Skip to content

bench: the OpenSSF CVE rig — codeaf beside DeepSource's security-review table - #1776

Closed
ZeroPoint95 wants to merge 3 commits into
devfrom
claude/sec-af-benchmarks-e5e503
Closed

ZeroPoint95 wants to merge 3 commits into
devfrom
claude/sec-af-benchmarks-e5e503

Conversation

@ZeroPoint95

@ZeroPoint95 ZeroPoint95 commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

No description provided.

ZeroPoint95 and others added 3 commits October 5, 2026 14:42
…ew table

bench/openssf-cve reproduces the protocol DeepSource published in April
2026 for eight code-review tools on the OpenSSF CVE Benchmark: for each
of 165 rows (85 JavaScript/TypeScript CVEs, vulnerable and fixed
revisions), the tool reviews a pull request that adds the fix's files in
full, and a blind Claude Opus 4.5 judge decides whether any finding names
the CVE's exact instance. TP/FP/TN/FN, precision, recall, F1 and accuracy
are counted their way; comparison/deepsource-2026-04.json recomputes
their rows from their published JSONL and score.py prints ours above it.

Drivers: gold (the oracle, F1 100 through the real judge), null (the
floor), codeaf (`codeaf do` headless, pinned to one model in an isolated
profile; the brief is the one line to swap when /security-review lands),
sec-af (af call sec-af.audit, not yet exercised here) and replay
(DeepSource's own processed findings, for calibrating the judge).
calibrate.py measured 97.5% and 95.0% agreement with their verdicts on
40-row samples of Claude Code and Semgrep, every disagreement ours being
stricter. README.md says what the number is honest to mean: 85 CVEs not
165, precision measures recognising the patch and nothing else, 2016-2021
CVEs every model has seen, a vendor-run comparison.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ge entry that fits on a line

A checkout under work/ carried apn-go/apn.go and go build ./... found it,
which is the same reason bench/prompt-diet writes outside any checkout.
BENCH_ROOT (default ~/bench-openssf-cve) now holds both work/ and results/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@ZeroPoint95 ZeroPoint95 closed this Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant