Exports and sharing

Export the inbox or a run's findings, share a repository inbox with guests, and publish a run report.

You can take findings out of V12 as files, give someone outside your organization access to one repository's findings, or publish a run's report for anyone with the link.

Export the inbox

The download icon beside Group by (its tooltip reads Export as CSV) saves the rows the current view and filters show as a CSV file. Collapsed groups are included. If the view is empty, V12 says "Nothing to export".

The file has one row per finding, with the columns id, severity, status, title, home_repository, focus, standing, baseline, owner and birth_run. severity is a letter (C, H, M, L or I), and status writes Won't fix as closed.

Export run findings

A complete run whose findings are not in the inbox can export them as a file:

Open the run and go to its Findings section.

Click Export and choose CSV, JSON or Markdown.

The button reads Exporting… while V12 prepares the file, and the download starts when it is ready. The file holds every finding the run published, dismissed ones included, up to 5,000.

Findings already imported into the inbox show on the run page as inbox rows, without Export. Export them from the inbox instead.

Share a repository inbox

An Admin can give a person outside the organization access to one repository's findings.

Open the Repositories page (/repos), click the … button on the repository's row and choose Share inbox.

Type the person's email in Existing V12 user email and click Share. They need a V12 account first.

The page lists everyone the inbox is shared with. Remove takes a guest's access away.

The page sums up what guests can do: "Guests can work findings from their personal organization. They cannot start runs." A guest finds the repository under Shared with me on the Repositories page of their personal workspace. They can triage and comment on its findings, but they see no links to its repository or runs.

Share a run report

Share on a run's page publishes a read-only report at /share/<run number>. Anyone with the link can read it without a V12 account. The person who started the run and Admins can publish it. Once a report is published, Share opens it.

Share appears only when all of these are true:

  • the run is complete;
  • it carried at least one focus;
  • every source is a named repository pinned to a commit;
  • no source is a public repository added without the V12 GitHub App.

The report lists the run's repositories and commits, and each finding's title, severity, status and repository. It shows no code, analysis or comments; Public run reports lists exactly what it publishes. Its statuses and severities are the run's own, not the ones set in your inbox.

On this page