{"id":15638053,"url":"https://github.com/jacobbednarz/go-csp-collector","last_synced_at":"2026-05-26T00:01:21.495Z","repository":{"id":17782881,"uuid":"82341613","full_name":"jacobbednarz/go-csp-collector","owner":"jacobbednarz","description":"A CSP and NEL collector written in Golang","archived":false,"fork":false,"pushed_at":"2026-05-25T22:30:13.000Z","size":1958,"stargazers_count":124,"open_issues_count":0,"forks_count":28,"subscribers_count":4,"default_branch":"master","last_synced_at":"2026-05-25T23:24:34.634Z","etag":null,"topics":["content-security-policy","csp","csp-collector","golang","nel","network-error-logging","reporting-api"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jacobbednarz.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2017-02-17T21:57:38.000Z","updated_at":"2026-05-25T22:30:17.000Z","dependencies_parsed_at":"2023-01-13T19:30:05.619Z","dependency_job_id":"b9feee9d-37a1-4e4d-9666-1b4a3fc6cd0a","html_url":"https://github.com/jacobbednarz/go-csp-collector","commit_stats":{"total_commits":192,"total_committers":19,"mean_commits":"10.105263157894736","dds":0.5729166666666667,"last_synced_commit":"8e91b7bf310855c09b0dff617a50cb32b28eb723"},"previous_names":[],"tags_count":26,"template":false,"template_full_name":null,"purl":"pkg:github/jacobbednarz/go-csp-collector","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jacobbednarz%2Fgo-csp-collector","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jacobbednarz%2Fgo-csp-collector/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jacobbednarz%2Fgo-csp-collector/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jacobbednarz%2Fgo-csp-collector/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jacobbednarz","download_url":"https://codeload.github.com/jacobbednarz/go-csp-collector/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jacobbednarz%2Fgo-csp-collector/sbom","scorecard":{"id":501129,"data":{"date":"2025-08-11","repo":{"name":"github.com/jacobbednarz/go-csp-collector","commit":"bfe6f18d627c580a380fe70c0a4f1afd18cb13b8"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4,"checks":[{"name":"Maintained","score":6,"reason":"8 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 6","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":-1,"reason":"Found no human activity in the last 14 changesets","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/build_image.yml:1","Warn: no topLevel permission defined: .github/workflows/lint.yml:1","Warn: no topLevel permission defined: .github/workflows/test.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.0.16 not signed: https://api.github.com/repos/jacobbednarz/go-csp-collector/releases/160415305","Warn: release artifact v0.0.15 not signed: https://api.github.com/repos/jacobbednarz/go-csp-collector/releases/160395913","Warn: release artifact v0.0.14 not signed: https://api.github.com/repos/jacobbednarz/go-csp-collector/releases/134246150","Warn: release artifact v0.0.13 not signed: https://api.github.com/repos/jacobbednarz/go-csp-collector/releases/84629162","Warn: release artifact v0.0.12 not signed: https://api.github.com/repos/jacobbednarz/go-csp-collector/releases/82869579","Warn: release artifact v0.0.16 does not have provenance: https://api.github.com/repos/jacobbednarz/go-csp-collector/releases/160415305","Warn: release artifact v0.0.15 does not have provenance: https://api.github.com/repos/jacobbednarz/go-csp-collector/releases/160395913","Warn: release artifact v0.0.14 does not have provenance: https://api.github.com/repos/jacobbednarz/go-csp-collector/releases/134246150","Warn: release artifact v0.0.13 does not have provenance: https://api.github.com/repos/jacobbednarz/go-csp-collector/releases/84629162","Warn: release artifact v0.0.12 does not have provenance: https://api.github.com/repos/jacobbednarz/go-csp-collector/releases/82869579"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_image.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/build_image.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_image.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/build_image.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_image.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/build_image.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_image.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/build_image.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_image.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/build_image.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_image.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/build_image.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_image.