Overview
Use the Reporting page to generate detailed, customizable reports that summarize SAST, SCA, and DAST issues captured in tests. Report types range from developer-focused summaries to executive overviews and compliance reports, and offer insights into vulnerabilities, test trends, checkers used in testing, and the risk posture of applications in your portfolio. Note the following:
- Reports are automatically deleted after 30 days. Up to 1000 reports can be saved at a time.
- Only the user who created a report can download it. Share reports in PDF or JSON format.
- It can take up to 60 minutes for:
- Issue data from a test to affect reports.
- Issue and component triage actions to affect reports. Note: Dismissed issues and excluded components (via issue and component triage) are not included in reports. Issue and component triage actions only affect reports after changes are approved.
- Components you add, edit, or delete to affect reports.
- Changes made to application, project, and branch settings (including application labels) to affect reports.
- Changes made to file and folder exclusion rules to affect reports.
- Reporting events are tracked in the audit logs.
- Issues you import from third-party tools appear in reports, but the components and licenses associated with issues you import do not.
- You can save report settings as report configurations to enable reports to be re-run. These saved configurations can also be shared with other users and groups in your organization. Each copy is unique to the recipient, letting them make changes without affecting the original configuration. Unless you're an admin for your organization, you can only share configurations with users or groups who have access to all applications mentioned in the configuration. If you are an organization admin, sharing with people who can't already access the relevant applications will allow recipients to see the configuration values, so you'll be warned of this before confirming the share action.
Available reports
You can generate the following reports:
| Type of report | Description |
|---|---|
| Developer Detail Dynamic | An overview of the issues in the selected application scope. Provides DAST issue details organized by the issue type and includes severity, location, and first detected date. |
| Developer Detail SCA | An overview of the issues in the selected application scope. Provides issue details organized by the component and includes the severity, vulnerability ID, Issue type, CWE, exposure, and first detected date of each issue. |
| Developer Detail Static* | An overview of the issues in the selected application scope. Provides issue details organized by the issue type and includes severity, location, file name, line number, and first detected date. |
| Executive Summary Report* | Provides an overview of your portfolio and modules that detail the overall risk posture. It includes issue summaries at the portfolio and application levels, detected and absent issue charts, issue trend charts, top issue types and top issues with policy violations. |
| Issue Overview* | A high level overview of your applications and projects. The report provides the total issue counts at the application level, and provides the new, recurrent, and total issue counts at the project level. This shows the risk posture across the entire portfolio. |
| Issue Summary* | Includes a summary of its scope and issue summaries by severity, per application(s), per project(s), and by issue type including top 10 vulnerable applications, exposure (SCA only) and more. |
| Security Audit* | Identifies vulnerable areas in the different components of your application that may be exploited by a malicious users, and estimates the application's protection from common attacks. This report also assesses the overall security risk for your application across all threat areas. It includes exposure (SCA only). |
| Software bill of materials (SBOM) | Creates a SPDX or CycloneDX-compatible SBOM report in JSON format. |
| Standard Compliance* | Provides issue counts for each application as it relates to a selected standard, exposure (SCA only), as well as a view of the total issues found per standard. |
| Standard Compliance Detail* | Along with the information in the Standard Compliance Report, this includes the issue counts for each project. It also provides issue details organized by test type and standard for each issue. |
| Test Summary Report | For applications and/or projects (depending on selected scope), shows first and last test, number of tests in a time period, test trends, assessment types scanned and a list of applications and/or projects not tested in time period. This report lists the versions of Coverity and Rapid Scan Static (Sigma) used in the latest SAST tests. |
| Notices File Report | The Notices File report provides a customizable list of open source components, the associated license text and copyright statements to help manage and leverage your licenses. If enabled, deep license data can be selected to be included. |
Report modules
Most reports include a Report Modules section where you can control which modules appear in the generated report and, for select modules, customize their content. This lets you tailor reports for your audience — for example, removing sections that aren't relevant to your stakeholders, or editing narrative text to add organizational context.
Note the following:
- All modules are enabled by default, except Tool checker information, which must be manually enabled.
- For modules that include an Edit button, you can customize the module's content. Depending on the module, selecting Edit reveals editable text fields or checkboxes to include or exclude specific information, like charts or table columns.
- Module selections and content customizations can be saved in report configurations.
Allow reporting notifications
In order to receive email notifications that your report is ready, check that your personal notification settings are set correctly.
Save report configurations
If you find you generate the same report on a routine basis, consider saving the report's settings as a report configuration. Doing so allows you to quickly generate the same report without having to configure the report's settings each time. Additionally, you can automate report generation (on a daily, weekly, or monthly basis) by adding a schedule to report configurations.
Saved report configurations are unique to individual users. If you create one, only you have access to it, but you can share a copy of it with users and groups within your organization. Shared copies of saved configurations have the following characteristics:
- Don't include any schedules associated with the original configuration.
- Distinct from the original configuration, so making changes to a saved configuration won't affect anyone else who has a copy of it.
- Unless you're an organization admin, configurations can only be shared with users and groups that can already access all applications mentioned in the configuration. If you are an org admin, sharing with people who can't already access the relevant applications will allow recipients to see the configuration values, so you'll be warned of this before confirming the share action.
- Configuration name includes the name of the person who shared it. Also, if the shared configuration has the same name as one of your existing saved configurations, the end of its name will get a distinguishing instance number. For example, the shared configuration might be named
Overdue TPS data for April - shared by Bob Porter - 6.
See Create and manage report configurations for more information.
Create a report
Create a software bill of materials report
To customize what is included in the report, see Ways to triage components in Polaris. If a component is triaged as Excluded, it will not be in the report.
Create a Notices File report
The Notices File report provides options to list open source components, the associated license text, and copyright information. This report will help you to manage and leverage your licenses.
This report is available as a text file, HTML, or PDF. You can include the following modules in the report:
- Scope (maximum of five branches).
- License data (components). Lists of components and their associated license names.
- Lists of licenses with their text.
- Copyright text. When enabled, the report will contain a section that lists the component origins and the associated copyright statements.
- Only available if components with origins are present in projects.
- If there are no copyrights associated with this component origin in our database, a “No copyrights found” statement appears.
To generate a Notices File report, follow these steps: