Skip to content

Commit 7c1b565

Browse files
committed
fix: Remove trailing whitespaces
1 parent e0dd40f commit 7c1b565

1 file changed

Lines changed: 4 additions & 4 deletions

File tree

‎README.md‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -36,16 +36,16 @@ To evaluate the quality and effectiveness of our security analysis, we benchmark
3636

3737
Our evaluation process is designed to test the extension's ability to identify vulnerabilities in code changes.
3838

39-
1. **Dataset**: We used the [OpenSSF CVE Benchmark](https://github.com/ossf-cve-benchmark/ossf-cve-benchmark), a dataset containing GitHub repositories of real applications in TypeScript / JavaScript. For each vulnerability, the dataset provides the commit containing the vulnerable code (`prePatch`) and the commit where the vulnerability was fixed (`postPatch`).
40-
2. **Analysis Target**: For each CVE, we set up the repository and computed the diff between the fixed commit and the vulnerable commit.
41-
3. **Report Generation**: We ran the /security:analyze command on this diff to generate a security report.
39+
1. **Dataset**: We used the [OpenSSF CVE Benchmark](https://github.com/ossf-cve-benchmark/ossf-cve-benchmark), a dataset containing GitHub repositories of real applications in TypeScript / JavaScript. For each vulnerability, the dataset provides the commit containing the vulnerable code (`prePatch`) and the commit where the vulnerability was fixed (`postPatch`).
40+
2. **Analysis Target**: For each CVE, we set up the repository and computed the diff between the fixed commit and the vulnerable commit.
41+
3. **Report Generation**: We ran the /security:analyze command on this diff to generate a security report.
4242
4. **Validation**: Since the dataset has a small number of repositories, we manually reviewed all the generated security reports and compared with the ground truth to calculate the final precision and recall numbers.
4343

4444
### Results
4545

4646
Our evaluation on this dataset yielded a precision of **90%** and a recall of **93%**.
4747

48-
* **Precision (90%)** measures the accuracy of our detections. Of all the potential vulnerabilities the extension identified, 90% were actual security risks.
48+
* **Precision (90%)** measures the accuracy of our detections. Of all the potential vulnerabilities the extension identified, 90% were actual security risks.
4949
* **Recall (93%)** measures the completeness of our coverage. The extension successfully identified 93% of all the known vulnerabilities present in the dataset.
5050

5151
### Caveat

0 commit comments

Comments
 (0)