by mbbutler 4 days ago

It would be helpful to add in some cases that do not contain any vulnerabilities to assess false-positive rate as well.

mufeedvh 4 days ago | [-0 more]

This is a good idea.

Will incorporate false-positive rates into the rubric from the next run onwards.

At winfunc, we spent a lot of research time taming these models to eradicate false-positive rates (it's high!) so this does feel important enough to be documented. Thanks!

cortesoft 4 days ago | [-0 more]

Any code that is certain that it doesn't have any vulnerabilities is going to be pretty trivial to verify.