Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Join us at FabCon Atlanta from March 16 - 20, 2026, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM. Register now.

Reply
venukurs
New Member

Custom Visual code scan

Hi,

 

For one of our customer, we have imported following custom visuals from Microsoft AppSource.

 

  1. Tachometer
  2. Sunburst
  3. HTMLViewer

 

As per the customer security requirements, any third-party custom visuals should follow Code Scan procedure hence requesting you to provide your feedback on the following queries.

 

  1. How to extract the code for custom visuals (especially Tachometer, Sunburst and HTMLViewer) in order to scan code for internal security team acceptance.
  2. Is there any way to scan the custom visual code to verify vulnerable issues, if yes then can you please suggest the tool that can support to scan the custom visuals.
1 ACCEPTED SOLUTION
v-lionel-msft
Community Support
Community Support

Hi @venukurs ,

 

1. Modify the .pbix file to a .zip file.

What makes up a Power BI Desktop PBIX File 

v-lionel-msft_0-1597391536924.png

2. Find the JSON files of the custom visuals.

v-lionel-msft_1-1597391920286.png

3. Use code analysis tools to analyze code.

Maybe you can use Visual Studio.

Using the Code Analysis Tool 

 

Best regards,
Lionel Chen

If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

 

 

 

 

View solution in original post

3 REPLIES 3
v-lionel-msft
Community Support
Community Support

Hi @venukurs ,

 

1. Modify the .pbix file to a .zip file.

What makes up a Power BI Desktop PBIX File 

v-lionel-msft_0-1597391536924.png

2. Find the JSON files of the custom visuals.

v-lionel-msft_1-1597391920286.png

3. Use code analysis tools to analyze code.

Maybe you can use Visual Studio.

Using the Code Analysis Tool 

 

Best regards,
Lionel Chen

If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

 

 

 

 

lbendlin
Super User
Super User

.pbiviz files are ZIP archives containing JSON files with the visual code.  Unpack and scan.

Thank you for your response.

 

Can you plesae suggest a tool that support to scan json code. 

Helpful resources

Announcements
FabCon Global Hackathon Carousel

FabCon Global Hackathon

Join the Fabric FabCon Global Hackathon—running virtually through Nov 3. Open to all skill levels. $10,000 in prizes!

October Power BI Update Carousel

Power BI Monthly Update - October 2025

Check out the October 2025 Power BI update to learn about new features.

FabCon Atlanta 2026 carousel

FabCon Atlanta 2026

Join us at FabCon Atlanta, March 16-20, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM.