Skip to content

Prepare v0.7.1 analyzer pin refresh - #162

Closed
DavidBakerEffendi wants to merge 1 commit into
mainfrom
dave/v071-pin-currency-prep
Closed

Prepare v0.7.1 analyzer pin refresh#162
DavidBakerEffendi wants to merge 1 commit into
mainfrom
dave/v071-pin-currency-prep

Conversation

@DavidBakerEffendi

Copy link
Copy Markdown
Collaborator

Summary

Refreshes public analyzer pins and tool preparation declarations for the v0.7.1 measurement lane.

Key changes

  • Bump Bifrost to v0.11.0, Joern to 4.0.621, and all eight benchmark-controlled CodeQL language packs; regenerate locks.
  • Record exact public tool paths/hashes, 19-script probe inventory, population-scoped timing commands, and retained-repeat semantics.
  • Keep OpenTaint direct-jar invocation pending fresh wrapper/rules equivalence and eligibility re-evaluation; update component digests.

Validation

  • Rebased onto origin/main 53050fa.
  • cargo fmt --check and git diff --check.
  • cargo test native (28 passed) via direct cargo with CARGO_TARGET_DIR=/private/tmp/dataflowbench-target.
  • Shell syntax checks for modified probes.
  • cargo run -- --population v0.7.0 measure-warm-latency --help and estimate-invocation-overhead --help.
  • Joern v4.0.621 public archive SHA-256 verified.

No measurements or normalized evidence were changed.

@DavidBakerEffendi
DavidBakerEffendi force-pushed the dave/v071-pin-currency-prep branch from 7cd6c1d to c0899da Compare September 7, 2026 14:52
@DavidBakerEffendi

Copy link
Copy Markdown
Collaborator Author

Superseded by the coordinated v0.7.1 evidence refresh on dave/v071-measurement-evidence. That branch already contains pin commit c0899da. This standalone PR correctly fails validation because its 11 CodeQL kernel reports retain the previous configuration hashes; the fresh non-native CodeQL sweep has now cleared that mismatch in the measurement worktree. Pins and complete refreshed evidence will be delivered together in the replacement PR, with full CI validation. No stale-report exemptions are being added. Closing this preparation PR preserves its branch and review history; the freeze work continues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant