Local test, scan, dependency, archive and family-reference audits
Inspect JUnit events, SARIF rules and locations, CycloneDX references, wheel RECORD and GEDCOM links locally; hand off full downloads and explicit unsupported states.
Match the report to the exported task
Use JUnit when CI has already run tests and only exported XML remains. Use CycloneDX when a generated SBOM has contradictory references. Use GEDCOM when a family export has one-way pointers or declared ancestor loops. A generic XML/JSON formatter cannot decide these relationships.
Select a local file or use a complete paste. The table preview is limited to 200 rows, while successful downloads contain every scoped result. Keep the original exports beside the reports. No test runner, SBOM package install, family import, remote reference fetch or user script runs.
| Task | Input | Result and useful check |
|---|---|---|
| JUnit | One or several exported JUnit XML documents | Offline HTML/JSON/CSV; compare testcase outcomes with the producer |
| SARIF | 2.1.0 JSON + directory URI overrides | Complete original results and location states; missing bases remain visible |
| CycloneDX | CycloneDX JSON 1.6 | All reference paths and edges; repair generator IDs rather than overwriting |
| Wheel | .whl archive, original filename | Every RECORD hash/size, metadata and tag; failed status explicit |
| GEDCOM | UTF-8 GEDCOM 5.5.1 with explicit header | Pointers, reciprocity, ancestry SCCs and original.ged; verify facts in source system |
Count JUnit cases separately from their events
The starter contains three cases: one passed, one with two failure events and one skipped. Its summary has one failure case and three outcome events. A testcase combining skipped and failure is mixed. Duplicate names have distinct indices and are never merged.
Suite/container declared counters and wall-clock time remain independent from testcase counts. measuredSeconds is the sum of testcase times only when every case supplies a finite nonnegative time; absent time makes it unknown. The starter container time is 99, while its measured case time is about 0.3.
Nested testsuites/testsuites and testsuite/testcase, ordinary properties and logs are supported. Unknown outcome attributes/elements, flaky/rerun extensions and DTD/entities reject. An empty suite must explicitly declare zero tests. The complete offline HTML escapes logs, failure messages and property text instead of rendering user HTML. Original XML is retained by you, rather than duplicated in downloads.
SARIF: preserve findings when a source base is unresolved
The starter has four results and five primary/related/code-flow locations. R1 resolves to the driver rule’s error level; missing bases, a base cycle and an unlocated result remain visible. Supplying {"ROOT":"file:///D:/new/"} maps the SRC chain to D:/new/src/ without reading source files there. Complete original results retain baseline, suppressions and unknown fields.
Bases must be directory URIs ending in /, without queries or fragments. Invalid indices and conflicting direct/indexed declarations reject; undeclared rules and unknown suppression/baseline states stay explicit. Message markdown is literal escaped text; messageStrings and arguments are not expanded. report.json retains complete originalResult number tokens and original.sarif.json retains input bytes. CSV and HTML list every scoped location plus unlocated results, without certifying the full SARIF schema.
Keep ambiguous SBOM references out of the graph
The starter root app depends on A, A on B, and B back on A. The report shows an A/B SCC plus separate missing and external URN targets. An SCC is a declared dependency cycle, not automatically an invalid or insecure result.
Every bom-ref in the original is indexed with its JSON pointer. Duplicate declarations expose all paths; edges that touch ambiguous declarations are excluded. Duplicated dependency source rows also stay explicit and are excluded. Other objects cannot stand in for component/service targets.
Root reachability is evaluated only with an explicit, unique metadata.component bom-ref. original.json retains all original bytes and numeric tokens. Provides, compositions, formulation, vulnerabilities and other relationship objects remain outside dependency analysis. Only version 1.6 is accepted, with basic structure checks; full official schema validation, vulnerability scanning and compliance decisions remain separate.
Wheel: generating a report does not mean integrity passed
Load the fixed demo_pkg-1.2.3-py2.py3-none-any.whl example: six archive files, five verified payload files and the unhashed RECORD itself. Expanded filename tags are compared with WHEEL; names normalize but versions compare literally. Folded/repeated METADATA headers and entry points remain literal data. Actual 32 MiB input, 64 MiB expanded and 10,000-entry vectors have Node Worker capacity/readback evidence; production-browser acceptance remains centralized.
A bad hash, wrong size, missing/unrecorded file or metadata mismatch yields a complete integrityStatus=failed diagnosis. SHA256/384/512 are supported; SHA224 and unknown hashes are explicitly incomplete, while MD5/SHA1 are forbidden and fail. RECORD self and legacy jws/p7s exceptions stay visible. verified_recorded_payload does not establish authenticity, safety or your machine ABI; nothing is installed, imported, executed or unpacked to disk.
- Keep the original wheel filename and check failures with a trusted producer; do not rewrite RECORD to conceal changes.
- This task audits the selected wheel, not an installed disk copy. Historical pip feedback demonstrates demand without claiming current pip behavior.
Treat GEDCOM links as declarations requiring evidence
The starter has an adopted parent-child declaration and a missing CHIL target. Each issue carries the original line. INDI FAMC/FAMS must point to FAM, while FAM CHIL/HUSB/WIFE must point to INDI. Missing reverse declarations are reported, not created.
Ancestor SCCs use directed declared parent-to-child edges. Adopted, foster, sealing, birth and unknown/multiple pedigree values remain visible; the graph does not establish biological facts. Spouse rings do not become ancestor cycles. Unknown tags and original UTF-8 BOM/newline bytes remain available.
CONT adds the preceding physical newline and CONC concatenates text. Values longer than 4096 UTF-8 bytes use value:null with external-original-value plus an exact span in original.ged; a logical continued value uses ordered byte/literal segments joined by concat. These nulls are present values stored in the original, not missing fields. Download original.ged with the JSON and reconstruct the specified bytes when reviewing long text.
Use all budgets together and recover from the actual failure
A supported input can exceed the complete 10 MiB download budget before its row-count limit. Such failures return no partial report. Do not discard unknown records to force a result; correct or partition in the producer only when the task remains meaningful.
When report JSON exceeds 20,000 characters, the result text and copy button provide a compact preview with row counts and fullReportInDownload:true. Download report.json/CSV/HTML for the complete handoff.
The table shows the first 200 rows; longer cells show their first 2,000 characters plus an ellipsis. Above 20,000 characters, text/copy is a summary preview. Full JSON/CSV/HTML are not truncated; the receiver should read downloaded files instead of treating copied previews as complete reports.
| Task | Input | Additional limits |
|---|---|---|
| JUnit | 20 files, each 5 MiB, total 10 MiB; paste 5 MiB | 10000 cases, 50000 XML elements, 64 levels |
| SARIF | One file/paste 5 MiB; base JSON 1 MiB | 10000 results,10000 artifacts/run,50000 locations,200000 JSON values,depth64 |
| CycloneDX | One file/paste 5 MiB | 10000 declarations, 50000 edges, 200000 JSON values, depth64 |
| Wheel | One file 32 MiB; no paste | 10000 ZIP entries,64 MiB expanded,ratio200,200000 report JSON values |
| GEDCOM | One file/paste 5 MiB | 50000 physical lines, 10000 top-level records, depth64, 50000 combined relationship/ancestry edges |
- JUnit: re-export unsupported producer outcomes; do not relabel flaky events as passes.
- CycloneDX: fix uniqueness and target references in the generator, then rerun; unresolved external URNs need their own workflow.
- GEDCOM: repair format/version/encoding or duplicate xrefs in the source system; check one-way links against evidence before editing.
- After cancellation, rerun a valid source. Keep complete downloads rather than treating the first-200 preview as a final artifact.
References
- JUnit XML to HTML question
First-person task: an exported test.xml needs a readable HTML report without the available Ant workflow. No tests are executed here.
- Conan duplicate and missing bom-ref report
First-person producer issue: generated component references repeat and dependency targets are absent. Demand evidence, not a claim about market scale.
- GEDCOM FAMC versus CHIL question
First-person evidence: inconsistent one-way family references need inspection, without automatically inventing reverse declarations.
- GEDCOM ancestor loops question
First-person request for online/local detection of self-ancestor relationships; spouse rings are a separate graph.
- Official CycloneDX JSON 1.6 schema
Correctness reference only. This tool checks scoped reference semantics and does not certify the entire schema.
- junitparser source
Independent reader used for testcase events and nested suites; producer dialects still need explicit support.
- python-gedcom source
Independent GEDCOM reader for pointers and CONT/CONC text; no family facts are inferred.
- SARIF Windows source-base feedback
First-person monorepo feedback about unresolved source bases; this tool accepts explicit directory URI mappings without traversing local source.
- Wheel RECORD hash-audit question
A2015 user reports editing a wheel and installing without warnings; evidence for archive audit demand, not a statement about current pip behavior.
- Python wheel binary-distribution specification
Correctness reference for filenames, tags, RECORD and signature exceptions; not evidence of demand volume.
- Python core-metadata specification
Current Metadata-Version2.6; headers/body are retained without certifying all metadata field semantics.
- Microsoft SARIF SDK source
Independent directory-URI readback reference; source reads and fingerprint features are not invoked.
Tools in this category
Expand a tool to see its steps, options and supported formats, then open its workspace.
JUnit offline test reportRead local JUnit XML results, distinguish testcase outcomes from declared counters and download every failure and log in an offline report.
Turn exported CI test XML into a readable report without running tests. Keep nested suite paths, repeated testcase names, multiple failure events and literal logs together with the original files.
Steps
- Open one or several exported JUnit XML files, or paste one document.
- Review case outcomes, mixed events, nested paths and separately declared suite counters.
- Download the full offline HTML, JSON/CSV; retain the original input separately.
Available options
- Protect CSV formula-like text
- On by default
Capabilities and limits
- Up to 20 UTF-8 files, each 5 MiB and 10 MiB combined, or one pasted XML up to 5 MiB. Across the input: 10,000 testcases, 50,000 XML element nodes and 64 element levels. Selected files take precedence. Combined downloads up to 10 MiB; an oversized complete report rejects atomically. Table preview first 200 cases.
- Supports nested testsuites/testsuites and testsuite/testcase, failure/error/skipped events, ordinary properties and system-out/system-err. A testcase may have multiple events; it counts once in summary. Multiple outcome kinds are explicitly mixed. Duplicate names remain separate indexed cases, without merging.
- Accepted testcase attributes: name, classname, time, assertions, file, line, url and id. Unknown outcome elements or attributes, flaky/rerun extensions, DTD and external entities reject. Empty suites must explicitly declare tests="0". Correct or re-export unsupported producer data; it is never labelled passed.
- Declared suite/container counters and time stay separate from testcase counts. measuredSeconds sums testcase times only if every case supplies a finite nonnegative time; otherwise null/unknown. This sum is not suite wall time. HTML escapes all text and has no script/source fetching. JSON retains every event, suite log and property; CSV retains every case, with optional formula protection. Keep the original XML beside the report; it is not copied into downloads.
- The result text and copy action use a compact preview when the report exceeds 20,000 characters. Complete report.json, CSV and HTML are downloaded artifacts. Long table cells show only their first 2,000 characters plus ellipsis; complete downloads are not truncated.
SARIF rules and locations reportRead local SARIF 2.1.0 runs, resolve rules, artifact indices and directory URI bases, preserving unlocated results, unknown states and complete original results.
Inspect a scanner’s exported SARIF offline: first check rule provenance, locations and bases, then interpret findings. Missing source paths, unknown suppression states and unlocated results remain visible instead of disappearing when resolution fails.
Steps
- Select or paste SARIF; optionally provide directory URI base mappings.
- Review rule resolution, primary/related/code-flow locations, missing bases and original suppression/baseline states.
- Download the complete report and original; use the producer to inspect message templates or unsupported relationships.
Available options
- Protect CSV formula-like text
- On by default
Capabilities and limits
- Select one UTF-8 SARIF 2.1.0 JSON file or paste up to 5 MiB; optional directory-base mapping JSON up to 1 MiB. Limits: 10,000 results, 10,000 artifacts per run, 50,000 locations overall, 200,000 JSON values and 64 levels. Combined downloads: 10 MiB, atomic rejection if exceeded. Each run is resolved separately.
- Resolves driver/extension rule IDs, indices and GUIDs. Conflicting rule declarations and invalid indices reject. Undeclared rules, unlocated/logical-only results and missing/cyclic bases remain visible. Original baselineState and suppression kind/status remain; unknown states are labelled unknown rather than filtering results.
- Resolves artifact indices, direct URIs and directory originalUriBaseIds chains; optional mappings override bases with absolute directory URIs. Bases must end in /, without queries/fragments. Backslashes, malformed escaping and non-directory bases reject. Relative URIs without a base stay unresolved. No local path guessing, source-file reads or network requests.
- Keeps each complete originalResult, including primary/related/code-flow locations, original regions, suppressions, baseline, messages and unknown fields. report.json and original.sarif.json retain large-integer and decimal number tokens. text/markdown/id are literal text; messageStrings/arguments and full relationship graphs are not expanded. This is not full SARIF schema certification.
- Table preview: first 200 rows, first 2,000 characters plus ellipsis for longer cells. Above 20,000 report characters, text/copy becomes a summary preview. Complete JSON, CSV, escaped offline HTML and exact original input remain in downloads.
CycloneDX dependency-reference auditAudit local CycloneDX 1.6 bom-ref declarations and dependency edges, showing duplicates, dangling references, external URNs and unambiguous cycles.
Inspect a generated SBOM before handing it to another system. Find cross-record reference problems that ordinary JSON syntax checks cannot explain, while retaining the complete original document.
Steps
- Open or paste a CycloneDX 1.6 SBOM exported by your build.
- Check every duplicate path, unresolved edge and SCC; check whether a root was explicitly declared.
- Download complete reference reports and original.json, then repair the generator and rerun.
Available options
- Protect CSV formula-like text
- On by default
Capabilities and limits
- One UTF-8 JSON file or paste up to 5 MiB; 10,000 bom-ref declarations, 50,000 declared dependsOn edges, 200,000 JSON values and depth 64. Selected file takes precedence. All downloads combined up to 10 MiB; a large complete report can reach this cap before a count cap and then rejects atomically. Preview first 200 rows.
- Supports CycloneDX JSON 1.6 only, with basic component/service/dependency shape checks, not complete official schema certification. Nested components/services and metadata.component are recognized. Every bom-ref declaration anywhere in the original is indexed with its JSON pointer. Other objects are not component/service graph targets. Version 1.4/1.5 reject.
- Duplicate bom-ref declarations report every original path; their edges are excluded instead of overwriting an object. Duplicate dependency ref rows are explicit and all of those source edges are excluded. Repeated targets within a single dependency row remain visible as duplicate_edge. Missing local references, wrong target kind and unresolved external urn:cdx references are distinct.
- SCC/self-loop analysis uses unambiguous internal component/service edges only. Reachability needs an explicit, unique metadata.component bom-ref; no first-component guess. The original JSON bytes, including precise numeric tokens and fields outside graph scope, remain in original.json. provides, compositions, formulation and vulnerabilities are preserved but not analysed. No network resolution, vulnerability scan or compliance verdict.
- The result text and copy action use a compact preview when the report exceeds 20,000 characters. Complete report.json, CSV and HTML are downloaded artifacts. Long table cells show only their first 2,000 characters plus ellipsis; complete downloads are not truncated.
Wheel archive and RECORD auditCompare a local wheel filename, metadata, tags and every RECORD hash/size, distinguishing integrity failures, unsupported hashes and unverified signatures.
Before installing an unfamiliar wheel, inspect whether its archive declarations agree with its bytes. This task reads the file without importing the package; a bad hash produces a failed audit, so generating a report never substitutes for passing verification.
Steps
- Select a wheel with its original filename, or load the fixed small-file example.
- Review integrity status, verified files, failures, unsupported hashes and unverified signatures.
- Download the complete audit and check failures with a trusted producer; the report is not a security or installation approval.
