Snapshot v0.7.1
v0.7.1 is a fresh measurement of the v0.7.0 population. The benchmark still contains 852 cases and the same score tiers and model profiles; no new case population was introduced. All 82 bound reports were freshly rerun, including the sixteen tool-native reports. The resulting freeze has 3,480 outcomes:
| Outcome | Count |
|---|---|
not-reached | 1,294 |
reached | 1,131 |
inconclusive | 300 |
unsupported | 755 |
The counts are outcome coverage across the retained reports. They do not pool scorecards into a leaderboard: benchmark-controlled and tool-native profiles remain separate populations, and incomplete outcomes are coverage rather than negative decisions.
Four outcome deltas
Section titled “Four outcome deltas”Against the published v0.7.0 manifest ref
(61300f47),
four cells changed:
- Bifrost’s Java
anonymous-implementationpair moved frominconclusivetoreachedon the positive andnot-reachedon the negative. - OpenTaint’s Java
callback-registrationpositive moved fromnot-reachedtoreached. - OpenTaint’s Java
map-iterationpositive moved fromnot-reachedtoreached.
No case was added, removed, or silently reclassified to make the totals agree. The case-evidence page links each retained artifact and its digest.
What the fresh evidence says
Section titled “What the fresh evidence says”The release audit records 82 fresh reports, 3,480 results, and verified membership and retained-hash references. The measurement audit is retained at the evidence commit; the release inventory is bound by the publication ref used by this snapshot.
The tool-native profile needs its own qualification. Bifrost’s 36 native
outcomes remain unsupported where the shipped selector/catalog evidence
does not bind the fixture surface. A separate positive control is retained as
inconclusive with partial_discovery; it is not used to turn those catalog-
grounded declines into successful activation claims. OpenTaint’s native
fixture results remain bounded by the source-selector barrier between the
environment-variable fixtures and its servlet/Spring source selectors, so
downstream semantics remain unresolved. Its functional product probe
demonstrates activation for a servlet control, while its timings are excluded
from latency qualification.
Timing qualification
Section titled “Timing qualification”This release has 2,725 cold timings. The remaining 755 outcomes are
unsupported and have no invented timing. Warm measurements retain Joern
batch sizes 1, 2, 4, 8, 16, twice, and Semgrep’s corrected eligible series
1, 2, 4, 8, 12, twice; the original Semgrep size-16 attempt failed during
pre-analysis and is retained as an unavailable attempt. Nine overhead groups
were measured three times each.
These are desktop characterization results with cache and background activity observed but uncontrolled. They do not support an uncontended-machine claim or timing parity between sandboxed and elevated execution. The latency page states the boundaries and exclusions beside the component tables.
- Scope:
release - Tracks:
taint - Score tiers:
calibrationcorelanguage-extensionmodeling - Model profiles:
benchmark-controlledtool-native - Exclusions: none
Bound evidence
Section titled “Bound evidence”Freeze ID (manifest SHA-256): f5416cded5891c92418d23ec5e2c638eb73f86695255cd5ea5f818b10f6c9e1d
Freeze manifest: reports/freeze.json
Continue to analyzers, languages, semantic templates, case evidence, profiles, or latency.