Repository navigation
bench: the OpenSSF CVE rig — codeaf beside DeepSource's security-review table - #1776
Closed
ZeroPoint95 wants to merge 3 commits into
Closed
ZeroPoint95 wants to merge 3 commits into
ZeroPoint95 wants to merge 3 commits into
Conversation
…ew table bench/openssf-cve reproduces the protocol DeepSource published in April 2026 for eight code-review tools on the OpenSSF CVE Benchmark: for each of 165 rows (85 JavaScript/TypeScript CVEs, vulnerable and fixed revisions), the tool reviews a pull request that adds the fix's files in full, and a blind Claude Opus 4.5 judge decides whether any finding names the CVE's exact instance. TP/FP/TN/FN, precision, recall, F1 and accuracy are counted their way; comparison/deepsource-2026-04.json recomputes their rows from their published JSONL and score.py prints ours above it. Drivers: gold (the oracle, F1 100 through the real judge), null (the floor), codeaf (`codeaf do` headless, pinned to one model in an isolated profile; the brief is the one line to swap when /security-review lands), sec-af (af call sec-af.audit, not yet exercised here) and replay (DeepSource's own processed findings, for calibrating the judge). calibrate.py measured 97.5% and 95.0% agreement with their verdicts on 40-row samples of Claude Code and Semgrep, every disagreement ours being stricter. README.md says what the number is honest to mean: 85 CVEs not 165, precision measures recognising the patch and nothing else, 2016-2021 CVEs every model has seen, a vendor-run comparison. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ge entry that fits on a line A checkout under work/ carried apn-go/apn.go and go build ./... found it, which is the same reason bench/prompt-diet writes outside any checkout. BENCH_ROOT (default ~/bench-openssf-cve) now holds both work/ and results/. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.