Skip to content

feat: enable stdout and file TOON for OS and Secrets - #7250

Closed
robertolopezlopez wants to merge 3 commits into
chore/CLI-1828from
func/CLI-1827
Closed

feat: enable stdout and file TOON for OS and Secrets#7250
robertolopezlopez wants to merge 3 commits into
chore/CLI-1828from
func/CLI-1827

Conversation

@robertolopezlopez

@robertolopezlopez robertolopezlopez commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

To be merged after #7239

./binary-releases/snyk-macos-arm64 test --toon

results[1]:
  - effectiveSummary:
      count: 8
      count_by:
        result_type:
          sca: 8
        severity:
          critical: 0
          high: 0
          low: 0
          medium: 8
    errors: null
    executionState: finished
    findings[11]:
      - attributes:
          cause_of_failure: false
          description: "## Overview\n\nAffected versions of this package are vulnerable to Uncontrolled Recursion in the `compose/resolve` phase due to using recursive function calls without a depth bound. An attacker can cause the application to throw a `RangeError` and potentially terminate the Node.js process by supplying a deeply nested YAML payload that exhausts the call stack.\n## PoC\n```js\r\nconst YAML = require('yaml');\r\n\r\n// ~10 KB payload: 5000 levels of nested flow sequences\r\nconst payload = '['.repeat(5000) + '1' + ']'.repeat(5000)

... cut because github does not allow such long text

./snyk-macos-arm64 test --toon-file-output=os.toon >> snyk_test.toon && cat os.toon

results[1]:
  - effectiveSummary:
      count: 8
      count_by:
        result_type:
          sca: 8
        severity:
          critical: 0
          high: 0
          low: 0
          medium: 8
    errors: null
    executionState: finished
    findings[11]:
      - attributes:
          cause_of_failure: false
          description: "## Overview\n[shescape](https://www.npmjs.org/package/shescape) is a simple shell escape library\n\nAffected versions of this package are vulnerable to Improper Encoding or Escaping of Output via the `getEscapeFunction` logic in `src/internal/unix/busybox.js`. An attacker can reveal the user's home directory and alter how a comman

... cut because github does not allow such long text

cat snyk_test.toon

<details>
results[1]:
  - effectiveSummary:
      count: 8
      count_by:
        result_type:
          sca: 8
        severity:
          critical: 0
          high: 0
          low: 0
          medium: 8
    errors: null
    executionState: finished
    findings[11]:
      - attributes:
          cause_of_failure: false
          description: "## Overview\n\nAffected versions of this package are vulnerable to Uncontrolled Recursion in the `compose/resolve` phase due to using recursive function cal

... cut because github does not allow such long text

./snyk-macos-arm64 test --toon --toon-file-output=os-both.toon && cat os-both.toon

results[1]:
  - effectiveSummary:
      count: 8
      count_by:
        result_type:
          sca: 8
        severity:
          critical: 0
          high: 0
          low: 0
          medium: 8
    errors: null
    executionState: finished
    findings[11]:
      - attributes:
          cause_of_failure: false
          description: "## Overview\n\nAffected versions of this package are vulnerable to Open Redirect due to missing verification of requested URLs. It allowed a victim to be redirected to a UNIX socket.\n## Remediation\nUpgrade `got` to version 11.8.5, 12.1.0 or higher.\n## References\n- [GitHub Diff](https://github.com/sindresorhus/got/compare/v12.0.3...v12.1.0)\n- [GitHub PR](https://github.com/sindresorhus/got/pull/2047)\n"
          evidence[2]:
            - path[4]{name,version}:
                snyk,1.0.0-monorepo
                snyk-nodejs-lockfile-parser,2.10.0
                @yarnpkg/core,4.5.0
                got,11.8.2
              source: dependency_path
            - path[5]{name,version}:
                snyk,1.0.0-monorepo
                snyk-docker-plugin,9.20.0
                snyk-nodejs-lockfile-parser,2.10.0
                @yarnpkg/core,4.5.0
                got,11.8.2
              source: dependency_path

... cut because github does not allow such long text

cat os-both.toon

results[1]:
  - effectiveSummary:
      count: 8
      count_by:
        result_type:
          sca: 8
        severity:
          critical: 0
          high: 0
          low: 0
          medium: 8
    errors: null
    executionState: finished
    findings[11]:
      - attributes:
          cause_of_failure: false
          description: "## Overview\n\nAffected versions of this package are vulnerable to Open Redirect due to missing verification of requested URLs. It allowed a victim to be redirected to a UNIX socket.\n## Remediation\nUpgrade `got` to version 11.8.5, 12.1.0 or higher.\n## References\n- [GitHub Diff](https://github.com/sindresorhus/got/compare/v12.0.3...v12.1.0)\n- [GitHub PR](https://github.com/sindresorhus/got/pull/2047)\n"
          evidence[2]:
            - path[4]{name,version}:
                snyk,1.0.0-monorepo
                snyk-nodejs-lockfile-parser,2.10.0

... cut because github does not allow such long text

./snyk-macos-arm64 test --toon --sarif-file-output=os.sarif

results[1]:
  - effectiveSummary:
      count: 8
      count_by:
        result_type:
          sca: 8
        severity:
          critical: 0
          high: 0
          low: 0
          medium: 8
    errors: null
    executionState: finished
    findings[11]:
      - attributes:
          cause_of_failure: false
          description: "## Overview\n[marked](https://marked.js.org/) is a low-level compiler for parsing markdown without caching or blocking for long periods of time.\n\nAffected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) when passing unsanitized user input to `inline.reflinkSearch`, if it is not being parsed by a time-limited worker thread.\r\n\r\n## PoC\r\n```js\r\nimport * as marked from 'marked';\r\n\r\nconsole.log(marked.parse(`[x]: x\r\n\r\n\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](\\\\[\\\\](`));\r\n```\n\n## Details\n\nDenial of Service (DoS) describes a family of attacks, all aimed at making a system inaccessible to its original and legitimate users. There are many types of DoS attacks, ranging from trying to clog the network pipes to the system by gen

... cut because github does not allow such long text

cat os.sarif

{"$schema": "https://docs.oasis-open.org/sarif/sarif/v2.1.0/errata01/os/schemas/sarif-schema-2.1.0.json","version": "2.1.0","runs": [{"tool": {"driver" : {"name" : "Snyk Open Source","semanticVersion" : "1.1307.0-preview.c3e52bd2b8af9be2a8d746dd1e8623c4c1ceb0b4","version" : "1.1307.0-preview.c3e52bd2b8af9be2a8d746dd1e8623c4c1ceb0b4","informationUri" : 
asd

... cut because github does not allow such long text

./snyk-macos-arm64 secrets test --toon

  - effectiveSummary:
      count: 33
      count_by:
        result_type:
          secrets: 33
        severity:
          critical: 2
          high: 31
          low: 0
          medium: 0
    errors: null
    executionState: finished
    findings[33]:
      - attributes:
          cause_of_failure: false
          component_key: secrets
          description: Detected a JSON Web Token, which may lead to unauthorized access to web application and sensitive data.
          evidence: []
          finding_type: secrets
          key: 7ddc12bd-4b1c-5991-8533-e27002eebf2c
          locations[1]{file_path,from_column,from_line,to_column,to_line,type}:
            test/jest/unit/lib/ecosystems/resolve-monitor.facts.spec.ts,6,14,233,14,source
          policy_modifications: []
          problems[2]:
            - id: CWE-798
              source: cwe
            - categories[1]: Security
              help: Detected a JSON Web Token, which may lead to unauthorized access to web application and sensitive data.
              id: json-web-token
              name: JSON Web Token
              precision: very-high
              severity: high
              short_description: JSON Web Token
              source: secret

... cut because github does not allow such long text

./snyk-macos-arm64 secrets test --toon-file-output=secrets.toon

Testing  (/Users/roberto/go/cli) ...

