Skip to main content

ssebench

The command-line tool of SSEBench, a benchmark that measures how well AI coding agents fix real security vulnerabilities.

Every task is a publicly disclosed bug in an open-source C, Go or Rust project, paired with its upstream fix. ssebench builds a Docker image for a task, runs one agent with one model on it, and grades the patch the agent leaves behind: does the project still build, does the proof of concept stop reproducing, and do the project's tests pass. The pilot dataset has 55 tasks.

Install and run

ssebench needs Docker with the buildx and Compose plugins, and Python 3.12 or newer. It runs without a clone of the repository: the wheel carries the agent definitions, the model list, the Compose file and the pilot manifest, and the task images are pulled from the registry.

mkdir ssebench-work && cd ssebench-work
uvx ssebench init          # writes .env with generated secrets, models/ and results/
uvx ssebench doctor        # checks Docker, disk space and .env
uvx ssebench tasks list    # the 55 tasks of the pilot dataset

# The reference agent applies the task's known fix, so it needs no API key.
uvx ssebench run --task gjson-196-bf4efcb --agent reference

# A real agent needs the key of its model provider in .env.
uvx ssebench run --task gjson-196-bf4efcb --agent claude-code --model claude-sonnet-4-6

Install it with pip install ssebench or uv tool install ssebench instead of uvx to keep the command. Run it from the directory that ssebench init set up: that directory holds .env and models/, and results/ is written there.

The first run of a task pulls its case image and builds the tool and agent layers on top of it, which takes a few minutes. The results are in results/<task>/<model>/<agent>/<run-id>/, a directory of its own for each run.

Versions

SSEBench components are released together under one version. ssebench pulls the runtime image with the same version, and the SDK inside the task container, ssebench-sdk, has the same version too.

More

Licensed under the Apache License 2.0.

Metadata

Release files for ssebench 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ssebench 1.0.0
File Size Uploaded
ssebench-1.0.0.tar.gz 361.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ssebench 1.0.0
File Interpreter ABI Platform
ssebench-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 790.5 kB

Release files / ssebench-1.0.0.tar.gz

Download URL ssebench-1.0.0.tar.gz
Size 361.9 kB
Tags Source
SHA-256 checksum
How to use checksums
add1057deb8cb0b09c54cd01a9dd5499a01a7a81863908780ab914f111b179d1
BLAKE2b-256 checksum
How to use checksums
e053f49d3a70cdbd67277f4d40c4c3cec12788212fde869652b6eaff17a80375
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / ssebench-1.0.0-py3-none-any.whl

Download URL ssebench-1.0.0-py3-none-any.whl
Size 428.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7c86a5ce89b9061cb7af322568dbe4a3d6aad9ee4bc022e3be889741b233d971
BLAKE2b-256 checksum
How to use checksums
816579e1087b62aad2aaa55dfc5184f4cd079385152191c82b5492b1e6202676
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release history Release notifications | RSS feed

1.1.0

2 release files

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page