Sealed reports & SARIF

Set a report profile, generate multi-format sealed reports, list issued copies, and export findings as SARIF.

What you’ll build

A sealed report for a finished pentest: you set (or inspect) a profile, generate with optional formats / audience overrides, list issued copies and fetch a signed download URL, then export findings as SARIF for a pipeline.

Report formats are pdf, html, markdown, docx and json. SARIF is not a report format — it is a finding export. Rank emails the PDF only if the issuance sealed.

Prerequisites

pip install rank-sdk
export RANK_API_KEY=rk_...
export RANK_PENTEST_ID=123
export RANK_REPORT_EMAIL=you@example.com

Steps

Run it

Save the following as sealed_reports.py, set RANK_API_KEY, RANK_PENTEST_ID and RANK_REPORT_EMAIL, then run python sealed_reports.py.

"""Set a report profile, generate a sealed report, list issuances, export SARIF.

What this script does:
  1. Updates the caller default report profile.
  2. Prints the effective settings for the pentest.
  3. Generates pdf+html+json for a technical audience and emails the PDF if sealed.
  4. Lists issued reports and prints a signed download URL.
  5. Writes a SARIF finding export.

The pentest must be completed.

Run:
    pip install rank-sdk
    export RANK_API_KEY=rk_...
    export RANK_PENTEST_ID=123
    export RANK_REPORT_EMAIL=you@example.com
    python sealed_reports.py
"""

from __future__ import annotations

import os

import rank

PENTEST_ID = int(os.environ.get("RANK_PENTEST_ID", "0"))
REPORT_EMAIL = os.environ.get("RANK_REPORT_EMAIL", "you@example.com")


def main() -> None:
    if PENTEST_ID <= 0:
        raise SystemExit("ERROR: set RANK_PENTEST_ID to a completed pentest ID.")

    with rank.Rank() as client:
        client.report_profiles.update(
            name="Technical delivery",
            methodology="wstg",
            compliance_overlays=["soc2"],
            audience="technical",
            default_formats=["pdf", "html"],
            include_unvalidated_appendix=False,
        )
        settings = client.pentests.report_settings.retrieve(PENTEST_ID)
        if settings.effective:
            print(
                f"Effective: audience={settings.effective.audience} "
                f"formats={settings.effective.default_formats} "
                f"method={settings.effective.methodology}"
            )

        generated = client.pentests.generate_report(
            PENTEST_ID,
            recipient_email=REPORT_EMAIL,
            recipient_name="Security Team",
            extended=1,
            formats=["pdf", "html", "json"],
            audience="technical",
        )
        print(f"{generated.message} sealed={generated.sealed} emailed={generated.emailed}")

        reports = client.pentests.reports.list(PENTEST_ID)
        for r in reports.items:
            print(f"  [{r.id}] {r.format} sha256={r.payload_sha256} sealed_at={r.sealed_at}")
        if reports.items:
            download = client.pentests.reports.retrieve(PENTEST_ID, reports.items[0].id)
            print(f"Download URL: {download.url}")

        sarif = client.pentests.vulnerabilities.export(PENTEST_ID, format="sarif")
        if isinstance(sarif, rank.VulnerabilityExportFile):
            path = sarif.filename or "findings.sarif"
            with open(path, "wb") as fh:
                fh.write(sarif.content)
            print(f"Wrote {path} ({len(sarif.content)} bytes)")


if __name__ == "__main__":
    try:
        main()
    except rank.AuthenticationError:
        print("ERROR: invalid or missing API key. Set RANK_API_KEY.")
    except rank.NotFoundError:
        print(f"ERROR: pentest #{PENTEST_ID} not found.")
    except rank.APIError as exc:
        print(f"API error ({exc.status_code}): {exc.message}")

Where to go next