ssebench
The command-line tool of SSEBench, a benchmark that measures how well AI coding agents fix real security vulnerabilities.
Every task is a publicly disclosed bug in an open-source C, Go or Rust project,
paired with its upstream fix. ssebench builds a Docker image for a task, runs
one agent with one model on it, and grades the patch the agent leaves behind:
does the project still build, does the proof of concept stop reproducing, and
do the project's tests pass. The pilot dataset has 55 tasks.
Install and run
ssebench needs Docker with the buildx and Compose plugins, and Python 3.12 or
newer. It runs without a clone of the repository: the wheel carries the agent
definitions, the model list, the Compose file and the pilot manifest, and the
task images are pulled from the registry.
mkdir ssebench-work && cd ssebench-work
uvx ssebench init # writes .env with generated secrets, models/ and results/
uvx ssebench doctor # checks Docker, disk space and .env
uvx ssebench tasks list # the 55 tasks of the pilot dataset
# The reference agent applies the task's known fix, so it needs no API key.
uvx ssebench run --task gjson-196-bf4efcb --agent reference
# A real agent needs the key of its model provider in .env.
uvx ssebench run --task gjson-196-bf4efcb --agent claude-code --model claude-sonnet-4-6
Install it with pip install ssebench or uv tool install ssebench instead of
uvx to keep the command. Run it from the directory that ssebench init set
up: that directory holds .env and models/, and results/ is written there.
The first run of a task pulls its case image and builds the tool and agent
layers on top of it, which takes a few minutes. The results are in
results/<task>/<model>/<agent>/<run-id>/, a directory of its own for each run.
Versions
SSEBench components are released together under one version. ssebench pulls
the runtime image with the same version, and the SDK inside the task
container, ssebench-sdk, has the same version too.
More
Licensed under the Apache License 2.0.
Metadata
Release files for ssebench 1.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ssebench-1.1.0.tar.gz | 372.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ssebench-1.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 811.9 kB
Release files / ssebench-1.1.0.tar.gz
| Download URL | ssebench-1.1.0.tar.gz |
|---|---|
| Size | 372.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
190658bba6c49e160f05b9069d8b2b9a597592c002d64965836f8985b1b7c236
|
|
BLAKE2b-256 checksum How to use checksums |
30f11d1f68a366e4263898416988006a6c903ae8c82e50332370bd4226fa1cf2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency logRelease files / ssebench-1.1.0-py3-none-any.whl
| Download URL | ssebench-1.1.0-py3-none-any.whl |
|---|---|
| Size | 439.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6a13c8c4791e6c0e6f57c79498c44c76e546657706a6d26d44d1f0138229feb9
|
|
BLAKE2b-256 checksum How to use checksums |
1fab4b7f4604015c6683341dc74c159fe383239795463b011308a27cff093755
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency log