v0.1.1 — Backtest corpus hotfix
Backtest hotfix. The bundled corpus was unusable against the live Security-Datasets repo; backtest/audit silently reported every rule as untested. Upgrade recommended.
pip install -U detect-forgeFixed
- JSON Lines datasets —
backtestnow parses the real Security-Datasets on-disk format (one event per line). The loader previously assumed a JSON array and failed every real dataset with "Extra data", reporting all rulesuntested. - Pruned + hashed Mordor index — 14 of 16 bundled dataset URLs had 404'd upstream; the index now lists only the datasets that are live, with real SHA256 hashes, so integrity is verified and runs no longer emit 404 warnings.
Verified end-to-end against live Security-Datasets: a rule now downloads → SHA-verifies → JSONL-parses → matches → fires.
Full diff: v0.1.0...v0.1.1