Neatbo.

SARIF rules and locations report

Read local SARIF 2.1.0 runs, resolve rules, artifact indices and directory URI bases, preserving unlocated results, unknown states and complete original results.

Browser-local processingInputSARIF 2.1.0 JSONOutputAudit report JSON / CSV / HTMLUp to 5 MiB per file · File limit: 1
  1. 1Add input
  2. 2Adjust settings
  3. 3Get your result

Tool input and files are processed in this browser without being uploaded.

Your input

Inputs are kept temporarily in this tab when switching tools. Refreshing or closing clears them; large results may need to be regenerated.

⌘ / Ctrl + Enter to run

or drag and drop it here

Files stay on this device. Your originals stay unchanged.

.sarif · .json

Up to 5 MiB per file · File limit: 1

    0 characters · 0 bytes
    Options

    Complete the required options first. You can keep the defaults for the rest.

    Preparing the tool…

    Before you start

    Inspect a scanner’s exported SARIF offline: first check rule provenance, locations and bases, then interpret findings. Missing source paths, unknown suppression states and unlocated results remain visible instead of disappearing when resolution fails.

    How to use this tool

    1. Select or paste SARIF; optionally provide directory URI base mappings.
    2. Review rule resolution, primary/related/code-flow locations, missing bases and original suppression/baseline states.
    3. Download the complete report and original; use the producer to inspect message templates or unsupported relationships.

    Supported inputs and limits

    Select one UTF-8 SARIF 2.1.0 JSON file or paste up to 5 MiB; optional directory-base mapping JSON up to 1 MiB. Limits: 10,000 results, 10,000 artifacts per run, 50,000 locations overall, 200,000 JSON values and 64 levels. Combined downloads: 10 MiB, atomic rejection if exceeded. Each run is resolved separately.

    Resolves driver/extension rule IDs, indices and GUIDs. Conflicting rule declarations and invalid indices reject. Undeclared rules, unlocated/logical-only results and missing/cyclic bases remain visible. Original baselineState and suppression kind/status remain; unknown states are labelled unknown rather than filtering results.

    Resolves artifact indices, direct URIs and directory originalUriBaseIds chains; optional mappings override bases with absolute directory URIs. Bases must end in /, without queries/fragments. Backslashes, malformed escaping and non-directory bases reject. Relative URIs without a base stay unresolved. No local path guessing, source-file reads or network requests.

    Keeps each complete originalResult, including primary/related/code-flow locations, original regions, suppressions, baseline, messages and unknown fields. report.json and original.sarif.json retain large-integer and decimal number tokens. text/markdown/id are literal text; messageStrings/arguments and full relationship graphs are not expanded. This is not full SARIF schema certification.

    Table preview: first 200 rows, first 2,000 characters plus ellipsis for longer cells. Above 20,000 report characters, text/copy becomes a summary preview. Complete JSON, CSV, escaped offline HTML and exact original input remain in downloads.

    Worked example

    Example input

    {
      "version": "2.1.0",
      "runs": [
        {
          "tool": {
            "driver": {
              "name": "test",
              "rules": [
                {
                  "id": "R1",
                  "defaultConfiguration": {
                    "level": "error"
                  }
                }
              ]
            }
          },
          "originalUriBaseIds": {
            "ROOT": {
              "uri": "file:///C:/repo/"
            },
            "SRC": {
              "uri": "src/",
              "uriBaseId": "ROOT"
            },
            "CYCLE": {
              "uri": "loop/",
              "uriBaseId": "CYCLE"
            }
          },
          "artifacts": [
            {
              "location": {
                "uri": "a%20b.ts",
                "uriBaseId": "SRC"
              }
            }
          ],
          "results": [
            {
              "ruleIndex": 0,
              "ruleId": "R1",
              "baselineState": "unchanged",
              "suppressions": [
                {
                  "kind": "inSource"
                }
              ],
              "locations": [
                {
                  "physicalLocation": {
                    "artifactLocation": {
                      "index": 0
                    },
                    "region": {
                      "startLine": 3,
                      "startColumn": 5
                    }
                  }
                }
              ],
              "relatedLocations": [
                {
                  "physicalLocation": {
                    "artifactLocation": {
                      "uri": "other.ts",
                      "uriBaseId": "ROOT"
                    }
                  }
                }
              ],
              "codeFlows": [
                {
                  "threadFlows": [
                    {
                      "locations": [
                        {
                          "location": {
                            "physicalLocation": {
                              "artifactLocation": {
                                "uri": "flow.ts",
                                "uriBaseId": "SRC"
                              }
                            }
                          }
                        }
                      ]
                    }
                  ]
                }
              ],
              "message": {
                "markdown": "**literal** <script>never runs</script>"
              }
            },
            {
              "ruleId": "UNKNOWN",
              "locations": [
                {
                  "physicalLocation": {
                    "artifactLocation": {
                      "uri": "x.ts",
                      "uriBaseId": "MISS"
                    }
                  }
                }
              ]
            },
            {
              "ruleId": "UNKNOWN",
              "locations": [
                {
                  "physicalLocation": {
                    "artifactLocation": {
                      "uri": "x.ts",
                      "uriBaseId": "CYCLE"
                    }
                  }
                }
              ]
            },
            {
              "ruleId": "NOLOCATION"
            }
          ]
        }
      ]
    }
    Example options
    {"secondary":"","params":{"spreadsheetSafe":true}}

