pkg.soopen package index

brew / rank 4871

Install sarif-tools with Homebrew, Nix

Set of command-line tools and Python library for working with SARIF files. Version 3.0.5 via Homebrew; verified 2026-09-13. Also installable with nix: nix profile install nixpkgs#sarif-tools.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install sarif-tools

local Homebrew formula metadata

Linux

Nixverified · 92%
nix profile install nixpkgs#sarif-tools

nixpkgs package indexes · pkgs/by-name/sa/sarif-tools/package.nix · source: api.github.com

overview

Package summary

Set of command-line tools and Python library for working with SARIF files

Commands and aliases

  • sarif

history

Project history and usage

SARIF Tools is a Python library and command suite for examining and transforming static-analysis reports.

Project history

Published under Microsoft's GitHub organization, SARIF Tools combines report conversion, comparison and filtering. The 2024 major release reorganized its Python reporting API around IssueReport.

Adoption history

The project documents pip installation on Windows, Linux and macOS. Its Code Climate export supports presenting results in GitLab code-quality reports; no quantitative adoption history is established.

How it is used

Run sarif summary, diff, html or csv against reports or directories. The --check option can produce a failing exit status for selected severities, supporting automated checks.

Why package nerds care

It provides a reusable reporting layer across analyzers that emit SARIF, with both a Python API and a command-line interface.

Timeline

  • 2024-09-10: Version 3.0.0 introduced an IssueReport-based Python API and revised report grouping.

Related projects

  • SARIF is the interchange format consumed by the toolkit; GitLab Code Quality is a documented export destination.

security posture

Risk level: green

library-like package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • library-like package without higher-risk signals

Signals

  • metadata:library-like

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Installs with 10 runtime dependencies.
  • Build metadata lists 4 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
sarifcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-09-19
manager version3.0.5
manager updated2026-09-13
local dataok
upstreamnot checked
latest detectednot detected

https://github.com/microsoft/sarif-tools

install metadata

Package metadata

Package keybrew:sarif-tools
Version3.0.5
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/sarif-tools
Homepagehttps://github.com/microsoft/sarif-tools
Repositoryhttps://github.com/microsoft/sarif-tools
LicenseMIT
Source archivehttps://files.pythonhosted.org/packages/16/3c/68e41db88aa15124175936017928e99182b3df8e6913c5e194c67d641996/sarif_tools-3.0.5.tar.gz
Last updated2026-09-13T14:23:33Z
Pulseupdated
Dependenciesfreetype, jpeg-turbo, libraqm, libtiff, libyaml, little-cms2, numpy, pillow, python@3.14, webp
Build dependenciescmake, meson, ninja, pkgconf
Uses from macOSlibxml2, libxslt
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namesarif-tools
Version Scheme0
Revision3
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

sarif-tools

nix profile install nixpkgs#sarif-tools
  • normalized package name match
  • Matched by: Sarif Tools
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/sa/sarif-tools/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation