Pixellint 0.36.0 catches an IAS installation placeholder and identifies more VAST pixel hosts.
Pixellint 0.36.0 follows up on a VAST tester report about tracking hosts that appeared in recent tags. The report exposed two different problems: an IAS installation placeholder could survive validation, and several observed hosts lacked a vendor directory entry. The release adds a precise IAS error and identifies six additional vendors. A companion Vastlint website update refreshes the embedded pixel engine and shows when an endpoint received only the shared core checks.
The scope matters when reading the result. Directory attribution gives a tracker a recognizable vendor name. A destination rulepack checks documented requirements for a particular request surface. This release adds seven exact host entries across six vendors, but it does not turn those entries into new destination packs. The existing inventory stays at 161 vendor packs. Broader contracts remain work for a later release when primary documentation supports them.
IAS installation instructions can leave a broken session identifier.
The IAS video guide includes URL templates with a placeholder for the ad-server impression identifier. That token tells an integrator where to supply the real session value. A copied template can leave the instruction in xsId while the event URL otherwise looks complete. The previous pack required a nonempty identifier, so the literal instruction satisfied that part of validation even though it did not identify an actual ad session.
The new error applies to the exact token [PLEASE_IMPLEMENT_UNIQUE_ADSERVER_IMPRESSION_ID_HERE] in xsId on the IAS video endpoint. URL parsing decodes percent escapes before the comparison, so a URL containing the percent-encoded placeholder receives the same finding. Both forms are covered by synthetic fixture artifacts and expected findings. The check stays attached to the field whose published purpose establishes why this token is invalid.
This is a bounded check. It does not require every valid identifier to look like a UUID, and it does not reject arbitrary opaque identifiers. The regression suite preserves supported template macros and ordinary session values. A request containing the same text in an unrelated field does not receive this particular error. Keeping those acceptance boundaries prevents a narrow installation fix from becoming an invented format requirement.
Observed tracker hosts now receive vendor labels.
The directory adds rm.aarki.net for Aarki, track.adwrap.io for AdWrap, 00px.net for Adxspace, us-east-1.event.prod.bidr.io for Beeswax, t.stredeo.com for Stredeo, and ads106.krushmedia.com plus ads133.krushmedia.com for Krush Media. These are exact observed hosts. The change does not use a broad wildcard to claim ownership of every similarly named host or every future regional collector.
The labels help a reviewer follow tracking URLs through a VAST response. An unfamiliar host no longer has to remain an unnamed row when the reported tag supplies attribution evidence. That is useful for inspecting a long impression or quartile list, but it does not prove which parameters the collector requires. The directory documentation records that distinction and keeps the evidence for host recognition separate from a vendor request contract.
The shared checks remain active for all of these URLs. For example, a Stredeo request with gdpr=NaN still receives the core privacy error. Recognizing Stredeo does not suppress that finding or promote the shared privacy rule into a Stredeo-specific requirement. The integration tests check both the directory result and continued core validation, so adding a vendor name cannot silently remove an existing error.
The Vastlint tester now explains pixel coverage.
The reported IAS video-event gap also pointed to deployment drift. The Vastlint tester had an older embedded Pixellint build even though newer package releases already included the video endpoint pack. Refreshing that browser engine gives the tester the current endpoint selection and the new placeholder check. A package release alone cannot update a separately committed website bundle, so both artifacts need to ship.
After the website update, each inspected tracking URL carries an explicit coverage state. A selected vendor endpoint pack supplies destination coverage. A URL checked only by the shared engine appears as core-only. An engine load or validation failure appears as unavailable. These states describe which checks actually ran for that endpoint, rather than inferring coverage from a vendor directory label.
The tester also avoids a clean success banner when tracking URLs have core-only or unavailable coverage. This does not change whether the VAST document passed its own XML and structural checks. It makes the pixel result more accurate: a reviewer can see the absence of pixel findings alongside the limits of the checks that produced it. URLs with an applicable vendor pack retain their normal success behavior.
Escaped XML receives specific paste guidance.
The tester report included a VAST tag pasted with escaped markup, including an AdSystem delimiter represented with an HTML entity. The companion website change recognizes escaped VAST markup and explains that the validator needs the raw XML document. The inspector also gives guidance when an XML document is pasted into the field that expects a remote tag URL.
The input stays available for correction. The website does not automatically decode the whole document, because valid XML text and tracking URL parameters can contain entity escapes that must be preserved. Parsing the document before applying the guidance prevents ordinary entity references and valid CDATA from being mistaken for a broken paste.
Regression coverage includes fully escaped documents, partially escaped tag delimiters and valid documents containing escaped text. Those cases exercise the boundary that matters to a user copying a tag between tools: identifying damaged outer markup while preserving legitimate content inside the XML. The fix changes the explanation and the inspector action, without claiming that every invalid XML document came from a particular editor.
Committed browser assets have a verifiable engine identity.
The website refresh now records the Pixellint version and SHA-256 hashes for its JavaScript glue and WASM binary. A prebuild check verifies those committed assets against the recorded metadata. The browser also checks the initialized engine version and uses the hashes in asset URLs, so a previously cached engine cannot keep hiding the refreshed validation behavior.
This closes the deployment gap that appeared in the tester report. Reviewers can verify the website's embedded engine separately from the npm package and Rust crates. The release keeps those identities aligned while retaining the normal package and website build checks. The metadata describes the committed build itself, rather than assuming the package version is enough to identify bytes served by another repository.
The regression cases keep the release scope measurable.
- The IAS suite rejects the literal and encoded installation placeholder while preserving ordinary IDs and supported template macros.
- Directory tests cover every newly listed host and retain the core gdpr=NaN error for Stredeo.
- Website cases exercise IAS findings, core-only coverage, engine failure, covered endpoint success and escaped XML guidance.
- Release checks rebuild the Rust and JavaScript packages and verify the embedded website assets before deployment.
Additional destination packs still need primary request evidence.
The tester report remains a useful backlog for Adtelligent, Smadex, ActiveMetering, RZR Global, Sovrn Lijit and rtactivate. Some entries provide only a shorthand host or a path shape. Neither is enough to specify the accepted request fields, conditional requirements, event values or failure boundaries for a complete pack. The recorded directory notes retain those gaps.
A subsequent pack can deepen these surfaces when public vendor documentation, a published producer or another primary contract supplies the missing evidence. Until then, the release identifies what it can support and leaves the coverage limit visible. A successful core check can help find malformed URLs and privacy values today, while a destination-specific result requires the endpoint contract to be established first.
Sources
Contract pages
The dated argument is above. These pages are the field lists.