Warning: this repository is intentionally vulnerable. It is a scanner benchmark, not an application template, and must never be deployed.
A reproducible Go SAST accuracy corpus for Vybscan. Every planted vulnerability has a safe twin in the same realistic handler file.
vybscan-expect:<category>— must be reportedvybscan-safe:<category>— must not be reported
The initial corpus contains eight vulnerable cases and eight safe controls covering command and SQL injection, path traversal, SSRF, LDAP injection, insecure cookies, weak randomness, and TLS verification. Published results must pin this repository's commit and the scanner image digest.