How does Bifrost measure up on semantic data flow?
Immutable evaluation · DataFlowBench v0.4.0
c kernel · correct decisions
Bifrost
2/48
2 of 2 decided
CodeQL
41/48
Semgrep CE
12/48
12 of 14 decided
24 templates · unanswered outcomes (Bifrost: 46 incomplete; Semgrep CE: 34 declined) are coverage, excluded from correctness and never counted against it
cpp kernel · correct decisions
Bifrost
2/56
2 of 2 decided
CodeQL
42/56
Semgrep CE
12/56
12 of 14 decided
28 templates · unanswered outcomes (Bifrost: 54 incomplete; Semgrep CE: 42 declined) are coverage, excluded from correctness and never counted against it
csharp kernel · correct decisions
Bifrost
3/58
3 of 3 decided
CodeQL
47/58
29 templates · unanswered outcomes (Bifrost: 55 incomplete) are coverage, excluded from correctness and never counted against it
go kernel · correct decisions
Bifrost
14/58
14 of 14 decided
CodeQL
45/58
Semgrep CE
12/58
12 of 14 decided
29 templates · unanswered outcomes (Bifrost: 44 incomplete; Semgrep CE: 44 declined) are coverage, excluded from correctness and never counted against it
java kernel · correct decisions
Bifrost
37/58
37 of 38 decided
CodeQL
48/58
Joern
47/58
Semgrep CE
12/58
12 of 14 decided
29 templates · unanswered outcomes (Bifrost: 18 incomplete, 2 runner-error; Semgrep CE: 44 declined) are coverage, excluded from correctness and never counted against it
javascript kernel · correct decisions
Bifrost
36/58
36 of 36 decided
CodeQL
48/58
Joern
44/58
Semgrep CE
12/58
12 of 14 decided
29 templates · unanswered outcomes (Bifrost: 20 incomplete, 2 runner-error; Semgrep CE: 44 declined) are coverage, excluded from correctness and never counted against it
kotlin kernel · correct decisions
Bifrost
25/58
25 of 28 decided
CodeQL
46/58
Semgrep CE
12/58
12 of 14 decided
29 templates · unanswered outcomes (Bifrost: 28 incomplete, 2 runner-error; Semgrep CE: 44 declined) are coverage, excluded from correctness and never counted against it
php kernel · correct decisions
Bifrost
21/58
21 of 22 decided
Joern
48/58
Semgrep CE
12/58
12 of 14 decided
29 templates · unanswered outcomes (Bifrost: 36 incomplete; Semgrep CE: 44 declined) are coverage, excluded from correctness and never counted against it
python kernel · correct decisions
Bifrost
36/58
36 of 36 decided
CodeQL
48/58
Joern
48/58
Semgrep CE
12/58
12 of 14 decided
29 templates · unanswered outcomes (Bifrost: 20 incomplete, 2 runner-error; Semgrep CE: 44 declined) are coverage, excluded from correctness and never counted against it
ruby kernel · correct decisions
Bifrost
0/58
0 of 0 decided
CodeQL
49/58
Joern
40/58
Semgrep CE
12/58
12 of 14 decided
29 templates · unanswered outcomes (Bifrost: 58 incomplete; Semgrep CE: 44 declined) are coverage, excluded from correctness and never counted against it
rust kernel · correct decisions
Bifrost
2/54
2 of 2 decided
CodeQL
44/54
Joern
43/54
Semgrep CE
12/54
12 of 14 decided
27 templates · unanswered outcomes (Bifrost: 40 incomplete, 12 runner-error; Semgrep CE: 40 declined) are coverage, excluded from correctness and never counted against it
scala kernel · correct decisions
Bifrost
10/58
10 of 10 decided
29 templates · unanswered outcomes (Bifrost: 48 incomplete) are coverage, excluded from correctness and never counted against it
typescript kernel · correct decisions
Bifrost
34/58
34 of 34 decided
CodeQL
48/58
Semgrep CE
12/58
12 of 14 decided
29 templates · unanswered outcomes (Bifrost: 22 incomplete, 2 runner-error; Semgrep CE: 44 declined) are coverage, excluded from correctness and never counted against it
Direct-flow breadth · languages fully correct
Bifrost
12/13
one positive and one negative direct-propagation assertion per language
Kernels, template by template
Each row is one semantic scenario with a balanced pair: the flow exists
(positive) and a minimally different variant where it does not (negative). A
sound-and-precise analyzer reads reached /
not-reached. Read the analyzers' columns
independently — DataFlowBench publishes no combined leaderboard, and the
scorecards stay separate under the benchmark-controlled model
profile.
