, efficiency, maintainability, security and a11y from 0 to 1, followed by figures for lines and files changed, coverage, the highest CRAP, functions over the threshold, and hallucinated imports. See CRAP and scores.
  • Gates: each gate's result, whether it is enforced, and the reason when it fails. See Gates.
  • Worst CRAP: the highest-scoring functions against the threshold.
  • Findings: each finding with its rule, severity, disposition, location and suggested fix.
  • Mutation · spec: mutation counts (skipped unless --mutation is set) and the spec check.
  • Runs: each command that ran, with its exit code and duration.

sca is advisory and never changes the exit code. From v0.1.1 the gates table shows it as reported only, as in the two reports linked above.

In CI

The GitHub Action takes the same formats. With format: html it writes sc-results.html:

- uses: moonbase2090/Scorecard/action@v0.1.3
  with:
    format: html

SARIF is uploaded to code scanning only when the format is sarif or all.

Full text: docs/packs.md, Flags · action/action.yml