Open Secrets issues: 33

 ✗ [HIGH] Generic Secret Key
   Finding ID: 05836e3f-e37a-54ac-ab68-290fc65403cb
   Info: Detected a generic secret, which could lead to unauthorized access and sensitive data exposure.
   Path: test/fixtures/demo-os/core/test/utils/fixtures/export/export-003-badValidation.json, line 64 to 64

 ✗ [HIGH] Generic Secret Key
   Finding ID: 1ca01ed1-61cd-5973-80a8-521ef9481c96
   Info: Detected a generic secret, which could lead to unauthorized access and sensitive data exposure.
   Path: ts-binary-wrapper/src/common.ts, line 385 to 385

 ✗ [HIGH] Generic Secret Key
   Finding ID: 2a90c607-69b7-5123-88b8-687778b4923d
   Info: Detected a generic secret, which could lead to unauthorized access and sensitive data exposure.
   Path: test/fixtures/demo-os/core/test/utils/fixtures/export/export-003-mu-noOwner.json, line 75 to 75

 ✗ [HIGH] Generic Secret Key
   Finding ID: 2fe719fd-f05b-5a4b-998a-340e07987d3b
   Info: Detected a generic secret, which could lead to unauthorized access and sensitive data exposure.
   Path: test/fixtures/demo-os/core/test/utils/fixtures/data-generator.js, line 87 to 87
   Path: test/fixtures/demo-os/core/test/utils/fixtures/data-generator.js, line 93 to 93
   Path: test/fixtures/demo-os/core/test/utils/fixtures/data-generator.js, line 99 to 99
   Path: test/fixtures/demo-os/core/test/utils/fixtures/data-generator.js, line 105 to 105
   Path: test/fixtures/demo-os/core/test/utils/fixtures/data-generator.js, line 111 to 111
   Path: test/fixtures/demo-os/core/test/utils/fixtures/data-generator.js, line 306 to 306

 ✗ [HIGH] Generic Secret Key
   Finding ID: 32ba2ff1-a0e2-57fd-84bf-0733d827eb96
   Info: Detected a generic secret, which could lead to unauthorized access and sensitive data exposure.
   Path: test/fixtures/sast/shallow_sast_webgoat/DeserializeTest.java, line 82 to 82

 ✗ [HIGH] Generic Secret Key

... cut because github does not allow such long text

cat secrets.toon

results[1]:
  - effectiveSummary:
      count: 33
      count_by:
        result_type:
          secrets: 33
        severity:
          critical: 2
          high: 31
          low: 0
          medium: 0
    errors: null
    executionState: finished
    findings[33]:
      - attributes:
          cause_of_failure: false
          component_key: secrets
          description: Detected a JSON Web Token, which may lead to unauthorized access to web application and sensitive data.
          evidence: []
          finding_type: secrets
          key: 7ddc12bd-4b1c-5991-8533-e27002eebf2c
          locations[1]{file_path,from_column,from_line,to_column,to_line,type}:
            test/jest/unit/lib/ecosystems/resolve-monitor.facts.spec.ts,6,14,233,14,source
          policy_modifications: []
          problems[2]:
            - id: CWE-798
              source: cwe
            - categories[1]: Security
              help: Detected a JSON Web Token, which may lead to unauthorized access to web application and sensitive data.
              id: json-web-token
              name: JSON Web Token
              precision: very-high
              severity: high
              short_description: JSON Web Token
              source: secret

... cut because github does not allow such long text

./snyk-macos-arm64 secrets test --toon --toon-file-output=secrets-both.toon

results[1]:
  - effectiveSummary:
      count: 34
      count_by:
        result_type:
          secrets: 34
        severity:
          critical: 2
          high: 32
          low: 0
          medium: 0
    errors: null
    executionState: finished
    findings[34]:
      - attributes:
          cause_of_failure: false
          component_key: secrets
          description: Detected a generic secret, which could lead to unauthorized access and sensitive data exposure.
          evidence: []
          finding_type: secrets
          key: 6170ee8c-5471-5820-b991-f5ac25952c7c
          locations[1]{file_path,from_column,from_line,to_column,to_line,type}:
            test/jest/unit/lib/ecosystems/fixtures/scan-results.ts,28,18,50,18,source
          policy_modifications: []
          problems[2]:
            - categories[1]: Security
              help: Detected a generic secret, which could lead to unauthorized access and sensitive data exposure.
              id: generic-secret
              name: Generic Secret Key
              precision: very-high
              severity: high
              short_description: Generic Secret Key
              source: secret
              tags[2]: "type:secret-key","provider:generic"
            - id: CWE-798

... cut because github does not allow such long text

cat secrets-both.toon

results[1]:
  - effectiveSummary:
      count: 34
      count_by:
        result_type:
          secrets: 34
        severity:
          critical: 2
          high: 32
          low: 0
          medium: 0
    errors: null
    executionState: finished
    findings[34]:
      - attributes:
          cause_of_failure: false
          component_key: secrets
          description: Detected a generic secret, which could lead to unauthorized access and sensitive data exposure.
          evidence: []
          finding_type: secrets
          key: 6170ee8c-5471-5820-b991-f5ac25952c7c
          locations[1]{file_path,from_column,from_line,to_column,to_line,type}:
            test/jest/unit/lib/ecosystems/fixtures/scan-results.ts,28,18,50,18,source
          policy_modifications: []
          problems[2]:
            - categories[1]: Security
              help: Detected a generic secret, which could lead to unauthorized access and sensitive data exposure.
              id: generic-secret
              name: Generic Secret Key
              precision: very-high
              severity: high
              short_description: Generic Secret Key
              source: secret
              tags[2]: "type:secret-key","provider:generic"
            - id: CWE-798

... cut because github does not allow such long text

./snyk-macos-arm64 secrets test --toon --sarif-file-output=secrets.sarif

results[1]:
  - effectiveSummary:
      count: 34
      count_by:
        result_type:
          secrets: 34
        severity:
          critical: 2
          high: 32
          low: 0
          medium: 0
    errors: null
    executionState: finished
    findings[34]:
      - attributes:
          cause_of_failure: false
          component_key: secrets
          description: Detected a JSON Web Token, which may lead to unauthorized access to web application and sensitive data.
          evidence: []
          finding_type: secrets
          key: 7ddc12bd-4b1c-5991-8533-e27002eebf2c
          locations[1]{file_path,from_column,from_line,to_column,to_line,type}:
            test/jest/unit/lib/ecosystems/resolve-monitor.facts.spec.ts,6,14,233,14,source
          policy_modifications: []
          problems[2]:
            - categories[1]: Security
              help: Detected a JSON Web Token, which may lead to unauthorized access to web application and sensitive data.
              id: json-web-token
              name: JSON Web Token
              precision: very-high
              severity: high
              short_description: JSON Web Token
              source: secret
              tags[2]: "type:web-token","provider:JWT"
            - id: CWE-798

... cut because github does not allow such long text

cat secrets.sarif

{"$schema": "https://docs.oasis-open.org/sarif/sarif/v2.1.0/errata01/os/schemas/sarif-schema-2.1.0.json","version": "2.1.0","runs": [{"tool": {"driver" : {"name" : "Snyk Secrets","semanticVersion" : "1.1307.0-preview.c3e52bd2b8af9be2a8d746dd1e8623c4c1ceb0b4","version" : "1.1307.0-preview.c3e52bd2b8af9be2a8d746dd1e8623c4c1ceb0b4","informationUri" : "https://docs.snyk.io/","rules" : [{"id": "generic-secret","shortDescription": {"text": "Generic Secret Key"},

... cut because github does not allow such long text

Pull Request Submission Checklist

  • Follows CONTRIBUTING guidelines
  • Commit messages
    are release-note ready, emphasizing
    what was changed, not how.
  • Includes detailed description of changes
  • Contains risk assessment (Low | Medium | High)
  • Highlights breaking API changes (if applicable)
  • Links to automated tests covering new functionality
  • Includes manual testing instructions (if necessary)
  • Updates relevant GitBook documentation (PR link: ___)
  • Includes product update to be announced in the next stable release notes

What does this PR do?

Wires TOON output for OS and Secrets using the existing GAF renderer.