c
| Template | Bifrost 0.10.6 | CodeQL 2.26.3 | Semgrep CE 1.174.0 | |||
|---|---|---|---|---|---|---|
| positive | negative | positive | negative | positive | negative | |
alias-propagation-separation | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
argument-position-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
arithmetic-expression-propagation | inconclusive | inconclusive | reached | not-reached | reached | not-reached |
array-element-separation | inconclusive | inconclusive | reached | reached | unsupported | unsupported |
branch-join | inconclusive | inconclusive | reached | not-reached | reached | not-reached |
call-context-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-callback-registration | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-context-pair-depth2 | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-deep-relay-chain | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-dispatch-table | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-element-object | inconclusive | inconclusive | reached | reached | unsupported | unsupported |
chal-function-field | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-map-iteration | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-nested-access-path | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-recursive-carry | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
direct-propagation | reached | not-reached | reached | not-reached | reached | not-reached |
infeasible-branch | inconclusive | inconclusive | reached | not-reached | reached | reached |
local-multi-step-chain | inconclusive | inconclusive | reached | not-reached | reached | not-reached |
local-overwrite-kill | inconclusive | inconclusive | reached | not-reached | reached | not-reached |
loop-carried-kill | inconclusive | inconclusive | reached | reached | reached | reached |
object-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
return-relay-one-hop | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
return-relay-two-hop | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
same-object-field-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
cpp
| Template | Bifrost 0.10.6 | CodeQL 2.26.3 | Semgrep CE 1.174.0 | |||
|---|---|---|---|---|---|---|
| positive | negative | positive | negative | positive | negative | |
alias-propagation-separation | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
argument-position-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
arithmetic-expression-propagation | inconclusive | inconclusive | reached | not-reached | reached | not-reached |
array-element-separation | inconclusive | inconclusive | reached | reached | unsupported | unsupported |
branch-join | inconclusive | inconclusive | reached | not-reached | reached | not-reached |
call-context-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-anonymous-implementation | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-callback-registration | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-closure-capture | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-computed-property | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-context-pair-depth2 | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-deep-relay-chain | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-dispatch-table | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-element-object | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-function-field | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-map-iteration | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-nested-access-path | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-recursive-carry | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
direct-propagation | reached | not-reached | reached | not-reached | reached | not-reached |
exception-catch | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
infeasible-branch | inconclusive | inconclusive | reached | not-reached | reached | reached |
local-multi-step-chain | inconclusive | inconclusive | reached | not-reached | reached | not-reached |
local-overwrite-kill | inconclusive | inconclusive | reached | not-reached | reached | not-reached |
loop-carried-kill | inconclusive | inconclusive | reached | reached | reached | reached |
object-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
return-relay-one-hop | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
return-relay-two-hop | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
same-object-field-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
csharp
| Template | Bifrost 0.10.6 | CodeQL 2.26.3 | ||
|---|---|---|---|---|
| positive | negative | positive | negative | |
alias-propagation-separation | inconclusive | inconclusive | not-reached | not-reached |
argument-position-separation | inconclusive | inconclusive | reached | not-reached |
arithmetic-expression-propagation | inconclusive | inconclusive | not-reached | not-reached |
array-element-separation | inconclusive | inconclusive | reached | reached |
branch-join | inconclusive | inconclusive | reached | not-reached |
call-context-separation | inconclusive | inconclusive | reached | not-reached |
chal-anonymous-implementation | inconclusive | inconclusive | reached | not-reached |
chal-callback-registration | inconclusive | inconclusive | not-reached | not-reached |
chal-closure-capture | inconclusive | inconclusive | reached | not-reached |
chal-computed-property | inconclusive | inconclusive | not-reached | not-reached |
chal-context-pair-depth2 | inconclusive | inconclusive | reached | not-reached |
chal-deep-relay-chain | reached | inconclusive | reached | not-reached |
chal-dispatch-table | inconclusive | inconclusive | not-reached | not-reached |
chal-element-object | inconclusive | inconclusive | reached | reached |
chal-function-field | inconclusive | inconclusive | not-reached | not-reached |
chal-map-iteration | inconclusive | inconclusive | reached | not-reached |
chal-nested-access-path | inconclusive | inconclusive | reached | not-reached |
chal-recursive-carry | inconclusive | inconclusive | reached | not-reached |
chal-reflective-invocation | inconclusive | inconclusive | not-reached | not-reached |
direct-propagation | reached | not-reached | reached | not-reached |
exception-catch | inconclusive | inconclusive | not-reached | not-reached |
infeasible-branch | inconclusive | inconclusive | reached | not-reached |
local-multi-step-chain | inconclusive | inconclusive | reached | not-reached |
local-overwrite-kill | inconclusive | inconclusive | reached | not-reached |
loop-carried-kill | inconclusive | inconclusive | reached | reached |
object-separation | inconclusive | inconclusive | reached | not-reached |
return-relay-one-hop | inconclusive | inconclusive | reached | not-reached |
return-relay-two-hop | inconclusive | inconclusive | reached | not-reached |
same-object-field-separation | inconclusive | inconclusive | reached | not-reached |
go
| Template | Bifrost 0.10.6 | CodeQL 2.26.3 | Semgrep CE 1.174.0 | |||
|---|---|---|---|---|---|---|
| positive | negative | positive | negative | positive | negative | |
alias-propagation-separation | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
argument-position-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
arithmetic-expression-propagation | inconclusive | inconclusive | not-reached | not-reached | reached | not-reached |
array-element-separation | inconclusive | inconclusive | reached | reached | unsupported | unsupported |
branch-join | inconclusive | inconclusive | reached | not-reached | reached | not-reached |
call-context-separation | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-anonymous-implementation | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-callback-registration | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-closure-capture | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-computed-property | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-context-pair-depth2 | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-deep-relay-chain | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-dispatch-table | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-element-object | inconclusive | inconclusive | reached | reached | unsupported | unsupported |
chal-function-field | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-map-iteration | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-nested-access-path | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-recursive-carry | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-reflective-invocation | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
direct-propagation | reached | not-reached | reached | not-reached | reached | not-reached |
exception-catch | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
infeasible-branch | inconclusive | inconclusive | reached | reached | reached | reached |
local-multi-step-chain | reached | not-reached | reached | not-reached | reached | not-reached |
local-overwrite-kill | inconclusive | inconclusive | reached | not-reached | reached | not-reached |
loop-carried-kill | inconclusive | inconclusive | reached | reached | reached | reached |
object-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
return-relay-one-hop | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-two-hop | reached | not-reached | reached | not-reached | unsupported | unsupported |
same-object-field-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
java
| Template | Bifrost 0.10.6 | CodeQL 2.26.3 | Joern 4.0.610 | Semgrep CE 1.174.0 | ||||
|---|---|---|---|---|---|---|---|---|
| positive | negative | positive | negative | positive | negative | positive | negative | |
alias-propagation-separation | reached | not-reached | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
argument-position-separation | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
arithmetic-expression-propagation | reached | not-reached | not-reached | not-reached | reached | not-reached | reached | not-reached |
array-element-separation | reached | not-reached | reached | reached | reached | not-reached | unsupported | unsupported |
branch-join | reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
call-context-separation | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-anonymous-implementation | inconclusive | inconclusive | reached | not-reached | reached | reached | unsupported | unsupported |
chal-callback-registration | inconclusive | inconclusive | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-closure-capture | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-computed-property | inconclusive | inconclusive | not-reached | not-reached | reached | reached | unsupported | unsupported |
chal-context-pair-depth2 | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-deep-relay-chain | reached | not-reached | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-dispatch-table | inconclusive | inconclusive | reached | reached | not-reached | not-reached | unsupported | unsupported |
chal-element-object | runner-error | runner-error | reached | reached | reached | not-reached | unsupported | unsupported |
chal-function-field | inconclusive | inconclusive | reached | reached | not-reached | not-reached | unsupported | unsupported |
chal-map-iteration | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-nested-access-path | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-recursive-carry | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-reflective-invocation | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
direct-propagation | not-reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
exception-catch | reached | not-reached | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
infeasible-branch | reached | not-reached | reached | not-reached | reached | reached | reached | reached |
local-multi-step-chain | reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
