chainsaw finding

Manage security findings (triage lifecycle: ack / snooze / resolve / suppress / reopen)

Manage security findings (triage lifecycle: ack / snooze / resolve / suppress / reopen)

SubcommandWhat it does
chainsaw finding ackAcknowledge a finding (move to status=acknowledged)
chainsaw finding assignAssign or unassign a finding’s owner
chainsaw finding feedbackSubmit FP / TP / retract feedback for a finding (Bayesian tuner signal)
chainsaw finding getShow a single finding’s full detail
chainsaw finding listList findings for the caller’s org
chainsaw finding reopenRe-open a resolved or suppressed finding (status=new)
chainsaw finding resolveMark a finding as resolved (status=resolved)
chainsaw finding snoozeSnooze a finding until the given timestamp
chainsaw finding suppressSuppress a finding (hides it from triage; does NOT bypass enforcement)
chainsaw finding [command]

Drive a finding through its lifecycle from the CLI — the same thing you would do on a finding’s page in the dashboard. Both go through the same server, so the permissions you need, the audit trail you leave, and the transitions that are allowed are identical either way.

chainsaw finding ack

Acknowledge a finding (move to status=acknowledged)

chainsaw finding ack <finding-id> [flags]

Flags

FlagTypeDefaultDescription
--jsonbool—Print updated finding as JSON

The global flags apply here too.

chainsaw finding assign

Assign or unassign a finding’s owner

chainsaw finding assign <finding-id> [flags]

Sets the assignee user id for a finding. Pass –user ’’ (or omit it) to clear the assignment. Mirrors the Web UI’s PATCH /api/findings/{id} behaviour where an empty assigneeId clears the row.

Flags

FlagTypeDefaultDescription
--clearbool—Clear the assignment (alternative to –user ‘’)
--jsonbool—Print updated finding as JSON
--userstring—User id to assign (empty string clears the assignment)

The global flags apply here too.

chainsaw finding feedback

Submit FP / TP / retract feedback for a finding (Bayesian tuner signal)

chainsaw finding feedback <finding-id> [flags]

Records an explicit operator opinion on a finding without changing its lifecycle status. –action accepts: false_positive, true_positive, retract. Use ‘suppress’ instead if you want to permanently exempt the package@version from enforcement; feedback is purely a signal for the tuning pipeline.

Flags

FlagTypeDefaultDescription
--actionstring—Required: false_positive | true_positive | retract
--jsonbool—Print server response as JSON
--notestring—Optional free-text note attached to the feedback event
--reason-chipstring—Optional one-tap categorization (e.g. ‘internal package’, ’test fixture’, ‘known good vendor’, ‘other’)
--referencing-event-idstring—Required for action=retract: the prior feedback event id being retracted

The global flags apply here too.

chainsaw finding get

Show a single finding’s full detail

chainsaw finding get <finding-id> [flags]

Flags

FlagTypeDefaultDescription
--jsonbool—Output as JSON

The global flags apply here too.

chainsaw finding list

List findings for the caller’s org

chainsaw finding list [flags]

Flags

FlagTypeDefaultDescription
--assigneestring—Filter by assignee user id
--jsonbool—Output as JSON
--limitint50Maximum rows to return (server caps via ListFilter.normalize)
--offsetint0Pagination offset
--packagestring—Filter by package name (exact match)
--policy-idstring—Filter by policy id
--severitystringSlice—Filter by severity (critical, high, medium, low, info). Repeatable.
--sortstring—Sort key (defaults to rank). See internal/finding/finding.go SortBy.
--statusstringSlice—Filter by status (new, acknowledged, snoozed, resolved, suppressed). Repeatable.

The global flags apply here too.

chainsaw finding reopen

Re-open a resolved or suppressed finding (status=new)

chainsaw finding reopen <finding-id> [flags]

Flags

FlagTypeDefaultDescription
--jsonbool—Print updated finding as JSON

The global flags apply here too.

chainsaw finding resolve

Mark a finding as resolved (status=resolved)

chainsaw finding resolve <finding-id> [flags]

Flags

FlagTypeDefaultDescription
--jsonbool—Print updated finding as JSON

The global flags apply here too.

chainsaw finding snooze

Snooze a finding until the given timestamp

chainsaw finding snooze <finding-id> [flags]

Hide a finding from the default queue until –until elapses. The server transitions snoozed → acknowledged automatically when the deadline passes. –until accepts an RFC3339 timestamp (e.g. 2026-12-31T15:04:05Z) or a Go-style duration relative to now via –for (e.g. –for 168h).

Flags

FlagTypeDefaultDescription
--forduration0sDuration from now (e.g. 24h, 7d=168h). Mutually exclusive with –until.
--jsonbool—Print updated finding as JSON
--untilstring—Wake time as RFC3339 timestamp (mutually exclusive with –for)

The global flags apply here too.

chainsaw finding suppress

Suppress a finding (hides it from triage; does NOT bypass enforcement)

chainsaw finding suppress <finding-id> [flags]

Suppression is a triage-only state flag: it hides the finding from the default triage view but does NOT bypass policy enforcement. The package stays blocked, and future installs of the same package@version mint new finding rows. To allow installs, create an exception instead (chainsaw exception create). Requires the findings:suppress permission. The reason is recorded on the row and shown in audit.

Flags

FlagTypeDefaultDescription
--jsonbool—Print updated finding as JSON
--reasonstring—Justification for suppression (required, recorded in audit)
--yesbool—Skip the confirmation prompt

The global flags apply here too.