chainsaw report
Cross-org reports derived from install events
Copies the raw Markdown source of this guide, for pasting into an LLM or notes.
Cross-org reports derived from install events
| Subcommand | What it does |
|---|---|
chainsaw report exposure | Answer “between dates X and Y, what packages did we install?” — IR-class exposure-window query |
chainsaw report multiversion | Show packages installed at multiple versions across repos |
chainsaw report provenance | Show what fraction of installed packages have verified provenance attestations |
chainsaw report sla | Per-team mean and median time-to-remediate for resolved violations |
chainsaw report [command]
chainsaw report exposure
Answer “between dates X and Y, what packages did we install?” — IR-class exposure-window query
chainsaw report exposure [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--ecosystem | string | — | Filter by ecosystem (e.g. npm, pypi, maven) |
--end | string | — | End of window, RFC3339 or YYYY-MM-DD (required). A bare date is extended to 23:59:59Z so the day itself is included; an explicit timestamp is used as given. |
--format | string | text | Output format: text or json |
--start | string | — | Inclusive start of window, RFC3339 or YYYY-MM-DD (required). A bare date starts at 00:00:00Z. |
The global flags apply here too.
chainsaw report multiversion
Show packages installed at multiple versions across repos
chainsaw report multiversion [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--ecosystem | string | — | Filter by ecosystem (e.g. npm, pypi, maven) |
--format | string | text | Output format: text or json |
--min-versions | int | 0 | Exclude packages with fewer distinct versions |
The global flags apply here too.
chainsaw report provenance
Show what fraction of installed packages have verified provenance attestations
chainsaw report provenance [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--ecosystem | string | — | Filter by ecosystem (e.g. npm, pypi, maven) |
--format | string | text | Output format: text or json |
The global flags apply here too.
chainsaw report sla
Per-team mean and median time-to-remediate for resolved violations
chainsaw report sla [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--format | string | text | Output format: text or json |
--since | string | — | Only consider violations resolved at or after this point, RFC3339 or YYYY-MM-DD. A bare date starts at 00:00:00Z. |
The global flags apply here too.