JevとCodeGraphによるセキュリティレビュー
typesafe-security-reviewプロジェクトは、Jevの確率判断をコードグラフやOWASP/CWEデータと組み合わせ、低コストのセキュリティスキャンに使います。
この投稿は、Jev モデルがセキュリティ質問票の応答分類(実装済み/該当なし/未実装)において、Claude と比較して、より正確な結果を得るために調整が必要だったことを述べています。
#Jev security questionnaire response categorization (implemented, N/A, not implemented) given the question+response then a ground truth eval. - Claude initially performed better with little direction - Jev questions needed tuning to provide a more accurate response. Once tuned,