Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

BenchmarkGo

Warning: this repository is intentionally vulnerable. It is a scanner benchmark, not an application template, and must never be deployed.

A reproducible Go SAST accuracy corpus for Vybscan. Every planted vulnerability has a safe twin in the same realistic handler file.

Ground truth

  • vybscan-expect:<category> — must be reported
  • vybscan-safe:<category> — must not be reported

The initial corpus contains eight vulnerable cases and eight safe controls covering command and SQL injection, path traversal, SSRF, LDAP injection, insecure cookies, weak randomness, and TLS verification. Published results must pin this repository's commit and the scanner image digest.

About

Reproducible intentionally vulnerable Go SAST accuracy benchmark

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages