Skip to main content
Finding is the canonical output item. Execute streams one per detected issue.

Fields

A zero Timestamp is omitted from the wire rather than shipped as bogus epoch time. Leave it unset when the tool does not provide one.

Validation

Every finding is validated before transport. An invalid finding is a protocol violation, not noise — the run stops and reports a fatal error.
The rules:
  • Name is required.
  • Severity must be one of the five allowed values.

Severities

Severity is a closed set. Anything else fails validation.

Mapping severities

Collapse the tool’s own scale onto the five-value enum with an explicit table. Never guess, and never let an unmapped value reach Validate — it kills the stream.
When a scanner emits a severity outside the enum — for example nuclei’s unknown — map it to info rather than dropping the finding. The catalog treats every finding value as strict; normalize at the adapter boundary.

Mapping output to a finding

Keep a single toFinding function that maps one raw tool result onto connector.Finding. Return an error for results with no usable name so the caller can skip them instead of failing the whole run.