PDF reports
Download PDF security reports for your whole workspace, a git workspace, a repository or a single scan, from the web app or the REST API.
Vulnara turns the same data you see in the web app into PDF reports you can share with people who do not use Vulnara: management, auditors, customers. There are four: a security summary for your whole workspace, and reports for one git workspace, one repository or one scan.
What it is for
- Giving a security owner or manager a readable answer to "how are we doing, and where is the problem?"
- Handing evidence of a scan to someone outside the team.
- Keeping a dated record of your posture at a point in time.
How it works
Every report is an A4 landscape PDF with a Vulnara header and a page footer on every page. Each opens with the score and a plain-language executive summary: how the posture reads, how urgent the critical and high findings are, which repository is weakest and how much has been scanned. Severities use the same scale and colours as the web app, advisory ids link to their NVD or GitHub advisory page, file paths link to the line on GitHub, GitLab or Bitbucket, and every repository, git workspace and scan links back to the web app.
The four reports
- Security summary: your whole workspace. Overall posture with the headline score, never-scanned and open-finding counts, the executive summary, a Workspaces table (when you have more than one git workspace) showing each git workspace's repositories, scanned and unscanned counts, findings and worst score, findings by severity, score by repository, findings by scanner, the repository inventory, the full scan history grouped by scanner, and a Not yet scanned list.
- Workspace report: one git workspace. Its score, coverage, executive summary, findings by severity, score by repository and a table of its repositories.
- Repository report: one repository across every scanner. Its score, findings by severity, a Scan results table with one row per scanner (that scanner's current scan), and the code, secret and dependency findings from those scans.
- Scan report: one scan. Its status, finding count, critical count and duration, findings by severity, and its Code and secret findings and Vulnerable dependencies tables.
Dependency tables show severity, package, installed version, fixed-in version (or "not fixed") and advisory. Finding tables are sorted with the most severe first.
Scores in reports
- The headline score in the security summary is the same score as on the dashboard. See Security score.
- Scores are labelled with a band: Strong (80 and above), Good (60 and above), Fair (40 and above) or Needs attention (below 40).
- A repository that has never been scanned shows as Not assessed, not as 0. Reports say how many repositories are unscanned and that unscanned is not the same as clean.
- A scan that did not finish successfully has no score. Its report says the scan did not complete and reports no findings, because a scan that never ran finds nothing and would otherwise read as clean.
- A git workspace's score in the security summary is its worst repository's score, not an average, and the report says so.
- In the security summary, a repository scanned by several scanners is counted once in the totals, while all its scans appear in the scan history.
What you can set
- Report type and scope: the security summary, or one git workspace, repository or scan.
- Workspace: reports cover the workspace you are working in. Switch workspace first to report on another.
- Schedule: to have a report emailed on a schedule instead of downloading it, see Schedule recurring scans.
Do it
In the web app
Every report is a Download report button in the web app at vulnara.rso.dev:
- Security summary: on the Dashboard, next to the period selector. Schedule beside it sets up a scheduled summary.
- Workspace report: in the git workspace's detail panel under Workspaces.
- Repository report: in the repository's detail drawer, or from its row actions under Repositories.
- Scan report: on the scan result page under Repository Scans.
The Vulnerabilities explorer also offers a repository or scan report when it is filtered to a single repository or scan. The report covers everything in that repository or scan, not only the rows the filters left.
The file is saved as vulnara-security-summary_<workspace>_<date>.pdf, or vulnara-<kind>-report_<workspace>_<name>_<date>.pdf for the others.
With the REST API
The reports are also plain HTTP downloads at https://vulnara-gw.rso.dev:
GET /reports/summary: the security summary.GET /reports/workspace/:id: a git workspace report.GET /reports/repository/:id: a repository report.GET /reports/scan/:id: a scan report.
Send your access token as Authorization: Bearer <token>. To choose the workspace, send its id in the X-Tenant header; without it, your first workspace is used.
curl -H "Authorization: Bearer $VULNARA_TOKEN" \
-H "X-Tenant: <workspace id>" \
-o summary.pdf \
https://vulnara-gw.rso.dev/reports/summarySee the REST reference for the full list of routes.
Good to know
- Any member of the workspace can download reports.
- A report lists at most 400 findings, most severe first. When there are more, it says how many of the total it shows and that the full list is in the web app.
- Text a PDF font cannot show, such as some characters in a matched value, is replaced rather than failing the report. Long values are shortened with
...to fit their column. - A missing or invalid token returns 401, and a workspace you are not a member of returns 403. A report that cannot be generated returns 404 or 502. In the web app, a failed download shows an error and saves no file.