chainsaw finding
Manage security findings (triage lifecycle: ack / snooze / resolve / suppress / reopen)
Manage security findings (triage lifecycle: ack / snooze / resolve / suppress / reopen)
| Subcommand | What it does |
|---|---|
chainsaw finding ack | Acknowledge a finding (move to status=acknowledged) |
chainsaw finding assign | Assign or unassign a finding’s owner |
chainsaw finding feedback | Submit FP / TP / retract feedback for a finding (Bayesian tuner signal) |
chainsaw finding get | Show a single finding’s full detail |
chainsaw finding list | List findings for the caller’s org |
chainsaw finding reopen | Re-open a resolved or suppressed finding (status=new) |
chainsaw finding resolve | Mark a finding as resolved (status=resolved) |
chainsaw finding snooze | Snooze a finding until the given timestamp |
chainsaw finding suppress | Suppress a finding (hides it from triage; does NOT bypass enforcement) |
chainsaw finding [command]
Drive a finding through its lifecycle from the CLI — the same thing you would do on a finding’s page in the dashboard. Both go through the same server, so the permissions you need, the audit trail you leave, and the transitions that are allowed are identical either way.
chainsaw finding ack
Acknowledge a finding (move to status=acknowledged)
chainsaw finding ack <finding-id> [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | — | Print updated finding as JSON |
The global flags apply here too.
chainsaw finding assign
Assign or unassign a finding’s owner
chainsaw finding assign <finding-id> [flags]
Sets the assignee user id for a finding. Pass –user ’’ (or omit it) to clear the assignment. Mirrors the Web UI’s PATCH /api/findings/{id} behaviour where an empty assigneeId clears the row.
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--clear | bool | — | Clear the assignment (alternative to –user ‘’) |
--json | bool | — | Print updated finding as JSON |
--user | string | — | User id to assign (empty string clears the assignment) |
The global flags apply here too.
chainsaw finding feedback
Submit FP / TP / retract feedback for a finding (Bayesian tuner signal)
chainsaw finding feedback <finding-id> [flags]
Records an explicit operator opinion on a finding without changing its lifecycle status. –action accepts: false_positive, true_positive, retract. Use ‘suppress’ instead if you want to permanently exempt the package@version from enforcement; feedback is purely a signal for the tuning pipeline.
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--action | string | — | Required: false_positive | true_positive | retract |
--json | bool | — | Print server response as JSON |
--note | string | — | Optional free-text note attached to the feedback event |
--reason-chip | string | — | Optional one-tap categorization (e.g. ‘internal package’, ’test fixture’, ‘known good vendor’, ‘other’) |
--referencing-event-id | string | — | Required for action=retract: the prior feedback event id being retracted |
The global flags apply here too.
chainsaw finding get
Show a single finding’s full detail
chainsaw finding get <finding-id> [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | — | Output as JSON |
The global flags apply here too.
chainsaw finding list
List findings for the caller’s org
chainsaw finding list [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--assignee | string | — | Filter by assignee user id |
--json | bool | — | Output as JSON |
--limit | int | 50 | Maximum rows to return (server caps via ListFilter.normalize) |
--offset | int | 0 | Pagination offset |
--package | string | — | Filter by package name (exact match) |
--policy-id | string | — | Filter by policy id |
--severity | stringSlice | — | Filter by severity (critical, high, medium, low, info). Repeatable. |
--sort | string | — | Sort key (defaults to rank). See internal/finding/finding.go SortBy. |
--status | stringSlice | — | Filter by status (new, acknowledged, snoozed, resolved, suppressed). Repeatable. |
The global flags apply here too.
chainsaw finding reopen
Re-open a resolved or suppressed finding (status=new)
chainsaw finding reopen <finding-id> [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | — | Print updated finding as JSON |
The global flags apply here too.
chainsaw finding resolve
Mark a finding as resolved (status=resolved)
chainsaw finding resolve <finding-id> [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | — | Print updated finding as JSON |
The global flags apply here too.
chainsaw finding snooze
Snooze a finding until the given timestamp
chainsaw finding snooze <finding-id> [flags]
Hide a finding from the default queue until –until elapses. The server transitions snoozed → acknowledged automatically when the deadline passes. –until accepts an RFC3339 timestamp (e.g. 2026-12-31T15:04:05Z) or a Go-style duration relative to now via –for (e.g. –for 168h).
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--for | duration | 0s | Duration from now (e.g. 24h, 7d=168h). Mutually exclusive with –until. |
--json | bool | — | Print updated finding as JSON |
--until | string | — | Wake time as RFC3339 timestamp (mutually exclusive with –for) |
The global flags apply here too.
chainsaw finding suppress
Suppress a finding (hides it from triage; does NOT bypass enforcement)
chainsaw finding suppress <finding-id> [flags]
Suppression is a triage-only state flag: it hides the finding from the default triage view but does NOT bypass policy enforcement. The package stays blocked, and future installs of the same package@version mint new finding rows. To allow installs, create an exception instead (chainsaw exception create). Requires the findings:suppress permission. The reason is recorded on the row and shown in audit.
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | — | Print updated finding as JSON |
--reason | string | — | Justification for suppression (required, recorded in audit) |
--yes | bool | — | Skip the confirmation prompt |
The global flags apply here too.