local-overwrite-kill | reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
loop-carried-kill | reached | not-reached | reached | reached | reached | reached | reached | reached |
object-separation | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-one-hop | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-two-hop | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
same-object-field-separation | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
javascript
| Template | Bifrost 0.10.6 | CodeQL 2.26.3 | Joern 4.0.610 | Semgrep CE 1.174.0 | ||||
|---|---|---|---|---|---|---|---|---|
| positive | negative | positive | negative | positive | negative | positive | negative | |
alias-propagation-separation | reached | not-reached | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
argument-position-separation | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
arithmetic-expression-propagation | reached | not-reached | not-reached | not-reached | reached | not-reached | reached | not-reached |
array-element-separation | reached | not-reached | reached | not-reached | reached | reached | unsupported | unsupported |
branch-join | reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
call-context-separation | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-anonymous-implementation | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-callback-registration | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-closure-capture | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-computed-property | inconclusive | inconclusive | reached | reached | reached | reached | unsupported | unsupported |
chal-context-pair-depth2 | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-deep-relay-chain | reached | not-reached | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-dispatch-table | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-element-object | runner-error | runner-error | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-function-field | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-map-iteration | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-nested-access-path | inconclusive | inconclusive | not-reached | not-reached | reached | reached | unsupported | unsupported |
chal-recursive-carry | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-reflective-invocation | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
direct-propagation | reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
exception-catch | reached | not-reached | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
infeasible-branch | reached | not-reached | reached | not-reached | reached | reached | reached | reached |
local-multi-step-chain | reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
local-overwrite-kill | reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
loop-carried-kill | reached | not-reached | reached | reached | reached | reached | reached | reached |
object-separation | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-one-hop | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-two-hop | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
same-object-field-separation | reached | not-reached | reached | not-reached | reached | reached | unsupported | unsupported |
kotlin
| Template | Bifrost 0.10.6 | CodeQL 2.26.3 | Semgrep CE 1.174.0 | |||
|---|---|---|---|---|---|---|
| positive | negative | positive | negative | positive | negative | |
alias-propagation-separation | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
argument-position-separation | reached | not-reached | reached | not-reached | unsupported | unsupported |
arithmetic-expression-propagation | not-reached | not-reached | not-reached | not-reached | reached | not-reached |
array-element-separation | inconclusive | inconclusive | reached | reached | unsupported | unsupported |
branch-join | reached | not-reached | reached | not-reached | reached | not-reached |
call-context-separation | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-anonymous-implementation | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-callback-registration | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-closure-capture | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-computed-property | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-context-pair-depth2 | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-deep-relay-chain | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-dispatch-table | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-element-object | runner-error | runner-error | reached | reached | unsupported | unsupported |
chal-function-field | inconclusive | inconclusive | reached | reached | unsupported | unsupported |
chal-map-iteration | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-nested-access-path | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-recursive-carry | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-reflective-invocation | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
direct-propagation | reached | not-reached | reached | not-reached | reached | not-reached |
exception-catch | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
infeasible-branch | reached | reached | reached | not-reached | reached | reached |
local-multi-step-chain | reached | not-reached | reached | not-reached | reached | not-reached |
local-overwrite-kill | reached | not-reached | reached | not-reached | reached | not-reached |
loop-carried-kill | reached | reached | reached | reached | reached | reached |
object-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
return-relay-one-hop | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-two-hop | reached | not-reached | reached | not-reached | unsupported | unsupported |
same-object-field-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
php
| Template | Bifrost 0.10.6 | Joern 4.0.610 | Semgrep CE 1.174.0 | |||
|---|---|---|---|---|---|---|
| positive | negative | positive | negative | positive | negative | |
