Skip to content
Wakemeup edited this page Aug 25, 2026 · 3 revisions

Hooray

Hooray is a Rust security-analysis and policy-enforcement platform for projects, CycloneDX and SPDX 2.x SBOMs, archives, OCI layouts, and container image archives. It combines software-composition analysis, focused source and infrastructure checks, deterministic policy decisions, reports, history, an authenticated HTTP API, and persistent monitoring.

Start here

Core guarantees

  • Stable identifiers and deterministic ordering for inventories, findings, policies, and reports.
  • Strict YAML/TOML configuration and policy parsing; unknown fields fail closed.
  • Bounded request, file, archive, scanner, dependency-path, and report processing.
  • Sensitive metadata and secret evidence are redacted in reports and API responses.
  • SQLite-backed history, normalized findings, baselines, audit records, monitor targets, and alert delivery state.
  • Clean enterprise CLI: the removed legacy positional scanner is not supported.

Important boundaries

Hooray is not a compiler-complete data-flow SAST engine, malware feed, legal opinion, TLS terminator, or container runtime. See Security Boundaries and Troubleshooting.

Clone this wiki locally