Finding is the canonical output item. Execute streams one per detected issue.
Fields
A zero
Timestamp is omitted from the wire rather than shipped as bogus epoch time. Leave it unset when the tool does not provide one.
Validation
Every finding is validated before transport. An invalid finding is a protocol violation, not noise — the run stops and reports a fatal error.Nameis required.Severitymust be one of the five allowed values.
Severities
Severity is a closed set. Anything else fails validation.
Mapping severities
Collapse the tool’s own scale onto the five-value enum with an explicit table. Never guess, and never let an unmapped value reachValidate — it kills the stream.
Mapping output to a finding
Keep a singletoFinding function that maps one raw tool result onto connector.Finding. Return an error for results with no usable name so the caller can skip them instead of failing the whole run.
