Skip to content

godaudits 2.11.0

Choose a tag to compare

@hannsxpeter hannsxpeter released this 23 Jul 04:05
69999b2

Measurement, evidence, and audit economics

This release makes accuracy claims harder to manufacture and audit scope harder to overstate.

Highlights

  • Adds a versioned accuracy program targeting the highest-weight check in all 18 domains, with pre-authored ground truth, clean controls, mandatory model and harness attribution, and matched with-skill versus without-skill arms.
  • Adds godaudits import-tool for SARIF, Semgrep, ast-grep, Gitleaks, and OSV-Scanner. Imported output remains provenance-bound evidence leads, never automatic findings.
  • Adds screening and deep-trace cost tiers. Medium is the focused default; full audits must be selected explicitly.
  • Adds honest domain depth labels and escalation criteria. Security and build are deep-capable; remaining domains are screening-grade.
  • Adds release cadence governance and a strict publication contract for recognizable OSS dogfood audits.

Accuracy status

The existing A-SEC-3 pilot remains five detected seeded defects, zero misses, and zero false positives on one clean control, with a Wilson lower bound of 0.5655. No matched control-versus-skill experiment has completed, none of the 18 expanded targets is fixture-ready, and no skill-lift value is claimed.

Validation

  • 134 tests passed
  • 8 benchmark cases passed
  • 11 detector cases passed
  • 5 evaluation suites passed
  • Catalog, prompt, schema, ASCII, zero-dependency, and official validator gates passed

See CHANGELOG.md and ACCURACY.md for the complete scope and limitations.