Exports
You can export any report, anonymous or in a project, from its Export menu in the formats below. Exports use the same data as the page, so an export can’t show a better result than the report it came from.
Formats
- Printable report
- Opens in a new tab as an A4 document: a cover, a one-page summary, the fix plan, and appendices with every finding and the inventory. To get a PDF, print it from the browser and choose Save as PDF. ?format=html&view=inline
- Offline HTML
- The same document as a single file to download. It doesn’t load anything from the network, so it opens offline and you can attach or archive it as it is. ?format=html
- Fix plan CSV
- One row per upgrade, in plan order. ?format=plan.csv
- Findings CSV
- One row per finding, including suppressed ones, with who suppressed each and why. ?format=csv
- JSON
- The complete report, schema version 1. The CI script reads this format, and it’s the portable copy of your data. ?format=json
From a project
A project exports its current report with your own decisions applied. A muted finding doesn’t disappear: it’s listed as ruled out, with your reason and a note that a user made the call. Early access adds a branded report with your company name and logo, and Report studio lets you preview and print it before downloading.
Checking a report is unchanged
The printable report lists a SHA-256 fingerprint of the report’s JSON export. Anyone with the JSON file can check it against that value using sha256sum. The printable report has no generation time, so the same report always produces the same document and the same fingerprint.
Fetching an export directly
An anonymous report’s exports are at /api/reports/<id>/export with the query shown above. The address is the only key, so anyone who has it can fetch them until the report expires. A project’s exports are at /api/projects/<id>/export and you need to be signed in as its owner. For a script that fetches the JSON and HTML for you, see scanning from CI.