receipt · SARIF report: sarif-sample-report

reading room · 336 words · 1 min

SARIF report: sarif-sample-report

Trust receipt for SARIF report: sarif-sample-report: SARIF summary generated without treating alerts as a certification. Includes checks, evidence, exclusions, freshness, and limitations.

Trust Receipt

trust receipt partial proof with gaps

SARIF report contains machine-readable static analysis results.

Verdict

mixed SARIF summary generated without treating alerts as a certification.

Freshness

static_fixture 2026-06-21T10:30:00Z

Checks

4 2 passed, 0 failed, 1 not checked, 1 inconclusive

Receipt ID

tr_sarif-sarif-sample-report 2026-06-27T00:00:00Z

Boundary

This receipt is not a safety certification, security approval, or live health guarantee. It summarizes the public-safe evidence, checks, exclusions, freshness, and limitations listed below.

Inconclusive

  • Results inconclusive

  • 1 result(s), 0 error-level result(s), 1 rule(s).

    • errors=0

    • warnings=1

    • notes=0

    • SARIF results are analyzer findings, not a policy verdict by themselves.

  • sarif-file

Not Checked

  • GitHub code-scanning upload not checked

  • The receipt summarizes SARIF; it does not upload to GitHub code scanning.

  • sarif-file

Passed

Evidence

Evidence entries are public-safe references and digests, not raw private reports.

ID Title Kind Reference Digest
sarif-file SARIF file sarif local-public-safe-input:sarif-file 3a067f6dbc47bd7a...

Intentionally Excluded

Raw source snippetsThe SARIF adapter summarizes counts and rules. It does not include code snippets, local paths, or fingerprints.

Result locations and fingerprintsThe receipt intentionally omits per-result file locations, partial fingerprints, and code-flow details for public safety.

GitHub code-scanning stateUpload status, alert state, dismissal state, and repository code-scanning configuration are not inferred from a local SARIF file.

Limitations

SARIF findings are alerts, not an independent policy verdict.

GitHub code scanning upload status is intentionally not inferred from a local SARIF file.

The adapter summarizes the file and does not preserve result locations or code snippets.

Freshness depends on optional producer invocation metadata when present.

Reproduce Or Inspect

Generate a SARIF report using the source analyzer.

Generate this receipt.trust-receipt sarif --input report.sarif

Payload SHA-256: a6d474728e234a8014e8efad910df43c7eef83ccec327670b9be1979cd66ec7d

Generated by trust-receipt-generator 0.1.0

payload sha-256 · a6d474728e234a8014e8efad910df43c7eef83ccec327670b9be1979cd66ec7d