JS 1.0 · Data

Versioned evidence with traceable provenance

The release data is shipped as immutable static assets. Every published value remains tied to the JS 1.0 protocol, source revision, and dataset version.

Downloads

Published release assets

JSONL

Benchmark run results

Published run-level results for all 300 benchmark scans, including model and deterministic reference runs.

Download
JSON

Chart data manifest

Published aggregate values and chart definitions used by the upstream research visualizations.

Download
GitHub

Complete source snapshot

Fixture projects, reference findings, generated visualizations, article notes, and Apache 2.0 license.

Download

Provenance

Exact upstream source

The website vendors the complete contents ofsnyk-labs/snyk-vulnbench-js-1.0at the published commit below. Upstream files are verified against their Git blob hashes during the website test suite.

Dataset version
1.0.0
Upstream commit
7c944ea438a31ea4cbd6803f1bb9560d01f932e5
Upstream tree
e1490c821be5be869b91e482eb037e3f2672f432
Commit timestamp
2026-06-09T06:39:46Z

Data dictionary

Core concepts

Run
One configuration executing one benchmark task once.
Reference finding
A deterministic Snyk Code finding declared for a fixture.
Reference match
A model report credited for the same vulnerability type under the JS 1.0 scorer.
Unmatched report
A model report outside the reference match; not an automatic false positive.
Normalized signature
The documented grouping identity used to measure recurrence across repeated runs.

Corrections

No silent rewrites

If published data changes, VulnBench will issue a new dataset patch version, preserve the prior snapshot, document affected values, and keep stable release URLs valid.