Neatbo.

Receive exported reports: check declarations before interpreting results

Read local build artifacts as declared evidence: distinguish unresolved references, integrity failures and unsupported formats without executing packages or following file paths.

Record what a receiver actually needs to decide

An XML file can parse while one testcase contains several failure events. A schema-valid SBOM can repeat a reference across objects. A GEDCOM export can open while its reverse family declaration is absent. Start from the receiving decision, then retain the evidence that supports it.

Three concrete observations
ObservationUseful conclusionNext action
Two failure events in one caseOne failure case, both assertions retainedRead every event before choosing the fix
Duplicate bom-ref AEdges involving A are ambiguousRepair the producer; do not overwrite one declaration
FAMC without reverse CHILOne-way declaration with original lineVerify export completeness and relationship evidence

Read every testcase event before comparing summary numbers

Run the JUnit starter and compare three cases with three events. The two failure assertions belong to one case. Suite time 99 does not become measured case time, and missing times do not become zero. Keep declared counters separate so a stale CI summary cannot inflate the result.

Open the complete offline HTML and inspect escaped logs. Unknown flaky/rerun dialects stop the run; exporting a supported document is safer than manually deleting outcome elements. No test execution is implied by a report that opens.

SARIF: preserve findings when a source base is unresolved

The starter has four results and five primary/related/code-flow locations. R1 resolves to the driver rule’s error level; missing bases, a base cycle and an unlocated result remain visible. Supplying {"ROOT":"file:///D:/new/"} maps the SRC chain to D:/new/src/ without reading source files there. Complete original results retain baseline, suppressions and unknown fields.

Bases must be directory URIs ending in /, without queries or fragments. Invalid indices and conflicting direct/indexed declarations reject; undeclared rules and unknown suppression/baseline states stay explicit. Message markdown is literal escaped text; messageStrings and arguments are not expanded. report.json retains complete originalResult number tokens and original.sarif.json retains input bytes. CSV and HTML list every scoped location plus unlocated results, without certifying the full SARIF schema.

Review dependency ambiguity before reachability

The SBOM starter has an explicit app root and a separate A/B dependency cycle. Missing references and external URNs are different statuses. A duplicated ID has every declaration path in the report, and its edges do not enter SCC analysis.

Do not infer root reachability from the first component. Keep original.json, including relations outside this dependency audit. A readable graph is not a vulnerability or compliance verdict; use the producer and receiving SBOM system for those checks.

Wheel: generating a report does not mean integrity passed

Load the fixed demo_pkg-1.2.3-py2.py3-none-any.whl example: six archive files, five verified payload files and the unhashed RECORD itself. Expanded filename tags are compared with WHEEL; names normalize but versions compare literally. Folded/repeated METADATA headers and entry points remain literal data. Actual 32 MiB input, 64 MiB expanded and 10,000-entry vectors have Node Worker capacity/readback evidence; production-browser acceptance remains centralized.

A bad hash, wrong size, missing/unrecorded file or metadata mismatch yields a complete integrityStatus=failed diagnosis. SHA256/384/512 are supported; SHA224 and unknown hashes are explicitly incomplete, while MD5/SHA1 are forbidden and fail. RECORD self and legacy jws/p7s exceptions stay visible. verified_recorded_payload does not establish authenticity, safety or your machine ABI; nothing is installed, imported, executed or unpacked to disk.

  • Keep the original wheel filename and check failures with a trusted producer; do not rewrite RECORD to conceal changes.
  • This task audits the selected wheel, not an installed disk copy. Historical pip feedback demonstrates demand without claiming current pip behavior.

Use original family lines when deciding whether to edit

A missing reciprocal family link can reflect an incomplete export or a source-system problem. The browser report retains the one-way declaration and never adds a parent, child or reverse pointer. Ancestor SCCs use declared directed relationships, with adopted/foster/sealing/unknown pedigree preserved.

For long names or notes, external-original-value is a present value stored in original.ged. Reconstruct its byte span or ordered continuation segments before editing. Do not treat value:null as an empty family field, and do not call spouse rings self-ancestor cycles.

  • Retain original.ged together with the report JSON.
  • Check the exact line and counterpart record in the source system.
  • Distinguish declared parentage from biological facts.
  • After fixing the source, rerun and compare issues rather than merely renaming the file.

