Pixellint 0.37.0 flags Segment setup tokens and accepts PostHog redaction.
Pixellint 0.37.0 follows up on tester findings from pasted event payloads and tracking URLs extracted from VAST documents. A Segment purchase event passed with an unfilled write-key token. PostHog context properties needed more precise treatment of deliberate null values. Several observed tracking hosts still lacked attribution. The release addresses those gaps and makes the scope of a clean playground result easier to inspect.
The changes have different effects on findings. Recognized Segment setup tokens produce warnings. Documented PostHog null values stop producing invalid-value errors. Newly attributed hosts remain covered by the shared core checks until a public endpoint contract supports a destination pack. Existing AppsFlyer missing-value and Adjust IP checks are preserved, with additional controls around the cases in the report.
Segment setup tokens now produce an actionable warning.
Segment identifies an event source using its configured write key. The HTTP API accepts that key in the JSON body or as the username in Basic authentication. Published request examples use YOUR_WRITE_KEY where the integrator must supply the configured value. The tester report used the compact YOUR_WRITEKEY variant, which also appears in a Pixellint documentation example. Both literals are recognizable setup tokens.
The new rules match only those two exact uppercase strings. A root writeKey is checked on a single event and on a batch envelope. For a complete HTTP capture, the decoded Basic username is checked as well. A body credential produces one warning from the body rule; it is not counted again merely because the artifact includes HTTP metadata.
The warning carries heuristic provenance. Segment does not publish a general key-length restriction that justifies rejecting every unusual string, and local validation cannot authenticate a key. Short opaque keys, longer keys containing the token as a substring, and the same text in unrelated properties stay accepted. The regression controls also preserve endpoint routing, so another collector does not inherit Segment credential checks from a similarly shaped body.
This synthetic purchase event leaves the setup token visible.
The writeKey receives a warning. Replace it with the configured source key before sending a real event. The example contains no customer data.
{
"writeKey": "YOUR_WRITEKEY",
"type": "track",
"event": "Order Completed",
"userId": "synthetic-user",
"properties": { "revenue": 129.99, "currency": "USD" }
}
PostHog can accept a deliberately redacted context value.
PostHog documents a before_send example that assigns null to properties.$current_url before capture. Requiring every supplied value to be a string rejected that supported redaction. Pixellint now accepts a string or null for this optional property. Omitting it is also allowed. A populated string retains its existing validation, and an empty string keeps the existing empty-value finding.
The properties.$ip contract also accepts an optional null value, consistent with the reviewed event-properties implementation. A populated IP value still passes through the IP format check. A SHA-256 digest in that field remains an error because a digest cannot serve as the raw address. Accepting null does not turn a malformed populated IP into a valid address or suppress another invalid field in the same event.
The reserved IP check stays attached to the IP property. Hash-shaped distinct IDs and custom property values remain allowed. A local artifact cannot establish how an identifier was created or whether a custom hash represents personal data. It also cannot certify that IP collection is disabled: setting $ip to null does not prove the project uses the Discard client IP data setting. Verify that setting separately when controlling server-side IP handling.
AppsFlyer and Adjust findings retain their existing contract checks.
The AppsFlyer af_purchase finding was already correct for the reviewed S2S surface. eventValue is required even when the event carries no value. Its documented no-value form uses a present string, so a missing property and an empty string need different outcomes. The regression cases preserve the missing-field error and the accepted empty-string form. Filling in an unrelated revenue property cannot substitute for the required eventValue field.
The Adjust sample also contained a real format problem. The S2S event documentation accepts IPv4 in ip_address. A SHA-256 hexadecimal string fails that contract, and an IPv6 address remains outside this documented parameter format. Added controls retain acceptance of an ordinary IPv4 address while preserving the digest finding and the existing invalid-address result.
These cases show why raw finding totals need interpretation. One hashed Adjust field can produce a format error and a more specific plaintext-field error. That is useful diagnostic detail, but it does not establish two independently broken fields. Release comparisons therefore inspect finding codes, severities and affected artifacts alongside totals, so a change in error count can be traced to its cause.
Twelve additional observed hosts receive vendor attribution.
The directory grows from 129 to 132 vendor entries by adding Adtelligent, Smadex and Sovrn. The exact Adtelligent hosts are ads55.adtelligent.com, ads228.adtelligent.com and ads283.adtelligent.com. The Smadex additions are br-trk.smadex.com, cr-err.smadex.com, ec-ed.smadex.com, geo-tracker.smadex.com, pixel-ed.smadex.com and va-trk.smadex.com. Sovrn gains n.adv.lijit.com. Existing entries gain ads161.krushmedia.com for Krush Media and segment.prod.bidr.io for Beeswax.
Observed artifacts establish which hosts occurred in the corpus. Primary sources corroborate vendor attribution: Adtelligent publishes examples on its infrastructure, Smadex identifies its platform on smadex.com, and Sovrn explicitly identifies lijit.com as its operational ad-serving domain. The directory documentation records the evidence and the exact additions. It does not expand these observations into a wildcard covering every possible sibling host.
All twelve additions remain directory-only. An incoming ad-request guide does not establish the required fields of an impression tracker, and an MMP integration index does not establish a video-event enumeration. The release does not invent required dimensions, identifiers or quartile names for those endpoints. Shared URL, macro and privacy checks still run, including the existing error for a populated gdpr=NaN value.
The playground makes core-only coverage visible.
A recognized vendor name helps reviewers identify a request, but the name alone does not show whether an endpoint pack ran. The playground now identifies core-only coverage when an artifact receives the shared checks without an applicable vendor destination pack. The result can still contain useful findings. It also explains why an unfamiliar tracking route may have no vendor-specific errors.
This distinction matters for tracking URLs lifted from a VAST response. Each impression or quartile URL is a separate artifact with its own host and endpoint. A single tag can contain several vendors, and coverage for one of them does not transfer to the others. Review the coverage attached to each URL before treating an absence of findings as destination-contract validation.
The new directory rows therefore improve attribution without promising deeper collector validation than the evidence supports. RZR Global, rtactivate and ActiveMetering remain deferred where exact-host attribution was not independently established. Talpa's private mock server does not establish a public destination contract. Those limits remain part of the backlog instead of becoming guessed requirements in the released rules.
Corpus comparisons separate detection changes from attribution changes.
The frozen comparison contains 8,798 stored Pixellint artifacts, including 248 rows beyond the earlier 8,550-row snapshot. Its latest stored artifact is dated 2026-10-10T01:56Z, which is October 9 in Pacific time. Both versions replayed the same artifacts at their original capture clocks. This keeps later submissions and time-sensitive checks from being mistaken for a change in validation behavior.
Error findings remained at 317, and error-bearing artifacts remained at 247. Warning findings increased from 741 to 742 because one Segment artifact contained an exact recognized placeholder. There were no engine exceptions and no finding removals. This snapshot therefore shows one additional warning, without an error-detection gain. It does not supply remote acceptance results or independent labels for every submitted artifact.
Fifty-four samples gained vendor attribution: 24 Adtelligent, 20 Smadex, two Sovrn, six Krush Media and two Beeswax. In total, 56 full reports changed. Fifty-five changed through findings or selection; one PostHog report changed its diagnostic text or source reference while retaining the same error code, severity and field. A changed vendor label is recorded separately from a changed error or warning.
The accepted PostHog null cases were absent from this frozen corpus, so their correction is established by authored source fixtures rather than an observed reduction in stored errors. Synthetic controls also exercise Segment Basic decoding, batch placement and negative boundaries, while preserving AppsFlyer and Adjust findings that were already correct. Corpus replay and these independent cases provide different evidence about the release, and both remain necessary.
The reviewed changes can be checked independently.
- Use the source fixtures to compare exact placeholder matches with short opaque keys, substring matches, lowercase variants and unrelated fields.
- Check PostHog null and missing context fields alongside a populated raw IP, a hashed IP and hash-shaped identifiers or custom properties.
- Inspect directory attribution and the core-only coverage message together when reviewing newly recognized tracking hosts.
- Keep the released engine version pinned when reproducing a finding, and preserve the artifact kind and reference clock used for the comparison.
Runtime delivery still needs separate evidence.
Pixellint checks the artifact it receives against the available rules. It cannot determine whether a Segment key is active, whether a destination accepted an event, or whether a browser actually fired every required tracker. A URL that passes a destination pack may still fail at runtime because of account configuration, network behavior or a missing trigger. Capture and destination-side evidence are needed to resolve those questions.
The next deepening work starts with public contracts for the remaining observed collectors. A useful pack needs source evidence for accepted fields, conditional requirements and invalid boundaries, plus examples that should remain accepted. Until those contracts are available, the release keeps host attribution useful, shared checks active and endpoint coverage explicit. The examples and fixtures in this post use synthetic values throughout.
Sources
- Pixellint 0.37.0 release and downloads
- Segment source-key authentication and example requests
- Finding a configured Segment source write key
- PostHog property redaction and IP data controls
- Reviewed PostHog event properties implementation
- AppsFlyer S2S eventValue requirements
- Adjust S2S device IP requirements
- Adtelligent infrastructure in published request and response examples
- Smadex platform attribution
- Sovrn ownership of the Lijit ad-serving domain
- Exact observed hosts and documented endpoint coverage limits
- Segment placeholder acceptance boundaries and regression tests
- Frozen D1 aggregate comparison of 0.36.0 and 0.37.0
Contract pages
The dated argument is above. These pages are the field lists.