RE: [sarif] rule.helpLocation: string URI or fileLocation?

From
Michael Fanning <>
Date
2018-05-30T15:36:56+00:00
ID
Thread
RE: [sarif] rule.helpLocation: string URI or fileLocation?
In general, I don’t think we’re trying to accommodate tools that provide relative references to constituent tool files. The embedded SARIF rules metadata is intended to help with distributing some core content if there’s no network/internet
 access.

 

From:  <>
On Behalf Of Larry Golding (Comcast)

Sent: Tuesday, May 29, 2018 5:31 PM

To: 

Subject: [sarif] rule.helpLocation: string URI or fileLocation?

 

I added this comment to Issue #175 (URI vs 
fileLocation):

The only existing properties whose value is an absolute-URI-valued string are:

·        
tool.downloadUri. This is correct.

·        
versionControlDetails.uri. This is correct.

The properties whose values are fileLocation objects
 are:

·        
result.workItemLocation is a deterministic fileLocation object.
 It needs to change to an absolute-URI-valued string.

·        
rule.helpLocation:
 This one is tricky. If the help files are on the machine, they're non-deterministic and we should use fileLocation.
 If they're on the web, they're deterministic and we should use an absolute-URI-valued string. Ideas?

All the other fileLocation-valued
 properties are non-deterministic, and so are using fileLocationappropriately.

What do you think is the right answer for 
rule.helpLocation?

 

Thanks,

Larry