Public proof

Evidence you can inspect. Misses included.

Two public audits, then the other findings. Counts are from the public record, read 30 August 2026.

PUBLIC AUDIT EVIDENCE

rsync

Audit still running.

  • 99filed
  • 45open
  • 21fixed
  • 28withdrawn
  • 5allowed to stand

The 3.5.0 release shipped 33 security fixes from this audit, daemon fuzzing, Trail of Bits, and other research. The release notes credit Leonid Bugaev. Withdrawn means the audit disproved its own finding and left the entry on the board. Ten findings date to 1996. Open reports stay unpublished until they are public and closed. The cycle carries 39 CVE IDs.

PUBLIC AUDIT EVIDENCE

jsonparser

Public master. Not the demo branch.

  • 123requirements
  • 6found
  • 2misses
  • 8defect records
  • 3changes

Proof’s founder maintains this library. Grafana Loki, Keybase, Coroot, and the Solana Go SDK require it. Two defects in Set() escaped the review and are fixed on master. One returned [9] for an array that had been [1,2]. The other panicked on an empty key.

“MC/DC has no notion of ‘correct’; it has only ‘exercised.’”

The corpus contains 123 requirements, with 28 approved in this snapshot. Its historical MC/DC result must be read with the measured scope and exclusions; it is not a claim of complete behavioral coverage. One change record covers the v1.5.0 feature. How to read MC/DC evidence.

Findings

The other public security work.

Fixes, pull requests, and issues beyond the two audits. Every row was reported by Proof. The label says whether the public record names us: credited upstream, not credited upstream, or credited to another reporter.

PUBLIC AUDIT EVIDENCE Each link opens the vendor’s own public record.

The public register lists every finding, entry by entry. Open the public register →

Open reports and private reports are not on this page. Rows were checked on 30 August 2026.

One finding

Run one jsonparser test.

Set() once returned malformed JSON and a nil error. The fix is on master, so the test passes. The file-by-file record is on the jsonparser page.

PUBLIC AUDIT EVIDENCE The command runs against public master. No account, no token.

buger/jsonparser · master Passes

Clone, then run

git clone https://github.com/buger/jsonparser

cd jsonparser && go test -run TestSetArrayIndexUnderObjectMalformedJSON_KI3

What you should see

ok  github.com/buger/jsonparser

Labels

Three places. Three jobs.

The portal, the register, and the case pages are not the same record.

The portal runs on proof-demo. Real findings on that view sit under Fixed. This page does not count the demonstrations.

What this record does not prove.

  1. We chose the subjects.

    rsync and jsonparser were not assigned. jsonparser is maintained by Proof’s founder. A chosen project is a weaker claim than an assigned one.

  2. The product demo is seeded.

    Open findings on the public dashboard are left broken on purpose, so the interface has something to show. A count from that branch is not an audit result.

  3. Two audits are not a rate.

    These are the only two full public audits, one in C and one in Go. The other cards are narrower security reports. They do not say how often the method finds things.

  4. Private work is absent.

    Unpatched reports, open disclosures, and client work are not on this page. What you can read is the part that is already public.

The bar

The standard is public.

No reproducer, no finding.

A finding you cannot re-run is an opinion. A person checks each finding before it is published.

Standing offer

One open-source audit a week.

No invoice. No commercial follow-up. The maintainer’s schedule.

Private customer work stays private, so the public record is open source that Proof funds itself. Apply with the repository, and say what worries you. If a release is coming, say when.

A small example you can rerun

The public investigations above concern real projects. This separate teaching fixture deliberately introduces a retention defect, executes the checks and preserves the failing result. Download the inputs and Proof packages to inspect what is established and what remains unassessed.

Inspect the executed example → · Explore a historical Omarchy review →