Skip to content

feat: TOON flags and field selection - #7267

Open
robertolopezlopez wants to merge 1 commit into
mainfrom
chore/CLI-1859-gaf-toon
Open

robertolopezlopez wants to merge 1 commit into
mainfrom
chore/CLI-1859-gaf-toon

Conversation

@robertolopezlopez

@robertolopezlopez robertolopezlopez commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Pull Request Submission Checklist

  • Follows CONTRIBUTING guidelines
  • Commit messages
    are release-note ready, emphasizing
    what was changed, not how.
  • Includes detailed description of changes
  • Contains risk assessment (Low | Medium | High)
  • Highlights breaking API changes (if applicable)
  • Links to automated tests covering new functionality
  • Includes manual testing instructions (if necessary)
  • Updates relevant GitBook documentation (PR link: ___)
  • Includes product update to be announced in the next stable release notes

What does this PR do?

  • Pins both Go modules to latest GAF #766 feat/CLI-1859 pseudo-version.
  • Includes template-owned field selection, native Secrets support and a generic fallback for other findings.
  • Integration changes needed to be updated according to GAF changes.

Where should the reviewer start?

cliv2/go.mod and cliv2-private/go.mod.

How should this be manually tested?

Run the SCA and Secrets TOON suites with TEST_SNYK_COMMAND pointing to the built CLI.

Passed: format, lint, Go tests, public host build and version smoke check. The build reused the existing legacy CLI binary.

Previous-pin acceptance: ten cases failed on obsolete results[] assertions. Not rerun for this refresh; update contract assertions before merge.

What's the product update that needs to be communicated to CLI users?

None yet; TOON rollout remains separate.

Risk assessment (Low | Medium | High)?

Medium: shared framework update. Keep draft until acceptance passes and the upstream pin is refreshed.


Note

Medium Risk
Shared framework bump changes default TOON output for SCA and Secrets; consumers of the old results[] shape would break unless they use --toon=full or update parsers.

Overview
Pins go-application-framework in cliv2 and cliv2-private from v0.25.2 to new pseudo-versions that pull in GAF TOON work (field selection, product-specific sections, and related CLI-1859 behavior).

Jest acceptance for --toon / --toon-file-output is updated to match the new default TOON shape: no more results[] / UFM envelope checks (executionState, passFail, nested findings). Tests now assert org, the --toon=full hint, and typed tables such as sca[2]{fixable,id,pkg,severity}: or secrets[1]{file,line,rule,severity}: (plus empty sca: [] / secrets: []). File-output cases still expect human stdout not to contain those TOON sections.

Reviewed by Cursor Bugbot for commit da83672. Bugbot is set up for automated code reviews on this repo. Configure here.

@snyk-io

snyk-io Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@robertolopezlopez
robertolopezlopez added this pull request to stack #7269 September 16, 2026 08:52
@robertolopezlopez
robertolopezlopez removed this pull request from stack #7269 September 16, 2026 10:24
@robertolopezlopez
robertolopezlopez changed the base branch from main to chore/bump-adm-zip September 16, 2026 10:27
@robertolopezlopez
robertolopezlopez added this pull request to stack #7272 September 16, 2026 10:27
@robertolopezlopez
robertolopezlopez marked this pull request as ready for review September 16, 2026 10:32
@robertolopezlopez
robertolopezlopez requested a review from a team as a code owner September 16, 2026 10:32
@robertolopezlopez
robertolopezlopez marked this pull request as draft September 16, 2026 10:33
@snyk-pr-review-bot

This comment has been minimized.

Base automatically changed from chore/bump-adm-zip to main September 16, 2026 10:41
@robertolopezlopez
robertolopezlopez force-pushed the chore/CLI-1859-gaf-toon branch 2 times, most recently from 8882c33 to e641814 Compare September 16, 2026 10:44
@robertolopezlopez robertolopezlopez changed the title chore: bump GAF feat: TOON flags and field selection Sep 16, 2026
@robertolopezlopez
robertolopezlopez force-pushed the chore/CLI-1859-gaf-toon branch 6 times, most recently from fbb4f1c to 40a6989 Compare September 16, 2026 14:16
@octavian-snyk

octavian-snyk commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Good to go once GAF #766 is merged and the version is updated. If the output format is changed, tests may need an update.

@robertolopezlopez
robertolopezlopez force-pushed the chore/CLI-1859-gaf-toon branch 5 times, most recently from 4483ab7 to 71b965d Compare September 17, 2026 10:03
@robertolopezlopez
robertolopezlopez removed this pull request from stack #7272 September 17, 2026 10:21
@robertolopezlopez
robertolopezlopez added this pull request to stack #7283 September 17, 2026 10:21
@robertolopezlopez
robertolopezlopez marked this pull request as ready for review September 17, 2026 12:11
@snyk-pr-review-bot

This comment has been minimized.

@snyk-pr-review-bot

This comment has been minimized.

@snyk-pr-review-bot

This comment has been minimized.

@snyk-pr-review-bot

This comment has been minimized.

@snyk-pr-review-bot

This comment has been minimized.

@snyk-pr-review-bot

This comment has been minimized.

@snyk-pr-review-bot

This comment has been minimized.

@snyk-pr-review-bot

This comment has been minimized.

@snyk-pr-review-bot

Copy link
Copy Markdown

PR Reviewer Guide 🔍

🧪 PR contains tests
🔒 No security concerns identified
⚡ Recommended focus areas for review

Dependency Mismatch 🟠 [major]

cliv2-private/go.mod is pinned to github.com/snyk/go-application-framework pseudo-version v0.25.3-0.20260918144703-6b159eda3e77, whereas cliv2/go.mod is pinned to v0.25.3-0.20260922100300-82abfb703136. As noted in the PR description, both modules should be pinned to the latest GAF pseudo-version; the older Sept 18 commit still emits the obsolete results[] output envelope. Leaving cliv2-private on the older pin causes runtime output drift between public and private distributions and will fail TOON contract expectations in private builds.

github.com/snyk/go-application-framework v0.25.3-0.20260918144703-6b159eda3e77 // indirect
📚 Repository Context Analyzed

This review considered 6 relevant code sections from 4 files (average relevance: 1.00)

🤖 Repository instructions applied (from AGENTS.md)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants