Neatbo.

SARIF规则与位置离线报告

读取本地SARIF 2.1.0多次运行结果,解析规则、归档索引与目录URI基址,保留未定位、未知状态和完整原结果。

浏览器本地处理输入SARIF 2.1.0 JSON输出核验报告JSON / CSV / HTML单个文件最多 5 MiB · 最多 1 个
  1. 1添加输入
  2. 2调整设置
  3. 3获取结果

工具输入和文件在当前浏览器处理,不会上传。

输入内容

切换工具时在当前标签页临时保留输入。刷新或关闭后清除,较大的结果可能需要重新生成。

⌘ / Ctrl + Enter 运行

或将文件拖到这里

文件留在当前设备,原始文件不会被覆盖。

.sarif · .json

单个文件最多 5 MiB · 最多 1 个

    0 个字符 · 0 字节
    处理选项

    先填写标记为必填的选项,其余可保留默认值。

    正在准备处理工具…

    开始之前

    把扫描器导出的SARIF交给离线报告:先核对规则来源、位置与基址,再解释结果。缺失源码路径、未知抑制状态和无位置结果都需保留,不能因无法定位就消失。

    如何使用

    1. 选择SARIF或粘贴,必要时提供目录URI基址映射。
    2. 查看规则解析、主/相关/代码流位置、缺失基址和原抑制/基线状态。
    3. 下载完整报告和原件;在扫描器中核对消息模板或未支持的关系。

    支持范围与限制

    选择1个或粘贴UTF-8 SARIF 2.1.0 JSON,最多5 MiB;可选目录URI基址JSON映射最多1 MiB。最多10000结果、每次运行10000归档声明、全部50000位置、200000 JSON值、64层。全部下载合计10 MiB,超限原子拒绝;多次运行独立解析。

    支持driver/extension规则的ID、索引和GUID;结果与规则声明冲突、无效索引拒绝。未声明规则、无位置、仅逻辑位置、缺失/循环基址保持可见。原baselineState与suppression kind/status保留,未知值标成unknown,不自动筛除结果。

    解析artifact索引、直接URI和目录originalUriBaseIds链;可选映射以绝对目录URI覆盖基址。基址必须以/结尾,不含查询/片段;反斜线、错误转义或非目录基址拒绝。相对URI无基址保持未解析,不猜本机路径。不读源码、文件系统或网络。

    保留每个完整originalResult,包括主/相关/code-flow位置、原区域、抑制、基线、消息和未知字段;report.json与original.sarif.json保留大整数和小数原数值token。消息text/markdown/id按字面显示,不执行Markdown,也不展开messageStrings、arguments或完整关系图;不是完整SARIF模式认证。

    表格预览前200行,超过2000字符的单元格仅前2000字符加省略号;超过20000字符的文本/复制为摘要预览。完整JSON、CSV、转义离线HTML与精确保留原件在下载文件中。

    操作示例

    示例输入

    {
      "version": "2.1.0",
      "runs": [
        {
          "tool": {
            "driver": {
              "name": "test",
              "rules": [
                {
                  "id": "R1",
                  "defaultConfiguration": {
                    "level": "error"
                  }
                }
              ]
            }
          },
          "originalUriBaseIds": {
            "ROOT": {
              "uri": "file:///C:/repo/"
            },
            "SRC": {
              "uri": "src/",
              "uriBaseId": "ROOT"
            },
            "CYCLE": {
              "uri": "loop/",
              "uriBaseId": "CYCLE"
            }
          },
          "artifacts": [
            {
              "location": {
                "uri": "a%20b.ts",
                "uriBaseId": "SRC"
              }
            }
          ],
          "results": [
            {
              "ruleIndex": 0,
              "ruleId": "R1",
              "baselineState": "unchanged",
              "suppressions": [
                {
                  "kind": "inSource"
                }
              ],
              "locations": [
                {
                  "physicalLocation": {
                    "artifactLocation": {
                      "index": 0
                    },
                    "region": {
                      "startLine": 3,
                      "startColumn": 5
                    }
                  }
                }
              ],
              "relatedLocations": [
                {
                  "physicalLocation": {
                    "artifactLocation": {
                      "uri": "other.ts",
                      "uriBaseId": "ROOT"
                    }
                  }
                }
              ],
              "codeFlows": [
                {
                  "threadFlows": [
                    {
                      "locations": [
                        {
                          "location": {
                            "physicalLocation": {
                              "artifactLocation": {
                                "uri": "flow.ts",
                                "uriBaseId": "SRC"
                              }
                            }
                          }
                        }
                      ]
                    }
                  ]
                }
              ],
              "message": {
                "markdown": "**literal** <script>never runs</script>"
              }
            },
            {
              "ruleId": "UNKNOWN",
              "locations": [
                {
                  "physicalLocation": {
                    "artifactLocation": {
                      "uri": "x.ts",
                      "uriBaseId": "MISS"
                    }
                  }
                }
              ]
            },
            {
              "ruleId": "UNKNOWN",
              "locations": [
                {
                  "physicalLocation": {
                    "artifactLocation": {
                      "uri": "x.ts",
                      "uriBaseId": "CYCLE"
                    }
                  }
                }
              ]
            },
            {
              "ruleId": "NOLOCATION"
            }
          ]
        }
      ]
    }
    示例参数
    {"secondary":"","params":{"spreadsheetSafe":true}}

    示例输出

    {"format":"SARIF2.1.0 offline report","summary":{"runs":1,"results":4,"locations":5,"unresolvedLocations":2,"unlocatedResults":1,"unknownRules":3,"baseMappings":0},"mappings":{},"results":[{"run":0,"index":0,"tool":"test","rule":{"id":"R1","status":"resolved","component":"driver","componentIndex":null,"level":"error"},"message":"**literal** <script>never runs</script>","baselineState":"unchanged","baselineStatus":"known","suppressionStates":[{"kind":"inSource","status":null,"kindKnown":true,"statusKnown":null}],"locations":[{"category":"primary","path":"locations/0","status":"resolved","resolvedUri":"file:///C:/repo/src/a%20b.ts","sourceUri":"a%20b.ts","uriBaseId":"SRC","artifactIndex":0,"region":{"startLine":3,"startColumn":5}},{"category":"related","path":"relatedLocations/0","status":"resolved","resolvedUri":"file:///C:/repo/other.ts","sourceUri":"other.ts","uriBaseId":"ROOT","artifactIndex":null,"region":null},{"category":"codeFlow","path":"codeFlows/0/threadFlows/0/locations/0/location","status":"resolved","resolvedUri":"file:///C:/repo/src/flow.ts","sourceUri":"flow.ts","uriBaseId":"SRC","artifactIndex":null,"region":null}],"locationStatus":"listed","originalResult":{"ruleIndex":0,"ruleId":"R1","baselineState":"unchanged","suppressions":[{"kind":"inSource"}],"locations":[{"physicalLocation":{"artifactLocation":{"index":0},"region":{"startLine":3,"startColumn":5}}}],"relatedLocations":[{"physicalLocation":{"artifactLocation":{"uri":"other.ts","uriBaseId":"ROOT"}}}],"codeFlows":[{"threadFlows":[{"locations":[{"location":{"physicalLocation":{"artifactLocation":{"uri":"flow.ts","uriBaseId":"SRC"}}}}]}]}],"message":{"markdown":"**literal** <script>never runs</script>"}}},{"run":0,"index":1,"tool":"test","rule":{"id":"UNKNOWN","status":"unknown_rule","component":"driver","componentIndex":null,"level":"warning"},"message":"","baselineState":null,"baselineStatus":"not_reported","suppressionStates":[],"locations":[{"category":"primary","path":"locations/0","status":"missing_base","resolvedUri":null,"sourceUri":"x.ts","uriBaseId":"MISS","artifactIndex":null,"region":null}],"locationStatus":"listed","originalResult":{"ruleId":"UNKNOWN","locations":[{"physicalLocation":{"artifactLocation":{"uri":"x.ts","uriBaseId":"MISS"}}}]}},{"run":0,"index":2,"tool":"test","rule":{"id":"UNKNOWN","status":"unknown_rule","component":"driver","componentIndex":null,"level":"warning"},"message":"","baselineState":null,"baselineStatus":"not_reported","suppressionStates":[],"locations":[{"category":"primary","path":"locations/0","status":"base_cycle","resolvedUri":null,"sourceUri":"x.ts","uriBaseId":"CYCLE","artifactIndex":null,"region":null}],"locationStatus":"listed","originalResult":{"ruleId":"UNKNOWN","locations":[{"physicalLocation":{"artifactLocation":{"uri":"x.ts","uriBaseId":"CYCLE"}}}]}},{"run":0,"index":3,"tool":"test","rule":{"id":"NOLOCATION","status":"unknown_rule","component":"driver","componentIndex":null,"level":"warning"},"message":"","baselineState":null,"baselineStatus":"not_reported","suppressionStates":[],"locations":[],"locationStatus":"unlocated","originalResult":{"ruleId":"NOLOCATION"}}]}

    出现问题时

    检查版本2.1.0、有效规则/归档索引及相互一致的直接URI声明。将基址改为正确绝对目录URI,或保留未解析状态。未知模板在生产者查看;完整下载超10 MiB时减少运行/结果再重试。

    常见问题

    没有位置的结果会丢吗?

    不会。结果行明确unlocated;原结果仍完整保留。

    为什么必须目录URI?

    URI基址参与相对引用解析。非目录、查询或片段不在本合同内,工具拒绝而不是猜源码路径。

    消息Markdown会执行吗?

    不会,按字面转义。消息模板与参数不展开,完整原消息仍保留用于生产者读回。

    文档与延伸阅读

    相关工具