alias-propagation-separation | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
argument-position-separation | reached | not-reached | reached | not-reached | unsupported | unsupported |
arithmetic-expression-propagation | inconclusive | inconclusive | reached | not-reached | reached | not-reached |
array-element-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
branch-join | reached | not-reached | reached | not-reached | reached | not-reached |
call-context-separation | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-anonymous-implementation | inconclusive | inconclusive | reached | reached | unsupported | unsupported |
chal-callback-registration | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-closure-capture | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-computed-property | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-context-pair-depth2 | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-deep-relay-chain | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-dispatch-table | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-element-object | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-function-field | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-map-iteration | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-nested-access-path | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-recursive-carry | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-reflective-invocation | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
direct-propagation | reached | not-reached | reached | not-reached | reached | not-reached |
exception-catch | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
infeasible-branch | reached | reached | reached | reached | reached | reached |
local-multi-step-chain | reached | not-reached | reached | not-reached | reached | not-reached |
local-overwrite-kill | reached | not-reached | reached | not-reached | reached | not-reached |
loop-carried-kill | inconclusive | inconclusive | reached | reached | reached | reached |
object-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
return-relay-one-hop | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-two-hop | reached | not-reached | reached | not-reached | unsupported | unsupported |
same-object-field-separation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
python
| Template | Bifrost 0.10.6 | CodeQL 2.26.3 | Joern 4.0.610 | Semgrep CE 1.174.0 | ||||
|---|---|---|---|---|---|---|---|---|
| positive | negative | positive | negative | positive | negative | positive | negative | |
alias-propagation-separation | reached | not-reached | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
argument-position-separation | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
arithmetic-expression-propagation | reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
array-element-separation | reached | not-reached | not-reached | not-reached | reached | not-reached | unsupported | unsupported |
branch-join | reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
call-context-separation | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-anonymous-implementation | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-callback-registration | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-closure-capture | inconclusive | inconclusive | not-reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-computed-property | inconclusive | inconclusive | not-reached | not-reached | reached | reached | unsupported | unsupported |
chal-context-pair-depth2 | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-deep-relay-chain | reached | not-reached | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-dispatch-table | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-element-object | runner-error | runner-error | reached | reached | reached | not-reached | unsupported | unsupported |
chal-function-field | inconclusive | inconclusive | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-map-iteration | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-nested-access-path | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-recursive-carry | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-reflective-invocation | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
direct-propagation | reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
exception-catch | reached | not-reached | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
infeasible-branch | reached | not-reached | reached | not-reached | reached | reached | reached | reached |
local-multi-step-chain | reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
local-overwrite-kill | reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
loop-carried-kill | reached | not-reached | reached | reached | reached | reached | reached | reached |
object-separation | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-one-hop | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-two-hop | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
same-object-field-separation | reached | not-reached | reached | not-reached | reached | not-reached | unsupported | unsupported |
ruby
| Template | Bifrost 0.10.6 | CodeQL 2.26.3 | Joern 4.0.610 | Semgrep CE 1.174.0 | ||||
|---|---|---|---|---|---|---|---|---|
| positive | negative | positive | negative | positive | negative | positive | negative | |
alias-propagation-separation | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
argument-position-separation | inconclusive | inconclusive | reached | not-reached | reached | reached | unsupported | unsupported |
arithmetic-expression-propagation | inconclusive | inconclusive | reached | not-reached | reached | not-reached | reached | not-reached |
array-element-separation | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
branch-join | inconclusive | inconclusive | reached | not-reached | reached | not-reached | reached | not-reached |
call-context-separation | inconclusive | inconclusive | reached | not-reached | reached | reached | unsupported | unsupported |