Deliver the complete report and its limits

Write down producer/version, original filename, selected options and the receiver check. A first-200 table is a preview; the downloads contain all successful rows. A 10 MiB output-budget failure returns no partial result. Partition only when it preserves the original task. These tools inspect exported data without executing its contents.

When report JSON exceeds 20,000 characters, the result text and copy button provide a compact preview with row counts and fullReportInDownload:true. Download report.json/CSV/HTML for the complete handoff.

The table shows the first 200 rows; longer cells show their first 2,000 characters plus an ellipsis. Above 20,000 characters, text/copy is a summary preview. Full JSON/CSV/HTML are not truncated; the receiver should read downloaded files instead of treating copied previews as complete reports.

References

Tools in this category

Expand a tool to see its steps, options and supported formats, then open its workspace.

JUnit offline test reportRead local JUnit XML results, distinguish testcase outcomes from declared counters and download every failure and log in an offline report.

Turn exported CI test XML into a readable report without running tests. Keep nested suite paths, repeated testcase names, multiple failure events and literal logs together with the original files.

Steps

  1. Open one or several exported JUnit XML files, or paste one document.
  2. Review case outcomes, mixed events, nested paths and separately declared suite counters.
  3. Download the full offline HTML, JSON/CSV; retain the original input separately.

Available options

Protect CSV formula-like text
On by default

Capabilities and limits

  • Up to 20 UTF-8 files, each 5 MiB and 10 MiB combined, or one pasted XML up to 5 MiB. Across the input: 10,000 testcases, 50,000 XML element nodes and 64 element levels. Selected files take precedence. Combined downloads up to 10 MiB; an oversized complete report rejects atomically. Table preview first 200 cases.
  • Supports nested testsuites/testsuites and testsuite/testcase, failure/error/skipped events, ordinary properties and system-out/system-err. A testcase may have multiple events; it counts once in summary. Multiple outcome kinds are explicitly mixed. Duplicate names remain separate indexed cases, without merging.
  • Accepted testcase attributes: name, classname, time, assertions, file, line, url and id. Unknown outcome elements or attributes, flaky/rerun extensions, DTD and external entities reject. Empty suites must explicitly declare tests="0". Correct or re-export unsupported producer data; it is never labelled passed.
  • Declared suite/container counters and time stay separate from testcase counts. measuredSeconds sums testcase times only if every case supplies a finite nonnegative time; otherwise null/unknown. This sum is not suite wall time. HTML escapes all text and has no script/source fetching. JSON retains every event, suite log and property; CSV retains every case, with optional formula protection. Keep the original XML beside the report; it is not copied into downloads.
  • The result text and copy action use a compact preview when the report exceeds 20,000 characters. Complete report.json, CSV and HTML are downloaded artifacts. Long table cells show only their first 2,000 characters plus ellipsis; complete downloads are not truncated.
Open JUnit offline test report →
SARIF rules and locations reportRead local SARIF 2.1.0 runs, resolve rules, artifact indices and directory URI bases, preserving unlocated results, unknown states and complete original results.

Inspect a scanner’s exported SARIF offline: first check rule provenance, locations and bases, then interpret findings. Missing source paths, unknown suppression states and unlocated results remain visible instead of disappearing when resolution fails.

Steps

  1. Select or paste SARIF; optionally provide directory URI base mappings.
  2. Review rule resolution, primary/related/code-flow locations, missing bases and original suppression/baseline states.
  3. Download the complete report and original; use the producer to inspect message templates or unsupported relationships.

Available options

Protect CSV formula-like text
On by default

Capabilities and limits

  • Select one UTF-8 SARIF 2.1.0 JSON file or paste up to 5 MiB; optional directory-base mapping JSON up to 1 MiB. Limits: 10,000 results, 10,000 artifacts per run, 50,000 locations overall, 200,000 JSON values and 64 levels. Combined downloads: 10 MiB, atomic rejection if exceeded. Each run is resolved separately.
  • Resolves driver/extension rule IDs, indices and GUIDs. Conflicting rule declarations and invalid indices reject. Undeclared rules, unlocated/logical-only results and missing/cyclic bases remain visible. Original baselineState and suppression kind/status remain; unknown states are labelled unknown rather than filtering results.
  • Resolves artifact indices, direct URIs and directory originalUriBaseIds chains; optional mappings override bases with absolute directory URIs. Bases must end in /, without queries/fragments. Backslashes, malformed escaping and non-directory bases reject. Relative URIs without a base stay unresolved. No local path guessing, source-file reads or network requests.
  • Keeps each complete originalResult, including primary/related/code-flow locations, original regions, suppressions, baseline, messages and unknown fields. report.json and original.sarif.json retain large-integer and decimal number tokens. text/markdown/id are literal text; messageStrings/arguments and full relationship graphs are not expanded. This is not full SARIF schema certification.
  • Table preview: first 200 rows, first 2,000 characters plus ellipsis for longer cells. Above 20,000 report characters, text/copy becomes a summary preview. Complete JSON, CSV, escaped offline HTML and exact original input remain in downloads.
Open SARIF rules and locations report →
CycloneDX dependency-reference auditAudit local CycloneDX 1.6 bom-ref declarations and dependency edges, showing duplicates, dangling references, external URNs and unambiguous cycles.

