Skip to content

Snapshot v0.7.1

Frozen snapshot v0.7.1 current

  • Freeze ID: f5416cded589… (SHA-256 of reports/freeze.json)
  • Benchmark revision 2007f15d687e, release v0.7.1, claim scope release
  • Fixture revision 9df209ed3d77…

v0.7.1 is a fresh measurement of the v0.7.0 population. The benchmark still contains 852 cases and the same score tiers and model profiles; no new case population was introduced. All 82 bound reports were freshly rerun, including the sixteen tool-native reports. The resulting freeze has 3,480 outcomes:

OutcomeCount
not-reached1,294
reached1,131
inconclusive300
unsupported755

The counts are outcome coverage across the retained reports. They do not pool scorecards into a leaderboard: benchmark-controlled and tool-native profiles remain separate populations, and incomplete outcomes are coverage rather than negative decisions.

Against the published v0.7.0 manifest ref (61300f47), four cells changed:

  • Bifrost’s Java anonymous-implementation pair moved from inconclusive to reached on the positive and not-reached on the negative.
  • OpenTaint’s Java callback-registration positive moved from not-reached to reached.
  • OpenTaint’s Java map-iteration positive moved from not-reached to reached.

No case was added, removed, or silently reclassified to make the totals agree. The case-evidence page links each retained artifact and its digest.

The release audit records 82 fresh reports, 3,480 results, and verified membership and retained-hash references. The measurement audit is retained at the evidence commit; the release inventory is bound by the publication ref used by this snapshot.

The tool-native profile needs its own qualification. Bifrost’s 36 native outcomes remain unsupported where the shipped selector/catalog evidence does not bind the fixture surface. A separate positive control is retained as inconclusive with partial_discovery; it is not used to turn those catalog- grounded declines into successful activation claims. OpenTaint’s native fixture results remain bounded by the source-selector barrier between the environment-variable fixtures and its servlet/Spring source selectors, so downstream semantics remain unresolved. Its functional product probe demonstrates activation for a servlet control, while its timings are excluded from latency qualification.

This release has 2,725 cold timings. The remaining 755 outcomes are unsupported and have no invented timing. Warm measurements retain Joern batch sizes 1, 2, 4, 8, 16, twice, and Semgrep’s corrected eligible series 1, 2, 4, 8, 12, twice; the original Semgrep size-16 attempt failed during pre-analysis and is retained as an unavailable attempt. Nine overhead groups were measured three times each.

These are desktop characterization results with cache and background activity observed but uncontrolled. They do not support an uncontended-machine claim or timing parity between sandboxed and elevated execution. The latency page states the boundaries and exclusions beside the component tables.

  • Scope: release
  • Tracks: taint
  • Score tiers: calibration core language-extension modeling
  • Model profiles: benchmark-controlled tool-native
  • Exclusions: none

Freeze ID (manifest SHA-256): f5416cded5891c92418d23ec5e2c638eb73f86695255cd5ea5f818b10f6c9e1d

Freeze manifest: reports/freeze.json

Continue to analyzers, languages, semantic templates, case evidence, profiles, or latency.