chal-anonymous-implementation | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-callback-registration | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-closure-capture | inconclusive | inconclusive | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-computed-property | inconclusive | inconclusive | not-reached | not-reached | reached | reached | unsupported | unsupported |
chal-context-pair-depth2 | inconclusive | inconclusive | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-deep-relay-chain | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-dispatch-table | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-element-object | inconclusive | inconclusive | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-function-field | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-map-iteration | inconclusive | inconclusive | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-nested-access-path | inconclusive | inconclusive | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-recursive-carry | inconclusive | inconclusive | reached | not-reached | reached | reached | unsupported | unsupported |
chal-reflective-invocation | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
direct-propagation | inconclusive | inconclusive | reached | not-reached | reached | not-reached | reached | not-reached |
exception-catch | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
infeasible-branch | inconclusive | inconclusive | reached | not-reached | reached | reached | reached | reached |
local-multi-step-chain | inconclusive | inconclusive | reached | not-reached | reached | not-reached | reached | not-reached |
local-overwrite-kill | inconclusive | inconclusive | reached | not-reached | reached | not-reached | reached | not-reached |
loop-carried-kill | inconclusive | inconclusive | reached | reached | reached | reached | reached | reached |
object-separation | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-one-hop | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-two-hop | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
same-object-field-separation | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
rust
| Template | Bifrost 0.10.6 | CodeQL 2.26.3 | Joern 4.0.610 | Semgrep CE 1.174.0 | ||||
|---|---|---|---|---|---|---|---|---|
| positive | negative | positive | negative | positive | negative | positive | negative | |
alias-propagation-separation | runner-error | runner-error | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
argument-position-separation | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
arithmetic-expression-propagation | inconclusive | inconclusive | reached | not-reached | reached | not-reached | reached | not-reached |
array-element-separation | runner-error | runner-error | reached | reached | reached | not-reached | unsupported | unsupported |
branch-join | inconclusive | inconclusive | reached | not-reached | reached | not-reached | reached | not-reached |
call-context-separation | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-anonymous-implementation | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-callback-registration | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-closure-capture | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-computed-property | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-context-pair-depth2 | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-deep-relay-chain | inconclusive | inconclusive | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-dispatch-table | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-element-object | runner-error | runner-error | not-reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-function-field | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-map-iteration | inconclusive | inconclusive | not-reached | not-reached | not-reached | not-reached | unsupported | unsupported |
chal-nested-access-path | runner-error | runner-error | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-recursive-carry | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
direct-propagation | reached | not-reached | reached | not-reached | reached | not-reached | reached | not-reached |
infeasible-branch | inconclusive | inconclusive | reached | not-reached | reached | reached | reached | reached |
local-multi-step-chain | inconclusive | inconclusive | reached | not-reached | reached | not-reached | reached | not-reached |
local-overwrite-kill | inconclusive | inconclusive | reached | not-reached | reached | not-reached | reached | not-reached |
loop-carried-kill | inconclusive | inconclusive | reached | reached | reached | reached | reached | reached |
object-separation | runner-error | runner-error | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-one-hop | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-two-hop | inconclusive | inconclusive | reached | not-reached | reached | not-reached | unsupported | unsupported |
same-object-field-separation | runner-error | runner-error | reached | not-reached | reached | not-reached | unsupported | unsupported |
scala
| Template | Bifrost 0.10.6 | |
|---|---|---|
| positive | negative | |
alias-propagation-separation | inconclusive | inconclusive |
argument-position-separation | reached | not-reached |
arithmetic-expression-propagation | inconclusive | inconclusive |
array-element-separation | inconclusive | inconclusive |
branch-join | inconclusive | inconclusive |
call-context-separation | reached | not-reached |
chal-anonymous-implementation | inconclusive | inconclusive |
chal-callback-registration | inconclusive | inconclusive |
chal-closure-capture | inconclusive | inconclusive |
chal-computed-property | inconclusive | inconclusive |
chal-context-pair-depth2 | inconclusive | inconclusive |
chal-deep-relay-chain | inconclusive | inconclusive |
chal-dispatch-table | inconclusive | inconclusive |
chal-element-object | inconclusive | inconclusive |
