godaudits 2.11.0
Measurement, evidence, and audit economics
This release makes accuracy claims harder to manufacture and audit scope harder to overstate.
Highlights
- Adds a versioned accuracy program targeting the highest-weight check in all 18 domains, with pre-authored ground truth, clean controls, mandatory model and harness attribution, and matched with-skill versus without-skill arms.
- Adds
godaudits import-toolfor SARIF, Semgrep, ast-grep, Gitleaks, and OSV-Scanner. Imported output remains provenance-bound evidence leads, never automatic findings. - Adds
screeninganddeep-tracecost tiers. Medium is the focused default; full audits must be selected explicitly. - Adds honest domain depth labels and escalation criteria. Security and build are deep-capable; remaining domains are screening-grade.
- Adds release cadence governance and a strict publication contract for recognizable OSS dogfood audits.
Accuracy status
The existing A-SEC-3 pilot remains five detected seeded defects, zero misses, and zero false positives on one clean control, with a Wilson lower bound of 0.5655. No matched control-versus-skill experiment has completed, none of the 18 expanded targets is fixture-ready, and no skill-lift value is claimed.
Validation
- 134 tests passed
- 8 benchmark cases passed
- 11 detector cases passed
- 5 evaluation suites passed
- Catalog, prompt, schema, ASCII, zero-dependency, and official validator gates passed
See CHANGELOG.md and ACCURACY.md for the complete scope and limitations.