Pixellint 0.38.0 adds documented tracker checks and deepens IAS session validation.
The release checks the documented endpoint.
Pixellint 0.38.0 adds three packs and deepens one existing pack after a review of tracking URLs lifted from VAST tags. The new scopes are Google’s Campaign Manager PCS view endpoint, the root tracker emitted by ADCTV’s public tag script, and the counting pixel documented by 00px. IAS video events gain an advisory for three exact timestamp or cachebuster macro values used as session IDs. The package now includes 164 vendor packs across 87 vendor identities.
The review started with a practical concern: a tracker can pass generic URL checks while its destination contract has never been evaluated. A vendor name in the directory helps identify that URL, but it supplies no missing field specification. The playground keeps that distinction visible through its Core checks only verdict when no destination pack runs. This release adds checks where primary sources support them and records the remaining route gaps.
The corpus comparison covers all 8,800 stored samples in a fresh frozen D1 export. Both versions receive identical artifacts, stored kinds and reference clocks. The new version adds 24 warning findings and preserves every existing error finding. That result measures the linter’s behavior on the stored corpus. It does not establish which requests a remote collector accepted, attributed or billed.
Google PCS gains a narrow template check.
Campaign Manager’s official pre-fetch troubleshooting page includes two blockedAdTracking examples on googleads4.g.doubleclick.net/pcs/view. Both carry xai, sai and sig. The new vendor/google-cm360-pcs-view pack treats those three opaque fields as recommended nonempty template inputs. Missing or empty values produce warnings with official-template provenance. Their contents do not receive an invented encoding rule, character alphabet, length cap or signature validator.
All 181 stored samples that select the new Google pack retain their previous errors and warnings. They carry the checked template fields. Their directory-only coverage note is removed because a destination pack now runs. Fourteen authored controls cover missing fields, valid opaque values and neighboring routes. An empty or omitted adurl remains accepted because the reviewed examples do not establish a universal requirement for it.
The scope is the exact googleads4 host and /pcs/view path. A different Google host does not inherit this template solely because its URL contains pcs. In particular, pagead2.googlesyndication.com/pcs/view and /pcs/click remain outside this new pack. Existing Google ActiveView and IMA telemetry packs still handle their documented routes. Signed token validity and collector acceptance require external context that these local checks cannot provide.
ADCTV’s producer supplies an event advisory.
ADCTV’s official studio application points to its public generated tag script. That script sets the tracker base to track.adctv.com and appends event to the root endpoint in both its sendBeacon and POST fetch branches. This gives the new vendor/adctv-tracker pack a concrete route and producer field to inspect. An absent or empty event produces a warning. Extra fields and custom event names remain open.
The producer source does not publish a complete server acceptance schema. The pack therefore does not require every metadata field that the script happens to emit, constrain events to an observed quartile list, or infer required privacy parameters. Thirteen authored controls exercise the event advisory and scope boundaries. All 24 matching stored ADCTV samples already contain event, so none gains an event finding in the replay.
The AV macro question remains contextual. Aniview publishes names such as AV_TIMESTAMP and AV_GDPR, but a tracker hostname cannot establish that the player or ad server will expand them. The existing non-IAB macro warning remains available. A passing ADCTV template check means that the local source-scoped advisory found no problem. It does not certify macro expansion or a completed measurement call.
The 00px counting pixel excludes the reported video routes.
The 00px guide publishes a counting-pixel template at /pixel/{opaque-token}/e.gif and shows an installation stub in the optional t query field. The new vendor/adxspace-pixel pack warns when the token slot is empty or when t still contains the exact INSERIR+CACHEBUSTER stub. It accepts opaque token spellings and does not require a numeric cachebuster, a mandatory t value, or a guessed token encoding.
This is an adjacent documented route. The reported 36 Adxspace video trackers use /tracking/ and /vast/pixel/, and those routes remain outside the pack. None of the stored samples selects the new counting-pixel pack. Twenty-one authored controls cover the published route, stub spellings, permitted cachebuster variations and exclusions. Adding a pack for the same vendor does not fill a contract gap on a different endpoint.
To select that variable path safely, manifests now support match.path_patterns. Expressions match the complete path and require an explicit host or host suffix. They cannot combine with any_host. The separate path_pattern property still extracts named fields after selection. Existing exact paths and prefixes retain their behavior. Scope tests include trailing segments, neighboring hosts, HTTP captures and query gates.
IAS session IDs should remain stable across events.
