Skip to content

Latest commit

 

History

History
35 lines (29 loc) · 1.74 KB

File metadata and controls

35 lines (29 loc) · 1.74 KB

Case Studies

Real public codebases the auditor runs against. The project currently runs in two phases (see docs/research/03-difficulty-scoring-model.md §8):

  • Phase 1 (current): pin a codebase, run the auditor, publish its readiness report (score, effort tier, ranked hotspots) as an estimate. No migration is performed.
  • Phase 2 (deferred, not currently active): migrate the pinned codebase (or mine one that already migrated for real) and log actual effort, to validate the score against measured effort (see docs/research/04-case-study-plan.md).

Case-study codebases are added as git submodules (git submodule add <repo-url> case-studies/<name>/repo), pinned to a specific commit, so the exact code a report describes is always reproducible, even though Phase 1 doesn't modify that code at all. (The submodule lives in repo/, not target/, because the standard Java .gitignore excludes target/.)

Structure (populated in Phase 1):

case-studies/
├── pre-scan.md                        (selection rationale + pinned commits)
├── phase1-findings.md                 (cross-repo estimation synthesis)
└── <codebase-name>/
    ├── repo/                          (git submodule, pinned to a specific commit)
    ├── readiness-report.json          (Phase 1: auditor output)
    ├── readiness-report.md            (Phase 1: auditor output)
    └── effort-log.md                  (Phase 2 only, once that phase starts)

Current case studies: jjwt, mina-sshd, californium, shiro. See pre-scan.md for pins and phase1-findings.md for the analysis.