Trust Receipt trust receiptpartial proof with gaps

SARIF report: sarif-sample-report

SARIF report contains machine-readable static analysis results.

Verdict
mixed
SARIF summary generated without treating alerts as a certification.
Freshness
static_fixture
2026-06-21T10:30:00Z
Checks
4
2 passed, 0 failed, 1 not checked, 1 inconclusive
Receipt ID
tr_sarif-sarif-sample-report
2026-06-27T00:00:00Z

Boundary

This receipt is not a safety certification, security approval, or live health guarantee. It summarizes the public-safe evidence, checks, exclusions, freshness, and limitations listed below.

Inconclusive

Results
inconclusive
1 result(s), 0 error-level result(s), 1 rule(s).
  • errors=0
  • warnings=1
  • notes=0
  • SARIF results are analyzer findings, not a policy verdict by themselves.
sarif-file

Not Checked

GitHub code-scanning upload
not checked
The receipt summarizes SARIF; it does not upload to GitHub code scanning.
sarif-file

Passed

SARIF version
passed
SARIF version is 2.1.0.
  • schema=https://json.schemastore.org/sarif-2.1.0.json
sarif-file
Runs present
passed
1 SARIF run(s) present.
  • rules=1
sarif-file

Evidence

Evidence entries are public-safe references and digests, not raw private reports.

IDTitleKindReferenceDigest
sarif-fileSARIF filesariflocal-public-safe-input:sarif-file3a067f6dbc47bd7a...

Intentionally Excluded

Raw source snippets
The SARIF adapter summarizes counts and rules. It does not include code snippets, local paths, or fingerprints.
Result locations and fingerprints
The receipt intentionally omits per-result file locations, partial fingerprints, and code-flow details for public safety.
GitHub code-scanning state
Upload status, alert state, dismissal state, and repository code-scanning configuration are not inferred from a local SARIF file.

Limitations

SARIF findings are alerts, not an independent policy verdict.
GitHub code scanning upload status is intentionally not inferred from a local SARIF file.
The adapter summarizes the file and does not preserve result locations or code snippets.
Freshness depends on optional producer invocation metadata when present.

Reproduce Or Inspect

Generate a SARIF report using the source analyzer.
Generate this receipt.
trust-receipt sarif --input report.sarif