I would like that the --xml-version=3 report contains a list of files. All source and header files that has been used in the analysis. And I would prefer to write the SHA-256 hash for each file.

With this information it will be possible to verify later if a certain xml report was generated when cppcheck checked certain files with specific contents or not.

I have looked up https://github.com/okdshin/PicoSHA2 it looks acceptable to me..

What is your opinions? Do you feel it's a nice feature for open source cppcheck? I can implement what I need in the premiumaddon. Do you have better suggestions for the library?