Skip to content

Snapshot v0.5.0

Frozen snapshot v0.5.0

  • Freeze ID: 43a34341ca3f… (SHA-256 of reports/freeze.json)
  • Benchmark revision 7d688c61e840, release v0.5.0, claim scope release
  • Fixture revision 9df209ed3d77…

The fifth immutable DataFlowBench snapshot. It is two things at once: the Bifrost v0.10.7 fix cycle, in which the previous freeze’s 22 runner-error results fall to zero and Bifrost’s decisive-correct count on the thirteen kernels roughly doubles, and the first freeze to publish the modeling tier and the tool-native tier alongside the benchmark-controlled kernels. Four analyzers are bound at one fixture revision: Bifrost v0.10.7, CodeQL 2.26.3, Joern 4.0.610, and Semgrep CE 1.174.0.

This snapshot therefore carries two model profiles. The benchmark-controlled profile covers the thirteen language kernels (whose population is byte-identical to v0.4.0’s) and the twelve-template modeling matrix, where DataFlowBench configures each tool to the benchmark’s own source/sink contract. The tool-native profile covers the six-template probe set, where each tool decides with nothing but what it ships. The two profiles are never pooled, never compared number-to-number, and never share a denominator. Each scorecard on these pages is labelled with the profile it was produced under.

Coverage differs by analyzer as well as by language and by tier: a kernel or a modeling category with no report for an analyzer means no extractor, no frontend, no adapter, or a category the tool’s own model surface cannot express. That is coverage, not a score. inconclusive and unsupported are capability coverage and are never converted into clean negatives — a row reading 0 / 12 with twelve unsupported results is a declared decline, not twelve wrong answers.

  • Scope: release
  • Tracks: taint
  • Score tiers: calibration core language-extension modeling
  • Model profiles: benchmark-controlled tool-native
  • Exclusions: none

Freeze manifest: reports/freeze.json — every case, fixture, normalized report, and raw-evidence file is digest-bound; cargo run -- validate-freeze reports/freeze.json re-verifies all of it. Each report’s build identity is witnessed from the binary actually invoked, including on runs that decide nothing.

The full release note, with the derived tables and the honest negatives — four new Bifrost false positives filed as bifrost-dev#2731, and the unreconciled Java direct-propagation instability — is docs/releases/v0.5.0.md.

Continue to analyzers, languages, semantic templates, or case evidence.