Each Benchmark version comes with a spreadsheet that lists every test case, the vulnerability category, the CWE number, and the expected result (true finding/false positive). Look for the file: expectedresults-VERSION#.csv in the project root directory. Every test case is: an HTTP Servlet a true vulnerability or a false positive for a single CWE Release History Version 1.0 of the Benchmark was rel