Everything it does
Every score comes with its reasoning
--report-risk writes a self-contained HTML report and a matching SARIF file. The HTML has no scripts and no external assets, so you can publish it straight from a build. Every point a package loses is listed, with a link to the evidence behind it.
