REPRODUCIBLE PRODUCT EVIDENCE

Secret Sentinel regression benchmark

This report answers a narrow question: did every automated case in the named private corpus pass at one exact revision? It does not turn regression tests into a claim of universal detection accuracy.

Sigstore-signed CI resultSigned by the private repository's GitHub Actions OIDC identity at commit 36f066384ead.

388/388

automated test cases passed

Benchmark version
2026.08
Core version
1.0.0
Generated
August 2, 2026 UTC
Revision
36f066384ead

Results by behavior

Detection and non-detection

90/90

0 failed · 0 skipped

Redaction integrity

57/57

0 failed · 0 skipped

Idempotency and convergence

50/50

0 failed · 0 skipped

Jira and Confluence workflow

97/97

0 failed · 0 skipped

Configuration and aggregate storage

67/67

0 failed · 0 skipped

Core reliability

27/27

0 failed · 0 skipped

What is actually measured

The unit is one automated test case, not one credential provider and not one customer document. The private synthetic corpus covers documented credential shapes and safe near misses, Jira ADF and Confluence storage redaction, repeated-event convergence, workflow routing, configuration, aggregate KVS behavior, and supporting reliability utilities.

Classification is deterministic and performed only after Vitest completes. The public JSON contains group counts—never fixture values, test names, repository paths, scanner rules, or regular expressions.

What the number does not mean

Integrity and independent inspection

CI first executes the private corpus, generates a canonical aggregate report, then signs that exact JSON blob with Cosign using GitHub's short-lived OIDC identity. The workflow publishes the report and Sigstore verification bundle together. A permanent private signing key is not stored in the repository.