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/build_image.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_image.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/build_image.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_image.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/build_image.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_image.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/build_image.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_image.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/build_image.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/lint.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/lint.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/lint.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:8: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/jacobbednarz/go-csp-collector/test.yml/master?enable=pin","Warn: containerImage not pinned by hash: Dockerfile:1","Warn: containerImage not pinned by hash: Dockerfile:9: pin your Docker image by updating alpine:3.22.1 to alpine:3.22.1@sha256:4bcff63911fcb4448bd4fdacec207030997caf25e9bea4045fa6c8c44de311d1","Info:   0 out of   7 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   9 third-party GitHubAction dependencies pinned","Info:   1 out of   1 goCommand dependencies pinned","Info:   0 out of   2 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-19T21:52:58.781Z","repository_id":17782881,"created_at":"2025-08-19T21:52:58.781Z","updated_at":"2025-08-19T21:52:58.781Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33497930,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-25T14:31:05.219Z","status":"ssl_error","status_checked_at":"2026-05-25T14:31:02.878Z","response_time":57,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["content-security-policy","csp","csp-collector","golang","nel","network-error-logging","reporting-api"],"created_at":"2024-10-03T11:17:16.867Z","updated_at":"2026-05-26T00:01:21.483Z","avatar_url":"https://github.com/jacobbednarz.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"This is a content security policy (CSP) violation and network error logging\n(NEL) collector written in Golang.\n\nIt has been designed to listen on port 8080 and accept POST payloads\ncontaining the violation report. It captures the report and will write\nit to STDOUT via Go's logger.\n\nA neat little feature of this tool is that it automatically ignores\nunactionable reports. Check out the [default list][1] if you're interested.\n\n### Installation\n\n```sh\n$ go get github.com/jacobbednarz/go-csp-collector\n```\n\nAlternatively, you can download the binaries from the [release page][2].\n\n### Running\n\n```sh\n$ go build -o csp_collector main.go\n$ ./csp_collector\n```\n\n### Endpoints\n\n#### CSP\n\n- `POST /`: accepts a CSP violation report (recommended to use `/csp` for future proofing though).\n- `POST /csp`: accepts a CSP violation report.\n- `POST /csp/report-only`: same as `/csp` but appends a `report_only=true` attribute to the log line. Helpful if you have enforced and report-only violations and wish to separate them.\n- `OPTIONS /reporting-api/csp`: CORS preflight handler for the Reporting API.\n- `POST /reporting-api/csp`: Implementation of the browser Reporting API ([w3c](https://www.w3.org/TR/reporting-1/) / [MDN](https://developer.mozilla.org/en-US/docs/Web/API/Reporting_API)) for CSP violations.\n\n#### NEL (Network Error Logging)\n\n\u003e [!IMPORTANT]  \n\u003e Network error logging is still experimental in most browsers. This functionality is best effort and may need to adjust as the specification does.\n\n- `POST /nel`: accepts NEL reports for an enforced NEL policy.\n- `POST /nel/report-only`: same as `/nel` but appends a `report_only=true` attribute to the log line. Useful when testing a NEL policy before enforcing it.\n\nNEL reports are delivered by the browser via the [Reporting API](https://www.w3.org/TR/reporting-1/) as a JSON array. Each entry with `\"type\": \"network-error\"` is logged; other types in a mixed batch are silently skipped.\n\nTo enable NEL reporting, send the `NEL` and `Report-To` (or `Reporting-Endpoints`) headers from your server:\n\n```http\nReporting-Endpoints: nel-endpoint=\"https://collector.example.com/nel\"\nNEL: {\"report_to\": \"nel-endpoint\", \"max_age\": 31536000}\n```\n\nEach logged NEL report includes the following fields:\n\n| Field               | Description                                              |\n| ------------------- | -------------------------------------------------------- |\n| `report_only`       | `true` when received on the `/nel/report-only` endpoint  |\n| `url`               | The URL of the request that failed                       |\n| `referrer`          | The referrer at the time of the request                  |\n| `type`              | Error type (e.g. `tcp.refused`, `dns.unreachable`, `ok`) |\n| `phase`             | Phase of the request: `dns`, `connection`, `application`, or `abandoned` |\n| `protocol`          | Network protocol (e.g. `h2`, `http/1.1`)                |\n| `method`            | HTTP method (e.g. `GET`, `POST`)                         |\n| `status_code`       | HTTP status code (0 if the connection never completed)   |\n| `elapsed_time`      | Duration of the request in milliseconds                  |\n| `server_ip`         | IP address of the server that handled the request        |\n| `sampling_fraction` | Fraction of matching requests that were reported         |\n| `metadata`          | Value of the `metadata` query parameter (if present)     |\n| `path`              | Path of the collector endpoint that received the report  |\n\n#### Building for Docker\n\nYou will either need to build within a docker container for the purpose, or use `CGO_ENABLED=0` flag\nto make the build compatible with alpine linux in a docker container.\n\n```sh\n$ CGO_ENABLED=0 go build -o csp_collector main.go\n```\n\n### Command Line Options\n\n| Flag                    | Description                                                                                                                                                                                       |\n| ----------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |\n| version                 | Shows the version string before exiting                                                                                                                                                           |\n| debug                   | Runs in debug mode producing more verbose output                                                                                                                                                  |\n| port                    | Port to run on, default 8080                                                                                                                                                                      |\n| metrics-port            | Port for the Prometheus metrics endpoint, default 9090                                                                                                                                            |\n| metrics-bind-addr       | Bind address for the Prometheus metrics endpoint, default 127.0.0.1                                                                                                                               |\n| filter-file             | Reads the blocked URI filter list from the specified file. Each line is matched as a prefix against the blocked URI. Note one filter per line.                                                    |\n| filter-domains-file     | Reads a domain block list from the specified file. Each line is a bare domain (e.g. `kaspersky-labs.com`). A report is dropped when the blocked URI's hostname exactly matches the domain or is any subdomain of it (e.g. `gc.kis.v2.scr.kaspersky-labs.com`). Matching uses exact suffix comparison — no fuzzy or regex logic. Note one domain per line. **Performance note:** each check requires a `url.Parse` call to extract the hostname, which costs roughly 20–35× more than the prefix filter (~180 ns/op vs ~5–8 ns/op). For high-throughput deployments, prefer `filter-file` for simple prefix matches and only use `filter-domains-file` where subdomain wildcard matching is genuinely needed. |\n| health-check-path       | Sets path for health checkers to use, default \\/\\_healthcheck                                                                                                                                     |\n| log-client-ip           | Include a field in the log with the IP delivering the report, or the value of the `X-Forwarded-For` header, if present.                                                                           |\n| log-truncated-client-ip | Include a field in the log with the truncated IP (to /24 for IPv4, /64 for IPv6) delivering the report, or the value of the `X-Forwarded-For` header, if present. Conflicts with `log-client-ip`. |\n| truncate-query-fragment | Remove all query strings and fragments (if set) from all URLs transmitted by the client                                                                                                           |\n| query-params-metadata   | Log all query parameters of the report URL as a map in the `metadata` field                                                                                                                       |\n\nSee the `sample.filterlist.txt` file as an example of the URI prefix filter list, and\n`sample.domainlist.txt` as an example of the domain filter list.