All notable changes to VulnGym are documented here. The format follows Keep a Changelog and this project adheres to Semantic Versioning.
Data refresh — further expansion of human-audited coverage.
- Human-audited entries grew from 350 → 393 / 408 (96.3 %), covering 178 / 184 advisories (96.7 %).
- Updated human-audit status flags only; row counts, schema,
desccoverage, and vulnerability-type distribution are unchanged.
- reports: 184 (unchanged)
- entries: 408 (unchanged)
- human-audited entries (verify = 1): 393 (was 350)
- human-audited advisories (≥ 1 verified entry): 178 (was 163)
Data refresh — further expansion of human-audited coverage and broad annotation refinements.
- Human-audited entries grew from 274 → 350 / 408 (85.8 %), covering 163 / 184 advisories (88.6 %).
descfield on theentry_point,critical_operation, andtracenodes of 400 entries — a natural-language explanation of each node's role in the vulnerability chain.
- reports: 184 (unchanged)
- entries: 408 (unchanged)
- human-audited entries (verify = 1): 350 (was 274)
- human-audited advisories (≥ 1 verified entry): 163 (was 137)
Data refresh — significant expansion of human-audited coverage and annotation refinements.
- Human-audited entries grew from 113 → 274 / 408 (67.2 %), covering 137 / 184 advisories (74.5 %).
- Refined
entry_point,critical_operation, andtraceannotations on 80 entries for improved accuracy.
- reports: 184 (unchanged)
- entries: 408 (unchanged)
- human-audited entries (verify = 1): 274 (was 113)
- human-audited advisories (≥ 1 verified entry): 137 (was 61)
Data refresh — adds a human-audit flag and additional human-verified entries.
verifyfield on every row indata/entries.jsonl(int,0or1):1marks entries that have been reviewed and confirmed by a human annotator (high-confidence ground truth);0marks automatically annotated entries that have not yet been human-confirmed.- 113 / 408 entries (≈ 27.7 %) are now flagged
verify = 1, covering 61 / 184 advisories (≈ 33.2 %; 50 advisories have all of their entries verified, 11 are partially verified).
- Refined values of selected
entry_point,critical_operation,trace, and other annotation fields indata/entries.jsonl. Row counts and thereport_id↔entry_idjoin structure are unchanged. SCHEMA.mdnow documentsverify;human_confirmedis removed from the "intentionally omitted internal fields" invariant since the audit status is exposed publicly viaverify.
- reports: 184 (unchanged)
- entries: 408 (unchanged)
- human-audited entries (verify = 1): 113
- human-audited advisories (≥ 1 verified entry): 61
Initial open-source release.
data/reports.jsonl— 184 GitHub Advisories (report-level aggregates).data/entries.jsonl— 408 per-entry-point records withentry_point/critical_operation/traceannotations.SCHEMA.md— full field reference and invariants.examples/load_dataset.py— stdlib / pandas / HuggingFacedatasetsloaders.examples/evaluate.py— coverage / recall evaluator.examples/example_result.jsonl— illustrative tool-findings submission.- CC-BY-4.0 license.
- reports: 184
- entries: 408
- projects: 38
- repositories: 23