$npx skillfedfor your agent

secscanner2junit

Convert Security Scanner Output to JUnit Format

With conditionsPyPI Quality AssuranceReleased Feb 2025116.5K downloads / moGPL-3.0-onlyPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — secscanner2junit-1.1.0-py3-none-any.whl
v1.1.0 · released 2025-02-08 · Python <4.0,>=3.10 · 4 runtime deps: junit-xml, PyYAML, pytest, setuptools

Yes, if you use GitLab's free tier and want security scan results visible in merge requests. The tool is actively maintained, has low install friction, and solves a specific GitLab limitation. GPLv3 copyleft is standard for security tooling and poses no barrier for internal use. No known vulnerabilities.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later; input JSON must be a valid GitLab security scanner report.
  • Low friction: pure Python wheel with four common runtime dependencies (junit-xml, PyYAML, pytest, setuptools).
  • Active maintenance with recent commits; last release 2025-02-08.

License · maintenance · safety

GPL-3.0-only (copyleft) — GPLv3 copyleft license; you may use and modify the package freely, but any derivative work or distribution must also be licensed under GPLv3.

last release 2025-02-08 (552 days) · last repo commit 2026-04-13 · 23 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 116,452 downloads/mo, #12,203 on PyPI

Verify before relying

pip install SecScanner2JUnit
ss2ju secrets gl-secret-detection-report.json gl-secret-detection-report.xml
  • Whether the tool handles all edge cases in GitLab's security report schema across different scanner versions.
  • Performance characteristics when processing large security reports.
Same gist for agents: .md · .json

What it is and what it does

SecScanner2JUnit is a command-line tool that bridges GitLab's free-tier security scanning gap by converting native security scanner output into JUnit XML format. GitLab's free tier runs security scans (SAST, secret detection, container scanning, infrastructure-as-code scanning) but only displays results in merge requests on the Ultimate tier; this tool lets you work around that limitation by converting the JSON reports to JUnit format and uploading them as test reports, which GitLab displays in merge requests regardless of tier.

The tool accepts four report types (sast, secrets, container_scanning, maven_dependency_check), reads the JSON output from GitLab's security templates, and writes JUnit XML. It also supports suppression rules via a YAML config file to filter out known or accepted vulnerabilities. It's designed for GitLab CI/CD pipelines and is available both as a pip package and a Docker image.

Use it for

  • Display SAST findings in GitLab merge requests on free tier by converting semgrep or brakeman reports to JUnit.
  • Surface secret detection results in merge requests without upgrading to Ultimate tier.
  • Aggregate container scanning vulnerabilities as JUnit reports in CI/CD pipelines.
  • Suppress known vulnerabilities from security reports using a config file before conversion.
  • Run security scanning in Docker-based CI without pip by using the logchange/secscanner2junit image.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you use GitLab's free tier and want security scan results visible in merge requests.

The tool is actively maintained, has low install friction, and solves a specific GitLab limitation. GPLv3 copyleft is standard for security tooling and poses no barrier for internal use. No known vulnerabilities.

Install

secscanner2junit on PyPI

Before you install

Low friction: pure Python wheel with four common runtime dependencies (junit-xml, PyYAML, pytest, setuptools). Active maintenance with recent commits; last release 2025-02-08.

Requires Python 3.10 or later; input JSON must be a valid GitLab security scanner report.

License in practice

GPLv3 copyleft license; you may use and modify the package freely, but any derivative work or distribution must also be licensed under GPLv3.

Quickstart

pip install SecScanner2JUnit
ss2ju secrets gl-secret-detection-report.json gl-secret-detection-report.xml

Verify before relying

  • Whether the tool handles all edge cases in GitLab's security report schema across different scanner versions.
  • Performance characteristics when processing large security reports.

Package facts

LicenseGPL-3.0-only copyleft
Python supportSupports the current Python release <4.0,>=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
4 packages
junit-xmlPyYAMLpytestsetuptools
MaintenanceActively maintained 552 days since the last release
Last repo commit
First released
Downloads116,452 / month, #12,203 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: GNU General Public License v3 (GPLv3)Programming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13

Evidence: secscanner2junit-1.1.0-py3-none-any.whl

Tags

Capabilities
gitlab security report to junitconvert sast output junitgitlab free tier security scanningsecurity scanner xml conversiongitlab ci junit report generation
Topics
gitlab-cisecurity-scanningjunit-reporting

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “gitlab security report to junit”

  • secscanner2junitConverts GitLab security scanner output (SAST, secrets, container…
  • flake8-junit-report-basicConverts flake8 linting output to JUnit XML format for display in CI…
  • junit-xml-2Generates JUnit XML test result reports from Python test data,…

Give your agent the search over MCP, or paste the wish link into any chat.

More Quality Assurance packages

coverage Worth it
PyPI · Testing · released Aug 2026

Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.

Install it if you want to measure test completeness or enforce coverage thresholds in your project.

permissive licensepure Python · 3.10+
335.8Mdownloads / mo
ruff Worth it
PyPI · Python Modules · released Aug 2026

Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.

MITcompiled wheel · 3.7+
316.1Mdownloads / mo
pexpect With conditions
PyPI · Software Development · released Nov 2023

Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.

ISCpure Pythonaging
200.8Mdownloads / mo
black Worth it
PyPI · Python Modules · released May 2026

Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.

MITpure Python · 3.10+
179.9Mdownloads / mo
pytest-xdist Worth it
PyPI · Utilities · released Jul 2025

pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.

Install it if your test suite takes long enough that parallelization would save meaningful time.

MITpure Python · 3.9+
177.1Mdownloads / mo
cfn-lint Worth it
PyPI · Quality Assurance · released Aug 2026

Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.

Install it if you work with CloudFormation templates.

MIT-0pure Python
114.9Mdownloads / mo

See also njsscan · mypy-gitlab-code-quality · junit2html · pylint-gitlab · junit-xml-2 · junitparser · semgrep · kingfisher-bin · flake8-formatter-junit-xml · pylint-junit