Output and reporting
--format text is for reading; --format summary is for a one-screen count;
--format json is for keeping; --format sarif is for a code-scanning
dashboard; --format fixplan is for acting.
- Reports and formatting — the summary, the text report, remediation, colour.
- Severity and filtering — severity sources,
--severity,--fixed-only,--triage. - VEX and vendor sources —
--vexhub,--distro-feeds,--prefer-vendor. - Contributing VEX back —
--vex-out, merged reports, CSAF. - JSON, SARIF, and gating — machine formats and
--fail-on.