  • Registers --toon and --toon-file-output.
  • Routes OS stdout through GAF when --toon is set.
  • Exposes existing Secrets stdout support and adds TOON to its custom file writers.
  • It does not handle errors nor perform validation: that's to be done in CLI-1828.

Where should the reviewer start?

cliv2/pkg/core/main.go: flag registration, runTestCommand, and runSecretsTestCommand. Then main_test.go for coverage.

Check that parsed --toon reaches configuration before the OS presenter flag is read; the open review thread covers this.

How should this be manually tested?

Build with make build. From projects supported by OS and Secrets, run the built CLI with test and secrets test:

  • --toon: TOON on stdout.
  • --toon-file-output=result.toon: TOON in the file, normal stdout.
  • Both flags: TOON on stdout and in the file.

Check clean and failing scans. Confirm exit codes and existing JSON/SARIF output still work.

What's the product update that needs to be communicated to CLI users?

TOON output for Open Source and Secrets scans via --toon and --toon-file-output.


Note

Medium Risk
Changes how primary test and secrets test commands route structured output, which can affect CI and tooling that parse stdout; behavior is flag-gated and covered by new tests.

Overview
Adds TOON as a scan output option for Open Source (snyk test) and Secrets (snyk secrets test) by wiring new CLI flags into the existing GAF output workflow.

Registers persistent --toon (console) and --toon-file-output flags on the root command. snyk test now uses a dedicated runTestCommand handler: when --toon is set, it sets internal_use_ufm_presenter so stdout TOON is rendered via GAF instead of the local unified presenter; file-only TOON does not flip that flag. snyk secrets test extends the SARIF/JSON file-writer setup with an optional TOON file writer (via extraFileWriters on runTestCommandWithSarifEqualJson). The test and monitor workflow branches are split so only test gets the new runner.

Unit tests cover TOON file emission for secrets, presenter-flag behavior, and flag parsing/idempotency.

Reviewed by Cursor Bugbot for commit dca39ae. Bugbot is set up for automated code reviews on this repo. Configure here.

@robertolopezlopez
robertolopezlopez requested a review from a team as a code owner September 9, 2026 13:57
@snyk-io

snyk-io Bot commented Sep 9, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@snyk-pr-review-bot

This comment has been minimized.

@snyk-pr-review-bot

This comment has been minimized.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 065d24f. Configure here.

Comment thread cliv2/pkg/core/main.go Outdated
@robertolopezlopez
robertolopezlopez marked this pull request as draft September 9, 2026 14:00
@robertolopezlopez robertolopezlopez changed the title feat: enable stdout and file TOON for OS and secrets feat: enable stdout and file TOON for OS Sep 9, 2026
@robertolopezlopez robertolopezlopez changed the title feat: enable stdout and file TOON for OS feat: enable stdout and file TOON for OS and Secrets Sep 9, 2026
@robertolopezlopez
robertolopezlopez marked this pull request as ready for review September 9, 2026 14:39
@snyk-pr-review-bot

This comment has been minimized.

@snyk-pr-review-bot

Copy link
Copy Markdown

PR Reviewer Guide 🔍

🧪 PR contains tests
🔒 No security concerns identified
⚡ No major issues detected
📚 Repository Context Analyzed

This review considered 14 relevant code sections from 9 files (average relevance: 0.92)

🤖 Repository instructions applied (from AGENTS.md)

@robertolopezlopez
robertolopezlopez marked this pull request as ready for review September 9, 2026 17:12
@octavian-snyk

Copy link
Copy Markdown
Contributor

Why do we want to add this here, instead of in GAF?

@robertolopezlopez
robertolopezlopez marked this pull request as draft September 10, 2026 07:36
@robertolopezlopez
robertolopezlopez changed the base branch from main to chore/CLI-1828 September 10, 2026 07:50
@robertolopezlopez
robertolopezlopez added this pull request to stack #7254 September 10, 2026 07:50
@robertolopezlopez
robertolopezlopez removed this pull request from stack #7254 September 10, 2026 11:50
@robertolopezlopez
robertolopezlopez deleted the func/CLI-1827 branch September 10, 2026 12:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants