Seems like this effort is very similar to: https://github.com/sarif-standard
Static Analysis Results Interchange Format (SARIF) - A proposed standard for the output format of static analysis tools.
Maybe join forces with, or simply work on that instead? Ideally, the format would support results from any type of appsec tool, not just static (e.g., SAST, DAST, IAST, and SCA (known CVEs in libraries)).
Seems like this effort is very similar to: https://github.com/sarif-standard
Static Analysis Results Interchange Format (SARIF) - A proposed standard for the output format of static analysis tools.
Maybe join forces with, or simply work on that instead? Ideally, the format would support results from any type of appsec tool, not just static (e.g., SAST, DAST, IAST, and SCA (known CVEs in libraries)).