Inspect a generated SBOM before handing it to another system. Find cross-record reference problems that ordinary JSON syntax checks cannot explain, while retaining the complete original document.

Steps

  1. Open or paste a CycloneDX 1.6 SBOM exported by your build.
  2. Check every duplicate path, unresolved edge and SCC; check whether a root was explicitly declared.
  3. Download complete reference reports and original.json, then repair the generator and rerun.

Available options

Protect CSV formula-like text
On by default

Capabilities and limits

  • One UTF-8 JSON file or paste up to 5 MiB; 10,000 bom-ref declarations, 50,000 declared dependsOn edges, 200,000 JSON values and depth 64. Selected file takes precedence. All downloads combined up to 10 MiB; a large complete report can reach this cap before a count cap and then rejects atomically. Preview first 200 rows.
  • Supports CycloneDX JSON 1.6 only, with basic component/service/dependency shape checks, not complete official schema certification. Nested components/services and metadata.component are recognized. Every bom-ref declaration anywhere in the original is indexed with its JSON pointer. Other objects are not component/service graph targets. Version 1.4/1.5 reject.
  • Duplicate bom-ref declarations report every original path; their edges are excluded instead of overwriting an object. Duplicate dependency ref rows are explicit and all of those source edges are excluded. Repeated targets within a single dependency row remain visible as duplicate_edge. Missing local references, wrong target kind and unresolved external urn:cdx references are distinct.
  • SCC/self-loop analysis uses unambiguous internal component/service edges only. Reachability needs an explicit, unique metadata.component bom-ref; no first-component guess. The original JSON bytes, including precise numeric tokens and fields outside graph scope, remain in original.json. provides, compositions, formulation and vulnerabilities are preserved but not analysed. No network resolution, vulnerability scan or compliance verdict.
  • The result text and copy action use a compact preview when the report exceeds 20,000 characters. Complete report.json, CSV and HTML are downloaded artifacts. Long table cells show only their first 2,000 characters plus ellipsis; complete downloads are not truncated.
Open CycloneDX dependency-reference audit →
Wheel archive and RECORD auditCompare a local wheel filename, metadata, tags and every RECORD hash/size, distinguishing integrity failures, unsupported hashes and unverified signatures.

Before installing an unfamiliar wheel, inspect whether its archive declarations agree with its bytes. This task reads the file without importing the package; a bad hash produces a failed audit, so generating a report never substitutes for passing verification.

Steps

  1. Select a wheel with its original filename, or load the fixed small-file example.
  2. Review integrity status, verified files, failures, unsupported hashes and unverified signatures.
  3. Download the complete audit and check failures with a trusted producer; the report is not a security or installation approval.