chal-function-field | inconclusive | inconclusive |
chal-map-iteration | inconclusive | inconclusive |
chal-nested-access-path | inconclusive | inconclusive |
chal-recursive-carry | inconclusive | inconclusive |
chal-reflective-invocation | inconclusive | inconclusive |
direct-propagation | reached | not-reached |
exception-catch | inconclusive | inconclusive |
infeasible-branch | inconclusive | inconclusive |
local-multi-step-chain | reached | not-reached |
local-overwrite-kill | inconclusive | inconclusive |
loop-carried-kill | inconclusive | inconclusive |
object-separation | inconclusive | inconclusive |
return-relay-one-hop | reached | not-reached |
return-relay-two-hop | inconclusive | inconclusive |
same-object-field-separation | inconclusive | inconclusive |
typescript
| Template | Bifrost 0.10.6 | CodeQL 2.26.3 | Semgrep CE 1.174.0 | |||
|---|---|---|---|---|---|---|
| positive | negative | positive | negative | positive | negative | |
alias-propagation-separation | reached | not-reached | not-reached | not-reached | unsupported | unsupported |
argument-position-separation | reached | not-reached | reached | not-reached | unsupported | unsupported |
arithmetic-expression-propagation | reached | not-reached | not-reached | not-reached | reached | not-reached |
array-element-separation | reached | not-reached | reached | not-reached | unsupported | unsupported |
branch-join | reached | not-reached | reached | not-reached | reached | not-reached |
call-context-separation | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-anonymous-implementation | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-callback-registration | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-closure-capture | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-computed-property | inconclusive | inconclusive | reached | reached | unsupported | unsupported |
chal-context-pair-depth2 | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-deep-relay-chain | reached | not-reached | reached | not-reached | unsupported | unsupported |
chal-dispatch-table | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-element-object | runner-error | runner-error | reached | not-reached | unsupported | unsupported |
chal-function-field | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-map-iteration | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-nested-access-path | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
chal-recursive-carry | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
chal-reflective-invocation | inconclusive | inconclusive | not-reached | not-reached | unsupported | unsupported |
direct-propagation | reached | not-reached | reached | not-reached | reached | not-reached |
exception-catch | inconclusive | inconclusive | reached | not-reached | unsupported | unsupported |
infeasible-branch | reached | not-reached | reached | not-reached | reached | reached |
local-multi-step-chain | reached | not-reached | reached | not-reached | reached | not-reached |
local-overwrite-kill | reached | not-reached | reached | not-reached | reached | not-reached |
loop-carried-kill | reached | not-reached | reached | reached | reached | reached |
object-separation | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-one-hop | reached | not-reached | reached | not-reached | unsupported | unsupported |
return-relay-two-hop | reached | not-reached | reached | not-reached | unsupported | unsupported |
same-object-field-separation | reached | not-reached | reached | not-reached | unsupported | unsupported |
Direct-flow breadth, language by language
| Language | Positive assertion | Negative assertion | Verdict |
|---|---|---|---|
c | reached | not-reached | both correct |
cpp | reached | not-reached | both correct |
csharp | reached | not-reached | both correct |
go | reached | not-reached | both correct |
java | reached | not-reached | both correct |
javascript | reached | not-reached | both correct |
kotlin | reached | not-reached | both correct |
php | reached | not-reached | both correct |
python | reached | not-reached | both correct |
ruby | inconclusive | inconclusive | incomplete analysis |
rust | reached | not-reached | both correct |
scala | reached | not-reached | both correct |
typescript | reached | not-reached | both correct |
What this result means
DataFlowBench measures whether analyzers correctly decide semantic
data-flow questions — and whether they stay quiet when they should. Cases
are balanced positive/negative pairs of language-neutral semantic templates
(aliasing, kills, call context, branch joins, exception paths, …) run under
a benchmark-controlled model profile, so the engines are
compared under a common contract rather than through their shipped model
packs.
This snapshot's bounded claim covers the synthetic direct-flow breadth
baseline and the propagation kernels of the 13 kernel
languages above on the taint track. Cores are sized per
language (24, 27, 28 or 29 templates), so each kernel is read on its own
denominator; language-only constructs are reported in separate
language-extension tiers on the snapshot pages. It does not
estimate real-project accuracy, tool-native model coverage, other
languages' kernel behavior, or performance. inconclusive,
unsupported, and
runner-error are capability coverage and are never converted
into clean negatives.
2452
frozen case results
13
languages in the breadth baseline
13
kernel languages (24, 27, 28 or 29 templates each)
v0.4.0
immutable evidence release
Why these numbers are trustworthy
Every count on this page is generated from the
freeze
manifest (91b0008a546e…),
which digest-binds the benchmark revision, every case and fixture, every
analyzer's identity, their normalized reports, and one retained raw
artifact per result. CI regenerates the numbers from the manifest and fails
on any drift; hand-authored prose cannot override a generated count. See
reproduction to verify locally,
or dive into the full
snapshot —
analyzers,
languages,
templates,
and per-case
evidence.