{"_id":"@a11yst/sarif","_rev":"3-064f17a4bd1cc5f17ca5c0b22ae2c5ef","name":"@a11yst/sarif","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"@a11yst/sarif","version":"1.0.0","license":"MPL-2.0","_id":"@a11yst/sarif@1.0.0","maintainers":[{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"}],"homepage":"https://github.com/angelabenavente/a11yst#readme","bugs":{"url":"https://github.com/angelabenavente/a11yst/issues"},"dist":{"shasum":"90b4122bb7d19e26d07b12e96c9e3e0895ea17d1","tarball":"https://registry.npmjs.org/@a11yst/sarif/-/sarif-1.0.0.tgz","fileCount":63,"integrity":"sha512-0a39NcCjSZTYJU5ZWjXmBKsV23nfiu3sIqFEYRhU2XPxkoPVd6LMhAngvwmM1PXJT3kxwsEjHXjAqhr8PmpapQ==","signatures":[{"sig":"MEQCIG5Gtz0J6dIRVjDY/h/pMME1ecE0NvS11gM7FZ+DC+eoAiBmUJ1zsKmO6/rKObWRC4Nj8DMWFLPDHWBzGDrYFiKYdw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":112451},"main":"./dist/index.js","type":"module","_from":"file:a11yst-sarif-1.0.0.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsc -p tsconfig.json","clean":"rm -rf dist *.tsbuildinfo","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"},"_resolved":"/private/var/folders/tf/l5jz90dj0yncc_ds04tbfs5c0000gn/T/3b450a3d7180dc1cdf4c740f6d9142ff/a11yst-sarif-1.0.0.tgz","_integrity":"sha512-0a39NcCjSZTYJU5ZWjXmBKsV23nfiu3sIqFEYRhU2XPxkoPVd6LMhAngvwmM1PXJT3kxwsEjHXjAqhr8PmpapQ==","repository":{"url":"git+https://github.com/angelabenavente/a11yst.git","type":"git"},"_npmVersion":"10.9.0","description":"Pure SARIF 2.1.0 generation for a11yst audit results","directories":{},"_nodeVersion":"22.12.0","dependencies":{"@a11yst/types":"1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.2"},"_npmOperationalInternal":{"tmp":"tmp/sarif_1.0.0_1787506233938_0.7067232832301829","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@a11yst/sarif","version":"1.0.1","license":"MPL-2.0","_id":"@a11yst/sarif@1.0.1","maintainers":[{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"}],"homepage":"https://github.com/angelabenavente/a11yst#readme","bugs":{"url":"https://github.com/angelabenavente/a11yst/issues"},"dist":{"shasum":"b685a025b45c71b727aa046072803bda3a8e7fac","tarball":"https://registry.npmjs.org/@a11yst/sarif/-/sarif-1.0.1.tgz","fileCount":63,"integrity":"sha512-nvgQ63btLESQOamygVV8lZY+z07MFN5Xj6t+T/5M4ZSv5KN41he1rYeFRtakuH5+gFdEpF422l+Ao4EnfOkQ/w==","signatures":[{"sig":"MEYCIQDFcj2fJfvWZ0c0tEsQZoFUgBwHwex0950OEKXShblBjwIhAIQdYmWLZ9omKFtN/3v88XNtb2HdYFgpZBem/wI53LUu","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":112451},"main":"./dist/index.js","type":"module","_from":"file:a11yst-sarif-1.0.1.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsc -p tsconfig.json","clean":"rm -rf dist *.tsbuildinfo","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"},"_resolved":"/private/var/folders/tf/l5jz90dj0yncc_ds04tbfs5c0000gn/T/fcef108524a70b60aec37699f3b0c15d/a11yst-sarif-1.0.1.tgz","_integrity":"sha512-nvgQ63btLESQOamygVV8lZY+z07MFN5Xj6t+T/5M4ZSv5KN41he1rYeFRtakuH5+gFdEpF422l+Ao4EnfOkQ/w==","repository":{"url":"git+https://github.com/angelabenavente/a11yst.git","type":"git"},"_npmVersion":"10.9.8","description":"Pure SARIF 2.1.0 generation for a11yst audit results","directories":{},"_nodeVersion":"22.23.1","dependencies":{"@a11yst/types":"1.0.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.2"},"_npmOperationalInternal":{"tmp":"tmp/sarif_1.0.1_1787508667207_0.22826724452016145","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@a11yst/sarif","version":"1.0.2","description":"Pure SARIF 2.1.0 generation for a11yst audit results","type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"main":"./dist/index.js","types":"./dist/index.d.ts","dependencies":{"@a11yst/types":"1.0.2"},"devDependencies":{"typescript":"^5.7.2"},"license":"MPL-2.0","repository":{"type":"git","url":"git+https://github.com/angelabenavente/a11yst.git"},"homepage":"https://www.a11yst.dev","bugs":{"url":"https://github.com/angelabenavente/a11yst/issues"},"publishConfig":{"access":"public"},"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","clean":"rm -rf dist *.tsbuildinfo"},"_id":"@a11yst/sarif@1.0.2","_integrity":"sha512-4RatAjCIZP+q2VOGCmEwzEg7In1HgG/vSi3dWPZfSOzO02dXUlIJWksw1dJOaGi6qcbVQeZyCQ2QKFP52KIn8g==","_resolved":"/private/var/folders/tf/l5jz90dj0yncc_ds04tbfs5c0000gn/T/faa6097bf20474a5650fb391160f524b/a11yst-sarif-1.0.2.tgz","_from":"file:a11yst-sarif-1.0.2.tgz","_nodeVersion":"22.23.1","_npmVersion":"10.9.8","dist":{"integrity":"sha512-4RatAjCIZP+q2VOGCmEwzEg7In1HgG/vSi3dWPZfSOzO02dXUlIJWksw1dJOaGi6qcbVQeZyCQ2QKFP52KIn8g==","shasum":"8da7a9432026baf6c3578027f5ceb60cf933b610","tarball":"https://registry.npmjs.org/@a11yst/sarif/-/sarif-1.0.2.tgz","fileCount":63,"unpackedSize":112763,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIBoACD+jYMl91Vh58Grigu8THuXBlX0zKEakMnUymizAAiEAsUyZFGd87tChREXlNNZhu4pPXwFwiXBvCkD9QaaV6ws="}]},"_npmUser":{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"},"directories":{},"maintainers":[{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sarif_1.0.2_1787683105022_0.951960060681045"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-23T17:30:33.768Z","modified":"2026-08-25T18:38:25.490Z","1.0.0":"2026-08-23T17:30:34.088Z","1.0.1":"2026-08-23T18:11:07.356Z","1.0.2":"2026-08-25T18:38:25.167Z"},"bugs":{"url":"https://github.com/angelabenavente/a11yst/issues"},"license":"MPL-2.0","homepage":"https://www.a11yst.dev","repository":{"type":"git","url":"git+https://github.com/angelabenavente/a11yst.git"},"description":"Pure SARIF 2.1.0 generation for a11yst audit results","maintainers":[{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"}],"readme":"# @a11yst/sarif [![NPM version](https://img.shields.io/npm/v/@a11yst/sarif.svg?style=flat)](https://www.npmjs.com/package/@a11yst/sarif) [![License: MPL-2.0](https://img.shields.io/badge/License-MPL--2.0-blue.svg)](LICENSE) [![NPM total downloads](https://img.shields.io/npm/dt/@a11yst/sarif.svg?style=flat)](https://www.npmjs.com/package/@a11yst/sarif)\n\nPure SARIF 2.1.0 generation for a11yst audit results.\n\nThis package converts structured a11yst findings into a SARIF log that validates\nagainst the OASIS SARIF 2.1.0 Plus Errata 01 schema. It does not read files,\nwrite artifacts, or integrate with the CLI (Phase 9d).\n\n## Public API\n\n- `generateSarif(input, options?)` — build a SARIF log, summary, and diagnostics\n- `serializeSarif(log)` — deterministic JSON with 2-space indent and trailing newline\n- `mapSeverityToSarifLevel(severity)` — a11yst → SARIF level mapping\n\n## Severity mapping\n\n| a11yst canonical | SARIF   |\n|------------------|---------|\n| minor            | note    |\n| medium           | warning |\n| high             | error   |\n| critical         | error   |\n\nResult properties include `a11yst.severity` (canonical) and `a11yst.sourceImpact`\n(raw axe impact when available).\n\nClassifications and policy breaches do **not** change result levels.\n\n## Rules and fingerprints\n\n- One SARIF rule descriptor per `ruleId`\n- `partialFingerprints[\"a11ystFingerprint/v1\"]` preserves a11yst fingerprints exactly\n- `primaryLocationLineHash` is never fabricated\n\n## Lifecycle\n\nWhen baseline comparison is complete, all results receive `baselineState`:\n\n- `new` → `new`\n- `known` → `unchanged`\n- `regressed` → `updated`\n\nWhen comparison is incomplete, `baselineState` is omitted on all results.\na11yst lifecycle is always preserved in `properties.a11yst.lifecycle`.\n\n## Classifications\n\nClassified findings remain visible SARIF results. SARIF suppressions are not used.\n\n## Locations\n\n- **Physical locations** only when `finding.sourceLocation` contains a validated\n  repository-relative path and line number\n- **Logical locations** for routes and flow checkpoints when no source location exists\n- Source mapping is not implemented in 9c\n\n## Validation\n\nUnit tests validate generated logs offline against a local copy of the official\nOASIS schema in `tests/fixtures/sarif/`.\n\n## Phase 9c scope\n\nPure SARIF generation only — no filesystem or CLI integration.\n\n## Phase 9d integration\n\n- `a11yst audit --sarif` writes `reports/a11yst.sarif` inside the audit bundle\n- `a11yst audit --sarif-output <path>` also writes an identical copy to a custom path\n- `a11yst audit --no-sarif` disables SARIF even when enabled in config\n- `a11yst report --format sarif --from <results.json> --output <path>` regenerates SARIF offline\n- SARIF is disabled by default in configuration\n- SARIF generation does not change CI policy exit codes (0/1/2)\n- SARIF is still written when policy exit code is 2\n- No GitHub upload, source mapping, or CLI stdout SARIF mode yet\n","readmeFilename":"README.md"}