SARIFAUDIT · PROFESSIONAL BROWSER TOOL

Reconcile rules, locations, and fingerprints before static-analysis results enter CI.

Walk SARIF 2.1.0 runs, driver rules, and results locally; summarize levels, messages, first physical locations, and fingerprints while flagging unknown rule references.

Open the workbench
Processed locally
Local report studioPreview · Markdown · JSON · SHA-256
SHA-256

Uses only the currently visible result summary, never input controls or original files; the fingerprint is also calculated locally.

Local analysis checkpointsUp to 5 · saved only when you choose

    Stores only the visible result summary, time, and an optional short label; imported files and input controls are never stored. Imports must match this tool and stay under 128KB; comparison also stays on this device.

    01

    Run, tool, and rule catalogs

    02

    Result level, message, and location

    03

    Rule references and result fingerprints

    It reads no source, opens no artifact URI, and does not decide whether findings are real, exploitable, duplicates, fixed, or acceptable.

    Read the source

    NO ACCOUNT · LOCAL PROCESSING · EXPORTABLE

    Professional tools can still be quiet and transparent.

    Read privacy and limitations →