Skip to content

SE Verification: Vulnerability Matching

An exploratory study of finite conformance auditing for security-relevant identity semantics in software vulnerability matching.

Purpose

This project applies the finite operational-identity framework from SE-210, Operational Identity: A Finite Audit of Declared and Implemented Rules of Sameness, to vulnerability matching in software composition analysis and VEX systems.

The repository plans an exploratory study to see whether implementation behavior conforms to applicable identity commitments when package, component, artifact, or product representations change under controlled transformations.

The contribution is identity conformance, not scanner disagreement.

Contents

The repository separates several kinds of research artifacts:

  • Contracts define identity commitments and record their provenance.
  • Validation cases use already-public evidence to test the engineering and analytical machinery.
  • Prospective cases define the registered study corpus and remain unexecuted before Stage 1 authorization.
  • Protocol documents define selection, execution, adjudication, analysis, reliability, disclosure, snapshot, and freeze procedures.
  • Validation fixtures and demonstrations support bounded engineering and feasibility work but are excluded from research-question analysis.
  • Implementation code provides scanner adapters, normalization, audit, and witness-construction machinery.
  • Prospective results are reserved for authorized study execution.

Current Status

The project is under active development for the MSR 2027 Registered Reports track.

The repository currently includes the study design, protocol, identity commitments, public validation cases, reduced fixtures, scanner-adapter foundations, and bounded feasibility demonstrations.

No prospective study results have been collected.

Known public validation evidence remains categorically separate from evidence used to answer the registered research questions.

Structural Explainability Role

This project reuses the finite SE-210 operational-identity audit rather than reimplementing its mathematical core.

Given a finite record domain, declared identity relations, operational surfaces, and observed uses, the underlying SE-210 machinery can identify structural divergence relative to the supplied formalization.

This repository is responsible for the applied layer:

  • identifying source-grounded identity commitments;
  • constructing controlled vulnerability-matching cases;
  • reproducing implementation behavior;
  • mapping observations into the formal model;
  • validating that the mapping does not invent unsupported identity relations;
  • adjudicating resulting witnesses; and
  • evaluating whether structural positioning adds explanatory value beyond a high-rigor conventional conformance audit.

Documentation

For repository-level scope, development instructions, release information, and the Registered Report boundary, see the project README.md.