Synopsis
fcli fod aviator apply-remediations [--preview] [--delim=<delimiter>] [--progress=<type>] [--source-dir=<sourceCodeDirectory>] [--issue-ids=<issueIds>[,<issueIds>…]]… [--source-encodings=encoding[, encoding…]]… [[-h] [--env-prefix=<prefix>] [--log-file=<logFile>] [--log-level=<logLevel>] [--log-mask=<level>] [--debug]] [[-o=<type+args>] [--style*=<style>,…]… ] [--to-file=<outputFile>_]] (--from-cache=<zip> | --rel=id|app[:ms]: _ rel_) [[--fod-session=<sessionName>]]
Description
Downloads the FPR from a FoD release, or reads a local remediations cache zip, and applies Fortify Remediation Aviator remediations to the source directory. Exactly one of --release/--rel or --from-cache must be specified. Online selection requires an FoD session; --from-cache does not.
Options
- --delim=<delimiter>
-
Change the default delimiter character when using options that accept "application[:microservice]:release" as an argument or parameter.
- --from-cache=<zip>
-
Local remediations cache zip produced by download-remediations-cache. Mutually exclusive with --release/--rel. Does not require an FoD session.
- --issue-ids=<issueIds>[,<issueIds>…]
-
Comma-separated list of issue IDs to apply. Matches requested values against remediations.xml instanceId entries. Requires --from-cache so integrations can download once via download-remediations-cache and apply selected remediations without repeated FoD downloads.
- --preview
-
Shows available remediations and their proposed changes without modifying source files. Does not validate whether the proposed changes apply cleanly to the current source.
- --progress=<type>
-
Configure progress output. Allowed values: auto, none, simple, stderr, single-line, ansi. Default value: auto. Proper output of single-line and ansi depends on console capabilities.
- --rel, --release=id|app[:ms]:rel
-
Release id or <application>[:<microservice>]:<release> name.
- --source-dir=<sourceCodeDirectory>
-
Directory containing source code to apply remediations to. Default value: /home/runner/work/fcli/fcli/fcli-other/fcli-doc.
- --source-encodings=encoding[,encoding…]
-
Comma-separated source encoding candidates to try in order when decoding source files. Use FPR to try the source encoding recorded in audit.fvdl. When writing remediated files, the accepted encoding is used. Default value: FPR,UTF-8,ISO-8859-1.
FoD session name options
- --fod-session=<sessionName>
-
Name of the FoD session to use for executing this command. Default value: default.
Output options (also see documentation link below)
- -o, --output=<type+args>
-
Select output type (csv, table, expr, json, xml, yaml) and optional type arguments.
- --store=<var>[:<prop>]
-
Store JSON results in an fcli variable for later reference.
- *--style*=<style>,…
-
Select output style: header, no-header, pretty, no-pretty, flat, no-flat, array, single, border, no-border, md-border, wrap, no-wrap, fast-output, no-fast-output, envelope, no-envelope, csv-escape, no-csv-escape.
- --to-file=<outputFile>
-
Write output to the specified file.
Generic fcli options (also see documentation link below)
- --debug
-
Enable collection of debug logs.
- --env-prefix=<prefix>
-
Prefix for resolving default option values. Default value: FCLI_DEFAULT.
- -h, --help
-
Use 'fcli [command] -h' to display help for fcli (sub-)commands.
- --log-file=<logFile>
-
Write log output to file. Default: ./fcli.log if logging is enabled.
- --log-level=<logLevel>
-
Set logging level: TRACE, DEBUG, INFO, WARN, ERROR, NONE.
- --log-mask=<level>
-
Log mask level: high, medium, low, none. Default: medium. Masking is done on a best-effort basis; no guarantee that all sensitive data will be masked.