Report format
dagsec scan --format json prints the report as JSON. Dashboard scans store the same structure.
json
{
"secrets": [
{
"rule_id": "aws-access-key-id",
"description": "AWS access key ID",
"commit": "3f2a9c1d7e04b1c2d3e4f5a6b7c8d9e0f1a2b3c4",
"author": "Jane Doe",
"date": "2026-09-28T16:05:12Z",
"path": "config/deploy.env",
"line": 1,
"secret_redacted": "AKIA********",
"fingerprint": "aws-access-key-id:3f2a9c1d7e04:config/deploy.env:1",
"location": "code",
"active": true
}
],
"dependencies": [
{ "name": "lodash", "ecosystem": "npm", "score": 85, "license": "MIT" }
],
"vulnerabilities": [
{
"ecosystem": "npm",
"package": "lodash",
"version": "4.17.4",
"id": "GHSA-jf85-cpcp-j695",
"cve": "CVE-2019-10744",
"summary": "Prototype Pollution in lodash",
"severity": "critical",
"fixed": "4.17.12",
"url": "https://osv.dev/vulnerability/GHSA-jf85-cpcp-j695"
}
],
"vulnerabilities_checked": true,
"fail_under": 40,
"packages": [
{ "ecosystem": "npm", "name": "lodash", "version": "4.17.4" }
],
"blocked_licenses": ["GPL-3.0"]
}Fields
secrets[]
| Field | Type | Meaning |
|---|---|---|
rule_id | string | One of the rules |
description | string | Human-readable secret type |
commit | string | Full SHA of the commit that added it |
author | string | Commit author name |
date | string | Commit time, RFC 3339 UTC |
path, line | string, number | Where it was added |
secret_redacted | string | Masked value; the full secret is never included |
fingerprint | string | ID for .dagsecignore |
location | string | code, test, docs or example |
active | boolean, optional | Whether the provider still accepts it; absent when not checked |
dependencies[]
Direct dependencies with a health score: name, ecosystem (npm, pypi, crates), score (0 to 100) and license when the registry reports one.
vulnerabilities[]
Sorted most severe first. severity is critical, high, moderate, low or unknown. cve and fixed are null when unknown.
Other fields
| Field | Meaning |
|---|---|
vulnerabilities_checked | false when OSV.dev couldn't be reached; an empty vulnerabilities then means unknown |
fail_under | Health score threshold used |
packages | Every pinned package version, direct and transitive; ecosystem is npm, pypi, crates, go, maven or nuget |
blocked_licenses | From .dagsec.toml; absent when there is no policy |
Markdown
--format markdown gives the pull request comment: a verdict line, then Leaked secrets (with fixtures in a collapsed section), Licenses (when there's a policy), Known vulnerabilities grouped per package with an All advisories section, and Dependencies.