microsoft/sarif-sdk v4.6.3
microsoft/sarif-sdk
Captured source
source ↗published Apr 28, 2026seen 4dcaptured 9hhttp 200method plain
v4.6.3
Repository: microsoft/sarif-sdk
Tag: v4.6.3
Published: 2026-04-28T22:12:02Z
Prerelease: no
Release notes:
v4.6.3 Sdk | Driver | Converters | Multitool | Multitool Library
- BRK: Renumber AI validation rules for RFC 2119 compliance (
AI1xxx= MUST/SHALL error;AI2xxx= SHOULD warning/note).AI2006→AI1005,AI1007→AI2014. TheAI3xxxseries is eliminated. - NEW: Add
AI1010.EvidenceBackingResolvable(error) — everysarif:URI inai/evidence[].backingSHALL resolve to an element within the log file (§3.10.3). - NEW: Add
AI1011.RedactedRunMarker(error) —ai/redactedSHALL betrueor absent (neverfalse); whentrue,run.redactionTokensSHALL be non-empty;ai/fullLogLocationSHALL NOT appear unlessai/redactedistrue. - NEW: Add
AI1012.ProvideRuleSubId(error) — AI-generated results MUST carry a hierarchical sub-component onresult.ruleIdbeyond the basereportingDescriptor.id. - NEW: Add
AI1013.NotificationAssociatedRuleResolvable(error) — ifnotification.associatedRuleis present, it SHALL resolve to a valid rule intool.driver.rules[]or an extension'srules[]. - NEW: Add
AI1014.ExecutionNotificationPlacement(error) —AI/EXEC/*descriptors SHALL appear only intoolExecutionNotifications;AI/CFG/*descriptors SHALL appear only intoolConfigurationNotifications. - NEW: Add
AI2015.ProvideAttackerPosition(warning) — each result SHOULD declareai/attackerPosition. Follows the all-or-nothing pattern. - NEW: Add
AI2016.EvidenceBackingConsistency(warning) — anai/evidence[]entry withstrength: "demonstrated"SHOULD carry non-emptybacking. - NEW: Add
AI2017.ProvideNotificationDescriptor(warning) — every notification SHOULD have adescriptorthat resolves to areportingDescriptorintool.driver.notifications[]. - NEW: Add
AI2018.ProvideExecutionSignalArtifact(note) —AI/EXEC/ALAS-SIGNALnotifications SHOULD include alocations[]entry referencing a valid artifact withrolescontaining"attachment". - NEW: Add
AI2019.ProvideNotificationTimestamp(note) — notifications SHOULD includetimeUtcfor execution timeline reconstruction.
Notability
notability 2.0/10Routine SDK release, no traction mentioned.