Available options
- Protect CSV formula-like text
- On by default
Capabilities and limits
- Select exactly one .whl file up to 32 MiB; no pasted archive. ZIP: 10,000 entries, 64 MiB expanded and compression ratio 200 per entry. Unsafe paths, duplicates, CRC failures, encryption, multiple disks and ZIP64 reject. Report: 200,000 JSON values and 10 MiB combined downloads. Any exceeded budget rejects atomically, without a partial audit.
- Supports Wheel-Version 1.0 and Metadata-Version 1.1, 1.2 and 2.1–2.6. Exactly one filename-matching dist-info directory must contain METADATA/WHEEL/RECORD. Names compare after dash/underscore/dot normalization; versions compare literally, without inferring PEP440 equivalence. Optional build and compressed tags are compared with WHEEL. Folded/repeated headers, description body and entry points remain literal data.
- Checks every archive file against canonical URL-safe Base64 SHA256/384/512 RECORD hashes and byte sizes. Missing, unrecorded, mismatched hash/size or inconsistent metadata means integrityStatus=failed. SHA224 and other unknown hashes are unsupported_hash/incomplete; MD5/SHA1 are forbidden and fail. A failed audit still delivers its complete diagnosis; it does not claim success.
- RECORD itself must have empty hash/size. Legacy RECORD.jws/p7s files are signature_not_verified. verified_recorded_payload describes recorded payload checks only, not package authenticity, installation safety, host ABI or platform suitability. Nothing is installed, imported, executed or unpacked to disk.
- Table preview: first 200 rows; cells over 2,000 characters show their first 2,000 plus an ellipsis. Above 20,000 report characters, text/copy becomes a summary preview. Full JSON, CSV and HTML remain downloadable, with unsupported hashes and exceptions visible.
GEDCOM references and ancestry auditInspect UTF-8 GEDCOM 5.5.1 family/person references, reciprocity and declared ancestry SCCs with original lines and pedigree classifications.
Check a genealogy export before import: locate dangling or one-way family links and declared ancestor cycles. Retain the original source and report the evidence without adding relatives or inferring biological relationships.
Steps
- Open a UTF-8 GEDCOM 5.5.1 export or paste its complete source.
- Review line-numbered target and reciprocity issues, pedigree declarations and ancestry SCC members.
- Download original.ged and full reports; verify facts with the source system before making corrections.
Available options
- Protect CSV formula-like text
- On by default
Capabilities and limits
- One UTF-8 file or paste up to 5 MiB, 50,000 physical lines, 10,000 top-level records including HEAD/TRLR, 64 hierarchy levels, and 50,000 combined declared relationship plus derived ancestry edges. Selected file takes precedence. Total downloads up to 10 MiB; oversized complete reports reject atomically. Preview first 200 rows.
- HEAD/GEDC/VERS must explicitly be 5.5.1 and HEAD/CHAR UTF-8. Exact source BOM and CRLF/LF/CR endings remain in original.ged. GEDCOM 7, ANSEL, UTF-16, level gaps, duplicate xrefs, blank physical lines and malformed pointers reject. Unknown tags remain in source-derived JSON and original bytes.
- INDI FAMC/FAMS and FAM CHIL/HUSB/WIFE targets are type-checked, with dangling/wrong-type/duplicate/absent reciprocal lines reported. CONT/CONC text is resolved without dropping continuation text; original hierarchy/value fields remain. Continued or nested continuation pointer syntax rejects rather than guessing.
- Ancestor SCCs use declared parent-to-child edges only. Pedigree values birth/adopted/foster/sealing/unknown/multiple and original PEDI values/lines remain visible; these declarations do not establish biological facts. Spouse rings are not ancestry cycles. Reports include every reference, issue and SCC member, not exponential enumeration of all simple cycles. No records edited, relationship inference, import or database write.
- Values longer than 4096 UTF-8 bytes have value:null with external-original-value and an exact byte span into downloaded original.ged. Multiline logical values carry ordered byte/literal segments joined by concat, preserving CONT newline and CONC concatenation. A null with this status is a present value stored in the original, not a missing field.
- The result text and copy action use a compact preview when the report exceeds 20,000 characters. Complete report.json, CSV and HTML are downloaded artifacts. Long table cells show only their first 2,000 characters plus ellipsis; complete downloads are not truncated.