JSON reports
Use --json when another tool needs to consume Pharos output.
pharos qs@6.13.0 --path ./my-app --json
The top-level report includes the target package and a list of lockfile results:
{
"schema_version": 1,
"package": {
"name": "qs",
"version": "6.13.0",
"fixed_range": ">=6.14.0"
},
"lockfiles": [
{
"path": "./package-lock.json",
"lockfile_type": "npm",
"status": "found",
"chains": []
}
]
}
Status values
status is one of:
foundwhen the exact package version exists in the lockfile.not_foundwhen the lockfile was parsed but does not contain that version.errorwhen the lockfile could not be parsed or analyzed.
Parse errors include an error string on the lockfile object.
Each found chain includes a stable target locator and a remediation object. Remediation status is semver_verified, candidate, or unavailable; primary_action and alternatives contain printable instructions. Existing fix_path and recommended fields remain available for compatibility.
CI usage
Pharos is most useful in CI when another step has already identified a vulnerable version. Pass that exact version to Pharos and attach the JSON report to the security finding, pull request, or incident note.