Sealed reports & SARIF
Set a report profile, generate multi-format sealed reports, list issued copies, and export findings as SARIF.
What you’ll build
A sealed report for a finished pentest: you set (or inspect) a profile, generate with
optional formats / audience overrides, list issued copies and fetch a signed download URL,
then export findings as SARIF for a pipeline.
Report formats are pdf, html, markdown, docx and json. SARIF is not a report
format — it is a finding export. Rank emails the PDF only if the issuance sealed.
Prerequisites
- A completed pentest (see First automated pentest).
- An API token (see Authentication).
pip install rank-sdk
export RANK_API_KEY=rk_...
export RANK_PENTEST_ID=123
export RANK_REPORT_EMAIL=you@example.com
Steps
-
Set the caller default profile, then inspect the effective settings for this pentest.
import rank client = rank.Rank() pentest_id = 123 client.report_profiles.update( name="Technical delivery", methodology="wstg", compliance_overlays=["soc2"], audience="technical", default_formats=["pdf", "html"], include_unvalidated_appendix=False, ) settings = client.pentests.report_settings.retrieve(pentest_id) print(settings.effective.audience, settings.effective.default_formats)Team default:
client.teams.report_profiles.update(team_id, ...). Branding (logo, colours) is a visual overlay via the Branding API, not the SDK. -
Generate.
formatsandaudienceoverride the profile for this issuance only.generated = client.pentests.generate_report( pentest_id, recipient_email="you@example.com", recipient_name="Security Team", extended=1, formats=["pdf", "html", "json"], audience="technical", ) print(generated.message, generated.sealed, generated.emailed) -
List sealed issuances and fetch a signed download URL (never inlined).
reports = client.pentests.reports.list(pentest_id) for r in reports.items: print(r.id, r.format, r.payload_sha256, r.sealed_at) if reports.items: download = client.pentests.reports.retrieve(pentest_id, reports.items[0].id) print(download.url) -
Export findings as SARIF (pipeline consumers). Fingerprints are stable across runs.
sarif = client.pentests.vulnerabilities.export(pentest_id, format="sarif") if isinstance(sarif, rank.VulnerabilityExportFile): open(sarif.filename or "findings.sarif", "wb").write(sarif.content)
-
Caller default profile, then pentest settings.
curl https://api.aleex-rank.ai/api/v2/report-profiles \ -X PUT \ -H "X-API-Key: $RANK_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "name": "Technical delivery", "methodology": "wstg", "compliance_overlays": ["soc2"], "audience": "technical", "default_formats": ["pdf", "html"], "include_unvalidated_appendix": false }' curl https://api.aleex-rank.ai/api/v2/pentests/123/report-settings \ -H "X-API-Key: $RANK_API_KEY" -
Generate on the streaming backend.
curl https://aleex.aleex-rank.ai/generate_report \ -H "X-API-Key: $RANK_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "pentest_id": 123, "recipient_email": "you@example.com", "recipient_name": "Security Team", "extended": 1, "formats": ["pdf", "html", "json"], "audience": "technical" }' -
List issued reports and download.
GET /api/v2/pentests/123/reports GET /api/v2/pentests/123/reports/12 X-API-Key: rk_...The second call returns
{report, url}— a time-limited signed URL, never inlined. -
SARIF export.
GET /api/v2/pentests/123/vulnerabilities/export?format=sarif X-API-Key: rk_...
Run it
Save the following as sealed_reports.py, set RANK_API_KEY, RANK_PENTEST_ID and
RANK_REPORT_EMAIL, then run python sealed_reports.py.
"""Set a report profile, generate a sealed report, list issuances, export SARIF.
What this script does:
1. Updates the caller default report profile.
2. Prints the effective settings for the pentest.
3. Generates pdf+html+json for a technical audience and emails the PDF if sealed.
4. Lists issued reports and prints a signed download URL.
5. Writes a SARIF finding export.
The pentest must be completed.
Run:
pip install rank-sdk
export RANK_API_KEY=rk_...
export RANK_PENTEST_ID=123
export RANK_REPORT_EMAIL=you@example.com
python sealed_reports.py
"""
from __future__ import annotations
import os
import rank
PENTEST_ID = int(os.environ.get("RANK_PENTEST_ID", "0"))
REPORT_EMAIL = os.environ.get("RANK_REPORT_EMAIL", "you@example.com")
def main() -> None:
if PENTEST_ID <= 0:
raise SystemExit("ERROR: set RANK_PENTEST_ID to a completed pentest ID.")
with rank.Rank() as client:
client.report_profiles.update(
name="Technical delivery",
methodology="wstg",
compliance_overlays=["soc2"],
audience="technical",
default_formats=["pdf", "html"],
include_unvalidated_appendix=False,
)
settings = client.pentests.report_settings.retrieve(PENTEST_ID)
if settings.effective:
print(
f"Effective: audience={settings.effective.audience} "
f"formats={settings.effective.default_formats} "
f"method={settings.effective.methodology}"
)
generated = client.pentests.generate_report(
PENTEST_ID,
recipient_email=REPORT_EMAIL,
recipient_name="Security Team",
extended=1,
formats=["pdf", "html", "json"],
audience="technical",
)
print(f"{generated.message} sealed={generated.sealed} emailed={generated.emailed}")
reports = client.pentests.reports.list(PENTEST_ID)
for r in reports.items:
print(f" [{r.id}] {r.format} sha256={r.payload_sha256} sealed_at={r.sealed_at}")
if reports.items:
download = client.pentests.reports.retrieve(PENTEST_ID, reports.items[0].id)
print(f"Download URL: {download.url}")
sarif = client.pentests.vulnerabilities.export(PENTEST_ID, format="sarif")
if isinstance(sarif, rank.VulnerabilityExportFile):
path = sarif.filename or "findings.sarif"
with open(path, "wb") as fh:
fh.write(sarif.content)
print(f"Wrote {path} ({len(sarif.content)} bytes)")
if __name__ == "__main__":
try:
main()
except rank.AuthenticationError:
print("ERROR: invalid or missing API key. Set RANK_API_KEY.")
except rank.NotFoundError:
print(f"ERROR: pentest #{PENTEST_ID} not found.")
except rank.APIError as exc:
print(f"API error ({exc.status_code}): {exc.message}")