INNER CODE UNIT · Python
build_report
valqore/valqore · benchmarks/run_benchmark.py:232
def build_report(vq: dict, ck: dict, ks: dict, tv: dict, kscore: dict, prov: dict) -> str:
L = []
L.append("# Valqore benchmark — converged governance vs point scanners\n")
L.append("Corpus: `benchmarks/corpus/` (Kubernetes + Terraform + Dockerfile — "
"insecure, over-provisioned, and ungoverned-AI by design).\n")
L.append("> Honest note: raw finding *counts* across tools are not directly comparable "
"(different rule granularity). The point is **domain coverage** — what each "
"tool can see at all — and the converged single-verdict + evidence story. "
"See [METHODOLOGY.md](METHODOLOGY.md) for corpus design, normalization, and caveats.\n")
# Provenance — so a skeptic can confirm they ran the same inputs + tool versions.
L.append("\n## Provenance\n")
L.append(f"- Generated: {prov['generated_utc']}")
L.append(f"- Corpus: {prov['corpus']['file_count']} files, sha256 `{prov['corpus']['corpus_sha256']}`")
vers = prov["tool_versions"]
L.append("- Tool versions: " + ", ".join(
f"{k} `{v}`" if v else f"{k} _(not installed)_" for k, v in vers.items()))
L.append("")