What is SARIF?
The Static Analysis Results Interchange Format, or SARIF, is a JSON-based OASIS standard, now at version 2.1.0, that gives static analysis tools a shared way to report results, so scanners, CI pipelines and code hosting platforms can exchange findings in a single common structure.
How it works
Every SARIF document contains one or more runs. A run identifies the tool that generated it and enumerates the results that tool produced. Within each result you will find a rule ID, a severity level, a message, and the position in the source where the finding sits:
{
"version": "2.1.0",
"runs": [{
"tool": { "driver": { "name": "example-scanner" } },
"results": [{
"ruleId": "example-rule",
"level": "error",
"message": { "text": "S3 bucket has no access logging." },
"locations": [{ "physicalLocation": {
"artifactLocation": { "uri": "infra/main.tf" },
"region": { "startLine": 3 }
} }]
}]
}]
}Since the layout follows a common standard, a single viewer can present output from many different tools. GitHub code scanning accepts SARIF submitted through github/codeql-action/upload-sarif and renders those findings in the repository's Security tab as well as on pull requests.
Why it matters for compliance
When IaC compliance scanning emits SARIF, that file serves as a pre-apply record: it documents that a change was examined, which checks ran, and what those checks reported. Stored alongside the commit SHA and pipeline logs, it forms part of your Terraform audit evidence.
How compliance.tf applies it
ctfkit produces SARIF aimed at code scanning, in addition to JSON intended for OPA and for Spacelift metadata:
ctfkit scan plan.json --format sarif --out findings.sarifBy default, the ctfkit GitHub Action pushes SARIF to the Security tab (sarif: 'true'). This requires code scanning to be turned on for the repository, together with the security-events: write permission. If code scanning is absent, the upload will fail the job, so set sarif: 'false' in that case. Today ctfkit output is unsigned, though signing is on the roadmap.