sarif-tools
SARIF tools
Decision gist · record as of 2026-08-14
Yes. The package is actively maintained, has low install friction, carries a permissive MIT license, and fills a clear need for teams working with SARIF output from multiple static analysis tools. No known vulnerabilities. Install it if you need to process, report on, or compare results from security or code-quality scanning tools.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.8 or later.
- The `sarif` command-line tool may need PATH configuration after installation on Windows, Linux, or macOS; alternatively use `python -m sarif`.
- Low friction install with a pure Python wheel.
License · maintenance · safety
permissive license (permissive) — MIT license (permissive) means you can use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.
last release 2025-07-17 (393 days) · last repo commit 2026-04-21 · 155 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 558,037 downloads/mo, #6,008 on PyPI
Alternatives
Verify before relying
pip install sarif-tools
# Command-line usage
sarif summary path/to/results.sarif
# Or via Python
from sarif_tools import loader
run = loader.loader_from_file_path('results.sarif')
for result in run.results:
print(result.message.text)- Whether the package handles all SARIF specification edge cases or only common tool outputs
- Performance characteristics when processing very large SARIF files
- Whether git blame integration (blame command) works across all repository types
What it is and what it does
SARIF Tools is a command-line utility and Python library for working with SARIF files—the standard interchange format for static analysis tool output. It reads SARIF files produced by security scanners, linters, and code analysis tools, then transforms them into human-readable formats (HTML, CSV, Word documents, Code Climate JSON) or processes them programmatically. The package includes commands to summarize issues, compare results across builds, generate trend reports from timestamped scans, and enhance results with git blame information.
The library depends on jinja2 for templating, jsonpath-ng for navigating SARIF JSON structures, matplotlib for visualization, python-docx for Word document generation, and pyyaml for configuration. It's designed to handle real-world SARIF output from tools that may diverge from the standard—applying minor normalization to severity levels, message formats, and location representations so that results are usable even when tool authors haven't perfectly aligned their output to the spec.
Use it for
- Convert SARIF output from security scanners into HTML reports for stakeholder review
- Generate CSV exports of all issues found across multiple static analysis tool runs
- Compare SARIF results between two builds to identify newly introduced or resolved issues
- Create Word document summaries of code quality findings for compliance or audit documentation
- Track trends in issue counts over time using timestamped SARIF filenames
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The package is actively maintained, has low install friction, carries a permissive MIT license, and fills a clear need for teams working with SARIF output from multiple static analysis tools. No known vulnerabilities. Install it if you need to process, report on, or compare results from security or code-quality scanning tools.
Install
sarif-tools on PyPI
Before you install
Low friction install with a pure Python wheel. Actively maintained as of April 2026 with recent releases. Requires Python 3.8 or later and five runtime dependencies (jinja2, jsonpath-ng, matplotlib, python-docx, pyyaml) that are all standard ecosystem packages.
Requires Python 3.8 or later. The `sarif` command-line tool may need PATH configuration after installation on Windows, Linux, or macOS; alternatively use `python -m sarif`.
License in practice
MIT license (permissive) means you can use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.
Quickstart
pip install sarif-tools
# Command-line usage
sarif summary path/to/results.sarif
# Or via Python
from sarif_tools import loader
run = loader.loader_from_file_path('results.sarif')
for result in run.results:
print(result.message.text)
Verify before relying
- Whether the package handles all SARIF specification edge cases or only common tool outputs
- Performance characteristics when processing very large SARIF files
- Whether git blame integration (blame command) works across all repository types
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release <4.0,>=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 5 packagesjinja2jsonpath-ngmatplotlibpython-docxpyyaml |
| Maintenance | Actively maintained 393 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 558,037 / month, #6,008 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: sarif_tools-3.0.5-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “SARIF file processing”
- sarif-toolsParses, analyzes, and transforms SARIF (Static Analysis Results…
- bandit-sarif-formatterConverts Bandit security analysis output into SARIF 2.1.0 format for…
- sarif-omProvides Python classes implementing the SARIF 2.1.0 object model for…
Give your agent the search over MCP, or paste the wish link into any chat.
More Quality Assurance packages
Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.
Install it if you want to measure test completeness or enforce coverage thresholds in your project.
Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.
Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.
Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.
pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.
Install it if your test suite takes long enough that parallelization would save meaningful time.
Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.
Install it if you work with CloudFormation templates.
See also sarif-om · bandit-sarif-formatter · socketsecurity · csv-diff · xlsx2csv · ansys-dpf-core · strip-markdown · pylint-gitlab · csvkit · njsscan