Skip to content

feat: FP reduction, benchmarks, example, mooncakes publishing - #9

Merged
I3eg1nner merged 3 commits into
mainfrom
fp-reduction-and-benchmarks
Sep 30, 2026
Merged

I3eg1nner merged 3 commits into
mainfrom
fp-reduction-and-benchmarks

Conversation

@I3eg1nner

Copy link
Copy Markdown
Owner

Summary

  • CWE-22 FP reduction: Add filtering for API routes, git refs, shell scripts, internal paths, custom protocols, and string comparison methods. Popular-project findings reduced 53→16 (~70%, FP rate ~19%)
  • CWE-113 safe variable tracking: Track let-bound sanitized/constant values and all-constant match branches to suppress false positives
  • 23 benchmark cases across 6 CWE rules with automated regression runner (scripts/detection_benchmark.py)
  • Runnable example (examples/vulnerable_server.mbt) demonstrating CWE-22 and CWE-113 detection
  • .moonignore for mooncakes publishing (package size 40MB→6.3MB, dry-run 202 accepted)
  • audit_hint disposition for CWE-248/676/704 rules in JSON and text output

Test plan

  • 118/119 unit tests pass (1 pre-existing failure in module_context_test)
  • 23/23 benchmark regression cases pass
  • Example produces exactly 2 expected findings
  • moon publish --dry-run succeeds (202)
  • No secrets in staged files

🤖 Generated with Claude Code

I3eg1nner and others added 3 commits September 30, 2026 04:52
CWE-22: Add API route, git ref, shell script, internal path, custom
protocol, and string comparison filters. Reduces popular-project
findings from 53 to 16 (~70% reduction, FP rate ~19%).

CWE-113: Add safe variable tracking for let-bound sanitized and
constant values. Recognize all-constant match branches. Keep
is_constant_string as base check to avoid false negatives.

Benchmarks: 23 cases across 6 CWE rules (CWE-22: 9, CWE-113: 5,
CWE-248: 3, CWE-676: 2, CWE-704: 2, CWE-079: 2) with automated
regression runner.

Add examples/vulnerable_server.mbt with CWE-22 and CWE-113 demo.
Add .moonignore to exclude non-library files for mooncakes publishing
(40MB → 6.3MB). Add audit_hint disposition for CWE-248/676/704 rules.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
moon fmt formatting and moon info interface regeneration to pass CI
checks. Update module_context_test assertions to expect 5 findings
instead of 2, matching CWE-248 requirement change to "none".

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Restore the project introduction, real-world results table, rule
tables, CI integration, and architecture sections from the original
README. Update for current state: 14 rules, FP reduction, mooncakes
install, quick example, benchmarks. Condense semantic/verification/
workspace into a single optional section.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@I3eg1nner
I3eg1nner merged commit 7456a62 into main Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant