Skip to content
These docs describe staging.zkao.io and the @zksecurity/zkao-cli@next release. For production, see docs.zkao.io.

Publish results

View .md

Publishing creates a public page on zkao for one finding or one scan. Anyone with the link can read it. Nothing else in the project becomes visible.

Publishing needs the publish scope. zkao login does not request it by default. Ask for it when you log in:

Terminal window
zkao login --scope read scans:launch findings:write publish

A published finding shows its title, severity, repository, commit, description, impact, and recommendation. You can also attach one of its comments as the team’s public response. Pass that comment’s id as the note.

Terminal window
zkao findings publish <findingId>
zkao findings publish <findingId> --note <noteId> --password

The note must belong to the finding. Another finding’s note returns 400. The finding id also accepts a ZK- label.

A published scan lists the scan’s reported findings, most severe first. It covers the findings zkao confirmed, and those it marked as needing review. Only a COMPLETED scan can be published.

Terminal window
zkao scans publish <scanId>
zkao scans publish <scanId> --password

Both calls return the same shape.

{
"artifactId": "…",
"publicId": "…",
"accessPassword": null
}

The public page lives at one of these URLs.

  • https://zkao.io/public/findings/<publicId>
  • https://zkao.io/public/scans/<publicId>

With withPassword, zkao generates a password and returns it as accessPassword. Visitors must enter it to read the page. Share it separately from the link.

The API publishes but does not unpublish. Unpublish a page from the finding or scan on zkao.

See Publish a finding and Publish a scan for the full schemas.