{
  "schemaVersion": 1,
  "runId": "2026-07-19",
  "runDate": "2026-07-19",
  "pkgxray": {
    "version": "1.0.3",
    "build": "calibration",
    "commit": "250a3b3",
    "node": "v26.0.0",
    "command": "pkgxray guard npm:<name>@<version> --format json"
  },
  "headline": {
    "packagesScanned": 1301,
    "topThousandFalseBlocks": {
      "count": 1,
      "of": 1000,
      "rate": 0.001
    },
    "knownMalwareCatchRate": {
      "blocked": 18,
      "of": 20,
      "rate": 0.9,
      "passedAsSafe": 0
    }
  },
  "methodologyUrl": "/stats/methodology",
  "reproInputs": "https://github.com/adamsjack711-ux/pkgxray/tree/main/validation/calibration-2026-07-19",
  "corrections": {
    "contact": "https://github.com/adamsjack711-ux/pkgxray/issues (label: calibration)",
    "policy": "Versioned runs are immutable. A corrected number is published as a new dated run; corrections are listed on the page, never silently edited.",
    "log": [
      {
        "date": "2026-07-19",
        "what": "Full 1,000-package scan re-run on the retuned engine; the single pre-retune heuristic false block now resolves to review, with no new false block.",
        "newRun": "2026-07-19-retuned"
      }
    ]
  },
  "notes": "Aggregate calibration of a one-time at-scale static scan. Catch rate is measured against the committed reconstructed known-malware corpus (npm removes live malware, so live recall is untestable). The one top-1000 false block is the as-measured figure that drove the retune; the full scan was not re-run on the fixed engine. See methodology."
}