Available options

Protect CSV formula-like text
On by default

Capabilities and limits

  • Select exactly one .whl file up to 32 MiB; no pasted archive. ZIP: 10,000 entries, 64 MiB expanded and compression ratio 200 per entry. Unsafe paths, duplicates, CRC failures, encryption, multiple disks and ZIP64 reject. Report: 200,000 JSON values and 10 MiB combined downloads. Any exceeded budget rejects atomically, without a partial audit.
  • Supports Wheel-Version 1.0 and Metadata-Version 1.1, 1.2 and 2.1–2.6. Exactly one filename-matching dist-info directory must contain METADATA/WHEEL/RECORD. Names compare after dash/underscore/dot normalization; versions compare literally, without inferring PEP440 equivalence. Optional build and compressed tags are compared with WHEEL. Folded/repeated headers, description body and entry points remain literal data.
  • Checks every archive file against canonical URL-safe Base64 SHA256/384/512 RECORD hashes and byte sizes. Missing, unrecorded, mismatched hash/size or inconsistent metadata means integrityStatus=failed. SHA224 and other unknown hashes are unsupported_hash/incomplete; MD5/SHA1 are forbidden and fail. A failed audit still delivers its complete diagnosis; it does not claim success.
  • RECORD itself must have empty hash/size. Legacy RECORD.jws/p7s files are signature_not_verified. verified_recorded_payload describes recorded payload checks only, not package authenticity, installation safety, host ABI or platform suitability. Nothing is installed, imported, executed or unpacked to disk.
  • Table preview: first 200 rows; cells over 2,000 characters show their first 2,000 plus an ellipsis. Above 20,000 report characters, text/copy becomes a summary preview. Full JSON, CSV and HTML remain downloadable, with unsupported hashes and exceptions visible.
Open Wheel archive and RECORD audit →
GEDCOM references and ancestry auditInspect UTF-8 GEDCOM 5.5.1 family/person references, reciprocity and declared ancestry SCCs with original lines and pedigree classifications.

Check a genealogy export before import: locate dangling or one-way family links and declared ancestor cycles. Retain the original source and report the evidence without adding relatives or inferring biological relationships.

Steps

  1. Open a UTF-8 GEDCOM 5.5.1 export or paste its complete source.
  2. Review line-numbered target and reciprocity issues, pedigree declarations and ancestry SCC members.
  3. Download original.ged and full reports; verify facts with the source system before making corrections.

Available options

Protect CSV formula-like text
On by default

Capabilities and limits

  • One UTF-8 file or paste up to 5 MiB, 50,000 physical lines, 10,000 top-level records including HEAD/TRLR, 64 hierarchy levels, and 50,000 combined declared relationship plus derived ancestry edges. Selected file takes precedence. Total downloads up to 10 MiB; oversized complete reports reject atomically. Preview first 200 rows.
  • HEAD/GEDC/VERS must explicitly be 5.5.1 and HEAD/CHAR UTF-8. Exact source BOM and CRLF/LF/CR endings remain in original.ged. GEDCOM 7, ANSEL, UTF-16, level gaps, duplicate xrefs, blank physical lines and malformed pointers reject. Unknown tags remain in source-derived JSON and original bytes.
  • INDI FAMC/FAMS and FAM CHIL/HUSB/WIFE targets are type-checked, with dangling/wrong-type/duplicate/absent reciprocal lines reported. CONT/CONC text is resolved without dropping continuation text; original hierarchy/value fields remain. Continued or nested continuation pointer syntax rejects rather than guessing.
  • Ancestor SCCs use declared parent-to-child edges only. Pedigree values birth/adopted/foster/sealing/unknown/multiple and original PEDI values/lines remain visible; these declarations do not establish biological facts. Spouse rings are not ancestry cycles. Reports include every reference, issue and SCC member, not exponential enumeration of all simple cycles. No records edited, relationship inference, import or database write.
  • Values longer than 4096 UTF-8 bytes have value:null with external-original-value and an exact byte span into downloaded original.ged. Multiline logical values carry ordered byte/literal segments joined by concat, preserving CONT newline and CONC concatenation. A null with this status is a present value stored in the original, not a missing field.
  • The result text and copy action use a compact preview when the report exceeds 20,000 characters. Complete report.json, CSV and HTML are downloaded artifacts. Long table cells show only their first 2,000 characters plus ellipsis; complete downloads are not truncated.
Open GEDCOM references and ancestry audit →

Tools used in this article

JUnit offline test report →Read local JUnit XML results, distinguish testcase outcomes from declared counters and download every failure and log in an offline report.SARIF rules and locations report →Read local SARIF 2.1.0 runs, resolve rules, artifact indices and directory URI bases, preserving unlocated results, unknown states and complete original results.CycloneDX dependency-reference audit →Audit local CycloneDX 1.6 bom-ref declarations and dependency edges, showing duplicates, dangling references, external URNs and unambiguous cycles.Wheel archive and RECORD audit →Compare a local wheel filename, metadata, tags and every RECORD hash/size, distinguishing integrity failures, unsupported hashes and unverified signatures.GEDCOM references and ancestry audit →Inspect UTF-8 GEDCOM 5.5.1 family/person references, reciprocity and declared ancestry SCCs with original lines and pedigree classifications.