Warning: this repository is intentionally vulnerable. It is a scanner benchmark, not an application template, and must never be deployed.
A reproducible JavaScript/TypeScript SAST accuracy corpus for Vybscan. Every planted vulnerability has a safe twin in the same realistic handler file.
vybscan-expect:<category>— must be reported (true-positive/false-negative ruler)vybscan-safe:<category>— must not be reported (false-positive/true-negative ruler)
Scoring matches findings by file and line with a two-line tolerance. The initial corpus covers SQL injection, code injection, path traversal, SSRF, open redirect, insecure cookies, and weak crypto. The benchmark commit SHA, scanner digest, and score artifact must be recorded with every published result.