chainsaw report

Cross-org reports derived from install events

Cross-org reports derived from install events

SubcommandWhat it does
chainsaw report exposureAnswer “between dates X and Y, what packages did we install?” — IR-class exposure-window query
chainsaw report multiversionShow packages installed at multiple versions across repos
chainsaw report provenanceShow what fraction of installed packages have verified provenance attestations
chainsaw report slaPer-team mean and median time-to-remediate for resolved violations
chainsaw report [command]

chainsaw report exposure

Answer “between dates X and Y, what packages did we install?” — IR-class exposure-window query

chainsaw report exposure [flags]

Flags

FlagTypeDefaultDescription
--ecosystemstring—Filter by ecosystem (e.g. npm, pypi, maven)
--endstring—End of window, RFC3339 or YYYY-MM-DD (required). A bare date is extended to 23:59:59Z so the day itself is included; an explicit timestamp is used as given.
--formatstringtextOutput format: text or json
--startstring—Inclusive start of window, RFC3339 or YYYY-MM-DD (required). A bare date starts at 00:00:00Z.

The global flags apply here too.

chainsaw report multiversion

Show packages installed at multiple versions across repos

chainsaw report multiversion [flags]

Flags

FlagTypeDefaultDescription
--ecosystemstring—Filter by ecosystem (e.g. npm, pypi, maven)
--formatstringtextOutput format: text or json
--min-versionsint0Exclude packages with fewer distinct versions

The global flags apply here too.

chainsaw report provenance

Show what fraction of installed packages have verified provenance attestations

chainsaw report provenance [flags]

Flags

FlagTypeDefaultDescription
--ecosystemstring—Filter by ecosystem (e.g. npm, pypi, maven)
--formatstringtextOutput format: text or json

The global flags apply here too.

chainsaw report sla

Per-team mean and median time-to-remediate for resolved violations

chainsaw report sla [flags]

Flags

FlagTypeDefaultDescription
--formatstringtextOutput format: text or json
--sincestring—Only consider violations resolved at or after this point, RFC3339 or YYYY-MM-DD. A bare date starts at 00:00:00Z.

The global flags apply here too.