SARIF report: sarif-sample-report
Trust receipt for SARIF report: sarif-sample-report: SARIF summary generated without treating alerts as a certification. Includes checks, evidence, exclusions, freshness, and limitations.
Trust Receipt
trust receipt partial proof with gaps
SARIF report contains machine-readable static analysis results.
Verdict
mixed SARIF summary generated without treating alerts as a certification.
Freshness
static_fixture 2026-06-21T10:30:00Z
Checks
4 2 passed, 0 failed, 1 not checked, 1 inconclusive
Receipt ID
tr_sarif-sarif-sample-report 2026-06-27T00:00:00Z
Boundary
This receipt is not a safety certification, security approval, or live health guarantee. It summarizes the public-safe evidence, checks, exclusions, freshness, and limitations listed below.
Inconclusive
Results inconclusive
1 result(s), 0 error-level result(s), 1 rule(s).
errors=0
warnings=1
notes=0
SARIF results are analyzer findings, not a policy verdict by themselves.
sarif-file
Not Checked
GitHub code-scanning upload not checked
The receipt summarizes SARIF; it does not upload to GitHub code scanning.
sarif-file
Passed
SARIF version passed
SARIF version is 2.1.0.
sarif-file
Runs present passed
1 SARIF run(s) present.
- rules=1
sarif-file
Evidence
Evidence entries are public-safe references and digests, not raw private reports.
| ID | Title | Kind | Reference | Digest |
|---|---|---|---|---|
| sarif-file | SARIF file | sarif | local-public-safe-input:sarif-file | 3a067f6dbc47bd7a... |
Intentionally Excluded
Raw source snippetsThe SARIF adapter summarizes counts and rules. It does not include code snippets, local paths, or fingerprints.
Result locations and fingerprintsThe receipt intentionally omits per-result file locations, partial fingerprints, and code-flow details for public safety.
GitHub code-scanning stateUpload status, alert state, dismissal state, and repository code-scanning configuration are not inferred from a local SARIF file.
Limitations
SARIF findings are alerts, not an independent policy verdict.
GitHub code scanning upload status is intentionally not inferred from a local SARIF file.
The adapter summarizes the file and does not preserve result locations or code snippets.
Freshness depends on optional producer invocation metadata when present.
Reproduce Or Inspect
Generate a SARIF report using the source analyzer.
Generate this receipt.trust-receipt sarif --input report.sarif
Payload SHA-256: a6d474728e234a8014e8efad910df43c7eef83ccec327670b9be1979cd66ec7d
Generated by trust-receipt-generator 0.1.0
payload sha-256 · a6d474728e234a8014e8efad910df43c7eef83ccec327670b9be1979cd66ec7d