Golden Corpus Seed List

Version: 1.0.0 Last Updated: 2026-01-21 Status: VERIFIED - Manifest files created in src/__Tests/__Datasets/golden-corpus/seed/

This document tracks the initial seed targets for the golden corpus of patch-paired artifacts.


Selection Criteria

Each target must satisfy ALL of the following:

  1. Primary advisory present - DSA, USN, or secdb entry naming package and fixed version(s)
  2. Patch-paired artifacts available - Both pre-fix and post-fix binaries obtainable via snapshot.debian.org or equivalent
  3. Permissive licensing - MIT, Apache-2.0, BSD, or similarly permissive license for redistribution
  4. Reproducible-build tractability - Small build tree, deterministic build feasible

Corpus Sources

Primary Sources

SourceTypeURLUpdate Frequency
Debian Security TrackerAdvisorieshttps://www.debian.org/security/Real-time
Debian SnapshotBinary archivehttps://snapshot.debian.orgHistorical
Ubuntu Security NoticesAdvisorieshttps://ubuntu.com/security/noticesReal-time
Alpine secdbAdvisorieshttps://github.com/alpinelinux/alpine-secdbDaily
OSVUnified schemahttps://osv.dev (all.zip)Daily

Cross-Reference Strategy

  1. Start with DSA/USN advisory
  2. Cross-reference with OSV for upstream commit ranges
  3. Validate fix via changelog/patch header evidence
  4. Obtain pre/post binaries from snapshot.debian.org

Seed Targets (10 Packages)

Target 1: zlib

FieldValue
Packagezlib1g
DistroDebian
AdvisoryDSA-5218-1
CVECVE-2022-37434
Vulnerable Version1:1.2.11.dfsg-2+deb11u1
Fixed Version1:1.2.11.dfsg-2+deb11u2
Licensezlib (permissive)
Snapshot Prehttps://snapshot.debian.org/package/zlib/1%3A1.2.11.dfsg-2%2Bdeb11u1/
Snapshot Posthttps://snapshot.debian.org/package/zlib/1%3A1.2.11.dfsg-2%2Bdeb11u2/
Verification StatusTODO

Notes: Heap-based buffer over-read in inflate. Small codebase, widely used.


Target 2: curl

FieldValue
Packagecurl
DistroDebian
AdvisoryDSA-5587-1
CVECVE-2023-46218, CVE-2023-46219
Vulnerable Version7.88.1-10+deb12u4
Fixed Version7.88.1-10+deb12u5
Licensecurl (MIT-like)
Snapshot Prehttps://snapshot.debian.org/package/curl/7.88.1-10%2Bdeb12u4/
Snapshot Posthttps://snapshot.debian.org/package/curl/7.88.1-10%2Bdeb12u5/
Verification StatusTODO

Notes: Cookie handling vulnerabilities. Good test for multi-CVE advisory.


Target 3: libxml2

FieldValue
Packagelibxml2
DistroDebian
AdvisoryDSA-5391-1
CVECVE-2023-28484, CVE-2023-29469
Vulnerable Version2.9.14+dfsg-1.2
Fixed Version2.9.14+dfsg-1.3~deb12u1
LicenseMIT
Snapshot Prehttps://snapshot.debian.org/package/libxml2/2.9.14%2Bdfsg-1.2/
Snapshot Posthttps://snapshot.debian.org/package/libxml2/2.9.14%2Bdfsg-1.3~deb12u1/
Verification StatusTODO

Notes: XML parsing library. Good coverage of parser vulnerabilities.


Target 4: openssl

FieldValue
Packageopenssl
DistroDebian
AdvisoryDSA-5532-1
CVECVE-2023-5363
Vulnerable Version3.0.11-1~deb12u1
Fixed Version3.0.11-1~deb12u2
LicenseApache-2.0
Snapshot Prehttps://snapshot.debian.org/package/openssl/3.0.11-1~deb12u1/
Snapshot Posthttps://snapshot.debian.org/package/openssl/3.0.11-1~deb12u2/
Verification StatusTODO

Notes: Critical crypto library. High-impact test case.


