Torito

SARIF Viewer & Findings Diff

Read a local static-analysis report without connecting a repository or sending findings elsewhere. Filter SARIF evidence, compare observations against a baseline and choose exactly which findings to export.

About SARIF viewerFeatures & how to use

Inspect SARIF 2.1.0 reports locally, filter static-analysis findings, compare a baseline and export selected evidence without uploading source data.

What it can do

  • Read SARIF 2.1.0 tool names, rules, levels, messages, file labels and line numbers, with filters and paginated selection.
  • Compare tool/rule fingerprints or fallback locations; duplicate identities are marked ambiguous and missing observations are not remediation claims.
  • Export selected rows to CSV or JSON. Markdown, paths and snippets remain inert text; external property files and source references are not fetched.
  • Each report is limited to 10 MiB and 25,000 findings. Review warnings about incomplete runs and external properties before drawing conclusions.

How to use it

  1. Open or paste a SARIF 2.1.0 report and optionally a baseline.
  2. Inspect results, filter by level or text, and select the relevant findings.
  3. Download only the selected evidence after reviewing it for sensitive details.