    Example output

    {"format":"SARIF2.1.0 offline report","summary":{"runs":1,"results":4,"locations":5,"unresolvedLocations":2,"unlocatedResults":1,"unknownRules":3,"baseMappings":0},"mappings":{},"results":[{"run":0,"index":0,"tool":"test","rule":{"id":"R1","status":"resolved","component":"driver","componentIndex":null,"level":"error"},"message":"**literal** <script>never runs</script>","baselineState":"unchanged","baselineStatus":"known","suppressionStates":[{"kind":"inSource","status":null,"kindKnown":true,"statusKnown":null}],"locations":[{"category":"primary","path":"locations/0","status":"resolved","resolvedUri":"file:///C:/repo/src/a%20b.ts","sourceUri":"a%20b.ts","uriBaseId":"SRC","artifactIndex":0,"region":{"startLine":3,"startColumn":5}},{"category":"related","path":"relatedLocations/0","status":"resolved","resolvedUri":"file:///C:/repo/other.ts","sourceUri":"other.ts","uriBaseId":"ROOT","artifactIndex":null,"region":null},{"category":"codeFlow","path":"codeFlows/0/threadFlows/0/locations/0/location","status":"resolved","resolvedUri":"file:///C:/repo/src/flow.ts","sourceUri":"flow.ts","uriBaseId":"SRC","artifactIndex":null,"region":null}],"locationStatus":"listed","originalResult":{"ruleIndex":0,"ruleId":"R1","baselineState":"unchanged","suppressions":[{"kind":"inSource"}],"locations":[{"physicalLocation":{"artifactLocation":{"index":0},"region":{"startLine":3,"startColumn":5}}}],"relatedLocations":[{"physicalLocation":{"artifactLocation":{"uri":"other.ts","uriBaseId":"ROOT"}}}],"codeFlows":[{"threadFlows":[{"locations":[{"location":{"physicalLocation":{"artifactLocation":{"uri":"flow.ts","uriBaseId":"SRC"}}}}]}]}],"message":{"markdown":"**literal** <script>never runs</script>"}}},{"run":0,"index":1,"tool":"test","rule":{"id":"UNKNOWN","status":"unknown_rule","component":"driver","componentIndex":null,"level":"warning"},"message":"","baselineState":null,"baselineStatus":"not_reported","suppressionStates":[],"locations":[{"category":"primary","path":"locations/0","status":"missing_base","resolvedUri":null,"sourceUri":"x.ts","uriBaseId":"MISS","artifactIndex":null,"region":null}],"locationStatus":"listed","originalResult":{"ruleId":"UNKNOWN","locations":[{"physicalLocation":{"artifactLocation":{"uri":"x.ts","uriBaseId":"MISS"}}}]}},{"run":0,"index":2,"tool":"test","rule":{"id":"UNKNOWN","status":"unknown_rule","component":"driver","componentIndex":null,"level":"warning"},"message":"","baselineState":null,"baselineStatus":"not_reported","suppressionStates":[],"locations":[{"category":"primary","path":"locations/0","status":"base_cycle","resolvedUri":null,"sourceUri":"x.ts","uriBaseId":"CYCLE","artifactIndex":null,"region":null}],"locationStatus":"listed","originalResult":{"ruleId":"UNKNOWN","locations":[{"physicalLocation":{"artifactLocation":{"uri":"x.ts","uriBaseId":"CYCLE"}}}]}},{"run":0,"index":3,"tool":"test","rule":{"id":"NOLOCATION","status":"unknown_rule","component":"driver","componentIndex":null,"level":"warning"},"message":"","baselineState":null,"baselineStatus":"not_reported","suppressionStates":[],"locations":[],"locationStatus":"unlocated","originalResult":{"ruleId":"NOLOCATION"}}]}

    When something does not work

    Check version 2.1.0, valid rule/artifact indices and consistent direct URI declarations. Supply correct absolute directory bases or keep unresolved states visible. Inspect unknown templates with the producer; reduce runs/results if complete downloads exceed 10 MiB.

    Frequently asked questions

    Are results without locations discarded?

    No. Their row is explicitly unlocated, and the complete original result remains.

    Why require directory URIs?

    Bases participate in relative-reference resolution. Non-directory/query/fragment bases are outside this contract and reject instead of guessing a source path.

    Does message markdown execute?

    No. It is escaped literal text. Message templates and arguments are not expanded; complete original messages remain for producer readback.

    Documentation & further reading

    Related tools