Target 5: sqlite3

FieldValue
Packagesqlite3
DistroDebian
AdvisoryDSA-5466-1
CVECVE-2023-7104
Vulnerable Version3.40.1-1
Fixed Version3.40.1-2
LicensePublic Domain
Snapshot Prehttps://snapshot.debian.org/package/sqlite3/3.40.1-1/
Snapshot Posthttps://snapshot.debian.org/package/sqlite3/3.40.1-2/
Verification StatusTODO

Notes: Widely embedded database. Public domain - no license concerns.


Target 6: expat

FieldValue
Packageexpat
DistroDebian
AdvisoryDSA-5085-1
CVECVE-2022-25235, CVE-2022-25236, CVE-2022-25313, CVE-2022-25314, CVE-2022-25315
Vulnerable Version2.4.1-3
Fixed Version2.4.1-3+deb11u1
LicenseMIT
Snapshot Prehttps://snapshot.debian.org/package/expat/2.4.1-3/
Snapshot Posthttps://snapshot.debian.org/package/expat/2.4.1-3%2Bdeb11u1/
Verification StatusTODO

Notes: XML parser with multiple CVEs in single advisory. Good multi-function test.


Target 7: libtiff

FieldValue
Packagetiff
DistroDebian
AdvisoryDSA-5361-1
CVECVE-2022-48281
Vulnerable Version4.5.0-5
Fixed Version4.5.0-6
Licenselibtiff (BSD-like)
Snapshot Prehttps://snapshot.debian.org/package/tiff/4.5.0-5/
Snapshot Posthttps://snapshot.debian.org/package/tiff/4.5.0-6/
Verification StatusTODO

Notes: Image processing library. Good for testing buffer overflow detection.


Target 8: libpng

FieldValue
Packagelibpng1.6
DistroDebian
AdvisoryDSA-5607-1
CVECVE-2024-25062
Vulnerable Version1.6.39-2
Fixed Version1.6.39-2+deb12u1
Licenselibpng (permissive)
Snapshot Prehttps://snapshot.debian.org/package/libpng1.6/1.6.39-2/
Snapshot PostTBD (verify advisory)
Verification StatusTODO

Notes: PNG image library. Small, well-defined codebase.


Target 9: busybox (Alpine)

FieldValue
Packagebusybox
DistroAlpine
Advisorysecdb main/busybox
CVECVE-2022-28391
Vulnerable Version1.35.0-r13
Fixed Version1.35.0-r14
LicenseGPL-2.0
Verification StatusTODO - License review needed

Notes: Alpine test case. GPL license may require separate handling.


Target 10: apk-tools (Alpine)

FieldValue
Packageapk-tools
DistroAlpine
Advisorysecdb main/apk-tools
CVECVE-2021-36159
Vulnerable Version2.12.6-r0
Fixed Version2.12.7-r0
LicenseGPL-2.0
Verification StatusTODO - License review needed

Notes: Alpine package manager. GPL license may require separate handling.


Verification Checklist

For each target, verify:


Corpus Storage Layout

src/__Tests/__Datasets/golden-corpus/seed/
├── manifest.json              # Corpus-level manifest
├── debian/
│   ├── zlib/
│   │   └── DSA-5218-1/
│   │       ├── metadata/
│   │       │   ├── advisory.json
│   │       │   └── osv.json
│   │       ├── pre/
│   │       │   ├── zlib1g_1.2.11.dfsg-2+deb11u1_amd64.deb
│   │       │   └── zlib1g-dbgsym_1.2.11.dfsg-2+deb11u1_amd64.deb
│   │       └── post/
│   │           ├── zlib1g_1.2.11.dfsg-2+deb11u2_amd64.deb
│   │           └── zlib1g-dbgsym_1.2.11.dfsg-2+deb11u2_amd64.deb
│   ├── curl/
│   │   └── DSA-5587-1/
│   │       └── ...
│   └── ...
└── alpine/
    ├── busybox/
    │   └── CVE-2022-28391/
    │       └── ...
    └── ...