\n\n### Request metadata\n\nAdditional information can be attached to each report by adding a `metadata`\nurl parameter to each report. That value will be copied verbatim into the\nlogged report.\n\nFor example a report sent to `https://collector.example.com/?metadata=foobar`\nwill include field `metadata` with value `foobar`.\n\nIf `query-params-metadata` is set, instead all query parameters are logged as a\nmap, e.g. `https://collector.example.com/?env=production\u0026mode=enforce` will\nresult in `\"metadata\": {\"env\": \"production\", \"mode\": \"enforce\"}` in JSON\nformat, and `metadata=\"map[env:production mode:enforce]\"` in default format.\n\n### `report-only` mode\n\nBoth CSP and NEL have dedicated `report-only` endpoints (`/csp/report-only` and\n`/nel/report-only`). Reports received on these endpoints are logged identically\nto their enforced counterparts, but with `report_only=true` in the log output.\nThis lets you distinguish enforced violations from report-only ones in your log\naggregation tool without needing separate collector instances.\n\n### Metrics\n\nPrometheus metrics are exposed on a dedicated endpoint:\n\n- Address: `127.0.0.1:9090` (default)\n- Path: `/metrics`\n- Full URL: `http://127.0.0.1:9090/metrics`\n\nThe collector exports:\n\n| Metric | Type | Labels | Description |\n| ------ | ---- | ------ | ----------- |\n| `csp_collector_reports_total` | Counter | `handler`, `mode` | Successfully processed CSP or Reporting API reports |\n| `csp_collector_nel_reports_total` | Counter | `mode` | Successfully processed NEL reports |\n| `csp_collector_reports_filtered_total` | Counter | `handler`, `reason` | Reports dropped by URI/domain filters |\n| `csp_collector_reports_ignored_total` | Counter | `handler`, `reason` | Reports intentionally ignored (for example unsupported NEL types) |\n| `csp_collector_reports_errors_total` | Counter | `handler`, `type` | Rejected reports (decode or validation failures) |\n| `csp_collector_http_request_duration_seconds` | Histogram | `handler`, `route`, `method`, `code` | HTTP request duration for report-ingestion endpoints |\n| `csp_collector_http_requests_in_flight` | Gauge | `handler`, `route` | Active in-flight report-ingestion requests |\n| `go_*` / `process_*` | Various | client-go defaults | Runtime and process health metrics |\n\nExample Prometheus scrape config:\n\n```yaml\nscrape_configs:\n  - job_name: \"go-csp-collector\"\n    static_configs:\n      - targets: [\"127.0.0.1:9090\"]\n```\n\nIf you expose metrics on a non-localhost interface using `--metrics-bind-addr`, protect access with network controls (firewall rules, private network, or service mesh policy).\n\n### Output formats\n\nThe output format can be controlled by passing `--output-format \u003ctype\u003e`\nto the executable. Available formats are:\n\n- **Text**: A key/value output that quotes all the values. Example:\n  `blocked_uri=\"about:blank\" ...`\n- **JSON**: Single line, compressed JSON object. Example:\n  `{\"blocked_uri\":\"about:blank\"}`\n\nThe default formatter is text.\n\n### Writing to a file instead of just STDOUT\n\nIf you'd rather have these violations end up in a file, I suggest just\nredirecting the output into a file like so:\n\n```sh\n$ ./csp_collector 2\u003e\u003e /path/to/violations.log\n```\n\n### Visualisation\n\nThis project purposely doesn't try to solve the problem of visualing the\nviolation data because there are already a bunch of great solutions out\nthere. Once you have your violations being collected, be sure to slurp\nthem into your favourite log aggregation tool.\n\n### Deployments\n\nCurrently supported deployment mechanisms:\n\n- [kubernetes/helm][3]\n- [systemd][4]\n\n### Release\n\n- Checkout `master`.\n- Create a tag and push.\n- GitHub Actions will build, publish a new release, and publish the Helm chart.\n\n[1]: https://github.com/jacobbednarz/go-csp-collector/blob/master/sample.filterlist.txt\n[2]: https://github.com/jacobbednarz/go-csp-collector/releases\n[3]: https://github.com/jacobbednarz/go-csp-collector/tree/master/deployments/kubernetes-helm/README.md\n[4]: https://github.com/jacobbednarz/go-csp-collector/tree/master/init\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjacobbednarz%2Fgo-csp-collector","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjacobbednarz%2Fgo-csp-collector","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjacobbednarz%2Fgo-csp-collector/lists"}