The IAS /vevent/ family was already covered before this release. Its installation placeholder check continues to reject the exact PLEASE_IMPLEMENT_UNIQUE_ADSERVER_IMPRESSION_ID_HERE stub. A report that IAS only handles /v2 routes describes an older coverage state. The current video pack also validates published video-event paths and the external session ID field.
IAS’s video guide discourages timestamp and cachebuster macros as session identifiers. The new advisory targets only xsId values equal to [CACHEBUSTING], [TIMESTAMP] or ${CACHEBUSTER}. Those changing values can undermine the intended shared session identity. The rule produces a warning rather than asserting that every collector rejects the URL. It adds 24 warnings to the frozen stored corpus.
Ten new controls preserve ordinary numeric IDs, genuine session macros and opaque identifiers containing the word timestamp. A nested URL or a timestamp token in another field does not trigger this rule. Equality and uniqueness across an entire ad session still need session history. A single URL cannot establish that the same ID was reused on every event or that no other impression reused it.
The replay preserves errors and distinguishes added checks.
The fresh export contains 8,639 VAST tracking artifacts, 112 URL artifacts and 49 JSON artifacts. Its 8,798 previously exported rows retain their artifact, kind, creation time and hash; two newly stored rows extend the snapshot. Capture clocks from the earlier replay are preserved, and new rows use their stored creation time. Both engines use the same frozen inputs and default selection policy.
Error findings stay at 323 in both versions, and the same 249 samples contain errors. Warning findings rise from 745 to 769. Complete reports change on 268 samples: 208 change their finding multiset, while 60 change only report selection or metadata. The removal of 181 directory-only info findings reflects Google PCS pack selection. Three new directory-only info findings accompany DISQO attribution.
The 58 new authored controls all meet their static expectations in 0.38.0. Nineteen already met those expectations in 0.37.0, so 39 outcomes improve. These controls include positive requests and deliberate exclusions, not just malformed inputs. They are independent source and dispatch expectations, separate from stored-corpus counts. No remote vendor acceptance labels exist in this evaluation.
Directory attribution leaves destination gaps visible.
Roku and Edmunds list track.activemetering.com under DISQO. The directory now uses that attribution for the exact host. No DISQO tracker pack is introduced because the reviewed sources establish ownership and integration listings rather than a complete collector field contract. Generic privacy validation still runs, and lookalike or neighboring hosts do not inherit the new attribution.
Adtelligent, Beeswax, Aarki, Krush Media, Smadex, AdWrap, Sovrn and Stredeo retain their existing directory recognition and generic checks on the reported tracking routes. Primary-source reviews did not establish those first-party wire contracts. Documentation about ad requests, cookie syncs, downstream log records or partner MMP integrations cannot supply required fields for a different tracking endpoint. RZR Global and rtactivate still lack sufficient exact-host primary evidence for new pack claims.
Talpa’s development mock host remains a custom endpoint rather than a public destination pack. These limits are recorded beside the primary sources reviewed for this release. They give future work a specific target: obtain a published tracker contract or an official producer for the reported route, then add bounded checks and controls. Silent generic validation is not reported as a vendor specification pass.
The package and both browser integrations use the same source.
The native workspace passes 549 tests, and Clippy runs with warnings denied. The rebuilt npm distribution passes its CommonJS and ES module smoke checks, including the new tracker packs and retained privacy errors. Native and WASM comparisons use complete reports for every changed stored sample and all 58 new authored controls, rather than comparing only total error counts.
Pixellint 0.38.0 ships through the existing crates, npm, CLI release and MCP registry channels. The pixellint.org playground and Vastlint’s embedded pixel validator receive the same reviewed browser build. Generated pack pages explain the narrow match scopes, source levels and local limits. The aggregate replay report publishes counts and hashes without customer URLs, identifiers, IPs or payload values.
Use the refreshed pack pages to decide whether a particular endpoint receives destination checks. For an uncovered route, inspect the generic findings and the coverage note separately. For a covered route, review what the source-backed checks actually claim. Neither the new pack count nor an empty finding list establishes collector acceptance, complete vendor coverage or successful ad delivery.
Sources
- Pixellint 0.38.0 release
- Aggregate old and new corpus comparison
- Google Campaign Manager pre-fetch examples
- ADCTV public tag producer
- 00px counting-pixel installation guide
- IAS video session identifier guidance
- Roku DISQO integration listing
- Deferred programmatic tracker contracts
- Source reviews and explicit completeness limits
Contract pages
The dated argument is above. These pages are the field lists.