Exports and sharing

Export the inbox or a run's findings, share a repository inbox or a run with guests, and publish a run report.

You can take findings out of V12 as files, give someone outside your organization access to one repository's findings or to one run's findings, or publish a run's report for anyone with the link.

Export the inbox

The download icon beside Group by (its tooltip reads Export as CSV) saves the rows the current view and filters show as a CSV file. Collapsed groups are included. If the view is empty, V12 says "Nothing to export".

The file has one row per finding, with the columns id, severity, status, title, home_repository, steer, standing, baseline, owner and birth_run. severity is a letter (C, H, M, L or I), and status writes Won't fix as closed.

Export run findings

A complete run whose findings are not in the inbox can export them as a file:

Open the run and go to its Findings section.

Click Export and choose CSV, JSON or Markdown.

The button reads Exporting… while V12 prepares the file, and the download starts when it is ready. The file holds every finding the run published, dismissed ones included, up to 5,000.

Findings already imported into the inbox show on the run page as inbox rows, without Export. Export them from the inbox instead.

Share a repository inbox

An Admin can give a person outside the organization access to one repository's findings.

Open the repository's Share inbox page at /<organization>/repos/<owner>/<repo>/guests. Nothing in V12 links to it, so type the address.

Type the person's email in Existing V12 user email and click Share. They need a V12 account first.

The page lists everyone the inbox is shared with. Remove takes a guest's access away.

The page sums up what guests can do: "Guests read and triage this repository's findings. They cannot start runs or see the rest of the organization." A guest finds the repository under Shared with you in Settings → Repositories of their personal workspace. Open opens its findings at the organization's own address, so links members share work for the guest too. They can triage and comment on its findings, but they see no links to its repository or runs.

A guest link opens one complete run's findings to people outside your organization. They need no V12 account. The person who started the run and Admins can make and manage its links once the run's findings are in the inbox.

Open the run and click Share.

Under Guest links, click New link. Optionally type a label, then choose what guests can do and how long the link lasts.

Click Create and copy. V12 copies the link, https://v12.sh/s/v12s_…, to your clipboard.

RoleGuests can
Can viewRead the findings, their reports and discussion
Can comment (the default)Also comment and reply
Can triageAlso change status and severity. Their changes apply to the finding everywhere in your inbox.

A link lasts 1, 7, 14 (the default) or 30 days, or never expires. Each live link has its own row in the dialog:

  • Its role and lifetime menus change the link at once. A new lifetime counts from today.
  • Copy link copies the link again.
  • Rename, under the … button, changes its label.
  • Revoke, under the … button, ends the link: anyone using it loses access at once. Revoked and expired links move under Ended links.
  • The row lists the guests who came through the link, with when each joined and was last active.

A run can have 20 live links and 250 guests on its live links; revoking a link frees its guests' places. A link keeps working after the person who made it leaves your organization, until it expires or is revoked. Revoking it leaves its guests' comments and changes in your inbox.

What guests see and do

A guest sees the run's findings in your inbox's own list, read-only: Open and All tabs, grouping by severity or status, and filters for status and severity, with repositories too when the run read several. A line above the list names each repository with the branch the run read and its commit. Statuses are the ones at that commit, so a fix recorded on a later commit does not change them. A finding opens on its own page, where j and k step through the list and Esc returns to it. Before a Can comment or Can triage link opens, the guest chooses the name they appear under: V12 offers a generated one, such as Nimble Beaver, with Shuffle to draw another, or they type their own, then click Enter the room. They can change the name until they first comment or change a finding. A Can view link opens at once, and its guests read anonymously.

Guests see the run's own findings with their reports, evidence and whole discussion, where members are named by username. Each finding carries your organization's key, such as F-12, and opens at the link's address followed by its number: https://v12.sh/s/v12s_…/12. Guests' comments and changes show in your inbox under their name, marked guest. V12 limits how often guests can comment and change findings.

Guests never:

  • see other runs, other repositories, the run's Steers or anyone's email;
  • assign, dismiss or restore a finding, or mark it a duplicate;
  • export findings, copy one as a prompt, or reference or attach files;
  • change the status of a finding your organization marked Won't fix, accepted risks included.

A guest's Open, Fixed or False positive applies to the finding at the commit the run read in each of its repositories, other runs' reports of it there included, and never to code outside the run.

Share a run report

Share on a run's page creates a link to a read-only report: https://v12.sh/share/ followed by a random code. Anyone with the link can read it without a V12 account. The person who started the run and Admins can share it. Once a run is shared, Share opens the report, and Stop sharing turns the link off at once. Sharing the run again creates a new link.

When Share opens the dialog that holds the run's guest links, the report is under Public summary: Publish creates its link, Open opens the report, and Unpublish turns the link off at once.

A run's report can be shared only when all of these are true:

  • the run is complete;
  • it carried at least one Steer;
  • every source is a named repository pinned to a commit;
  • no source is a public repository added without the V12 GitHub App.

The report lists the run's repositories and commits, and each finding's title, severity, status and repository. It shows no code, analysis or comments; Public run reports lists exactly what it publishes. Its statuses and severities are the run's own, not the ones set in your inbox.

On this page