Initiative methodology

Comparable evidence requires explicit boundaries

VulnBench releases share principles for transparent measurement and provenance while preserving protocol-specific definitions.

  1. 01

    Define the protocol before reading the result

    Every release declares its task, repeated conditions, reference or ground-truth model, scorer, metrics, and limitations.

  2. 02

    Preserve uncertainty and recurrence

    Repeated-run spread remains visible wherever an aggregate could hide variable behavior.

  3. 03

    Keep values traceable

    Published charts identify release, dataset version, aggregation, units, sample size, and source assets.

  4. 04

    Block incompatible comparisons

    Metrics only compare across releases when their definitions and protocols explicitly declare compatibility.

  5. 05

    Publish corrections, never silent rewrites

    Corrected data receives a new patch version and a visible record of affected values and reasons.

Current protocol

Snyk VulnBench JS 1.0

Repeatability and Snyk-reference agreement

Read the benchmark design, matching rules, metric definitions, limitations, and source-reproduction notes for the current release.

Open JS 1.0 methodology