feat: TOON flags and field selection - #7267
robertolopezlopez wants to merge 1 commit into
Conversation
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
0909098 to
2dc3bb8
Compare
2dc3bb8 to
4381715
Compare
This comment has been minimized.
This comment has been minimized.
8882c33 to
e641814
Compare
fbb4f1c to
40a6989
Compare
|
Good to go once GAF #766 is merged and the version is updated. If the output format is changed, tests may need an update. |
4483ab7 to
71b965d
Compare
71b965d to
36c5407
Compare
This comment has been minimized.
This comment has been minimized.
36c5407 to
bd9a4fe
Compare
This comment has been minimized.
This comment has been minimized.
bd9a4fe to
af9f99f
Compare
This comment has been minimized.
This comment has been minimized.
af9f99f to
d97beeb
Compare
This comment has been minimized.
This comment has been minimized.
d97beeb to
42c2269
Compare
This comment has been minimized.
This comment has been minimized.
42c2269 to
832ac6a
Compare
This comment has been minimized.
This comment has been minimized.
832ac6a to
ab48fd8
Compare
This comment has been minimized.
This comment has been minimized.
ab48fd8 to
099b5f9
Compare
This comment has been minimized.
This comment has been minimized.
099b5f9 to
da83672
Compare
PR Reviewer Guide 🔍
|
Pull Request Submission Checklist
are release-note ready, emphasizing
what was changed, not how.
What does this PR do?
feat/CLI-1859pseudo-version.Where should the reviewer start?
cliv2/go.modandcliv2-private/go.mod.How should this be manually tested?
Run the SCA and Secrets TOON suites with
TEST_SNYK_COMMANDpointing to the built CLI.Passed: format, lint, Go tests, public host build and version smoke check. The build reused the existing legacy CLI binary.
Previous-pin acceptance: ten cases failed on obsolete
results[]assertions. Not rerun for this refresh; update contract assertions before merge.What's the product update that needs to be communicated to CLI users?
None yet; TOON rollout remains separate.
Risk assessment (Low | Medium | High)?
Medium: shared framework update. Keep draft until acceptance passes and the upstream pin is refreshed.
Note
Medium Risk
Shared framework bump changes default TOON output for SCA and Secrets; consumers of the old
results[]shape would break unless they use--toon=fullor update parsers.Overview
Pins
go-application-frameworkincliv2andcliv2-privatefromv0.25.2to new pseudo-versions that pull in GAF TOON work (field selection, product-specific sections, and related CLI-1859 behavior).Jest acceptance for
--toon/--toon-file-outputis updated to match the new default TOON shape: no moreresults[]/ UFM envelope checks (executionState,passFail, nestedfindings). Tests now assertorg, the--toon=fullhint, and typed tables such assca[2]{fixable,id,pkg,severity}:orsecrets[1]{file,line,rule,severity}:(plus emptysca: []/secrets: []). File-output cases still expect human stdout not to contain those TOON sections.Reviewed by Cursor Bugbot for commit da83672. Bugbot is set up for automated code reviews on this repo. Configure here.