{
  "campaign": "JRS mined regression-pair recall",
  "updated_utc": "2026-07-23",
  "headline": "628/938 maintainer-adjudicated regressions detected at the introducing PR",
  "method": "Run the shipped jrs:java-review-agent finders on the diff that INTRODUCED a bug, score recall against the defect the maintainers' later fix PR proves. Finders-only (upper-bound recall). 0 fabrications across all runs. Finder model is per-pair (see finder_model field) \u2014 batches 1\u20137 Opus 4.8 (n=1\u201370), batches 8+ Grok 4.5 (n=71+); see finder_model per pair (Grok 4.5 n=817, Opus 4.8 n=70, Opus 5 n=51). Scoring regime is also per-pair (scoring field): 'self-scored' segments (n=71\u2013220, 291\u2013370) were scored by the mining orchestrator with the fix PR open and are pending blind re-audit \u2014 the one sampled window of that regime dropped 23% on blind re-score; n=221\u2013290 is blind-rescored; n\u2265371 is quote-backed (bank_mined_pair.py, scored_blind); n=531+ re-ran under the second-pass / Layer B surface_complete finder prompt. Treat the headline as a mixed-method upper bound, not one measurement. Recent hard-gate rate window n=781\u2013880 (batches 80\u201389): 42/99 (42%). Miss postmortem: mining/ledgers/batch80-89-miss-postmortem-2026-07-23.md (adjacent-target dominant; empty minority). Soft shortlist R9 multi-sibling/dual-path.",
  "total": 938,
  "hits": 628,
  "misses": 310,
  "pairs": [
    {
      "n": 1,
      "batch": "n=1-10 (2026-07-16/17)",
      "repo": "apache/pulsar",
      "key": "pulsar-24784",
      "introducing_pr": 24784,
      "fixing_pr": 26045,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "under-rated LOW",
      "defect": "PulsarClientImpl.shutdown() closes addressResolver + dnsResolverGroupLocalInstance UNGUARDED; a throw from either (the fix's test simulates AddressResolver.close() throwing 'channel not registered to an event loop', a real Netty shutdown ra",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 2,
      "batch": "n=1-10 (2026-07-16/17)",
      "repo": "apache/pulsar",
      "key": "pulsar-21798",
      "introducing_pr": 21798,
      "fixing_pr": 24512,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "PersistentTopicsBase.internalGetDelayedDeliveryPolicies (introducing tree line 908) builds a DelayedDeliveryPolicies from a persisted TopicPolicies: it calls .maxDeliveryDelayInMillis(policies.getDelayedDeliveryMaxDelayInMillis()) where Top",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 3,
      "batch": "n=1-10 (2026-07-16/17)",
      "repo": "apache/pulsar",
      "key": "pulsar-24533",
      "introducing_pr": 24533,
      "fixing_pr": 24593,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "under-rated LOW",
      "defect": "In ServerCnx.isTopicOperationAllowed (introducing tree lines 480-482), #24533 replaced a two-part proxy authorization (isProxyAuthorizedFuture on the original principal .thenCombine isAuthorizedFuture on the proxy authRole+authDataSource, r",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 4,
      "batch": "n=1-10 (2026-07-16/17)",
      "repo": "apache/pulsar",
      "key": "pulsar-25352",
      "introducing_pr": 25352,
      "fixing_pr": 25460,
      "lane": "concurrency",
      "review_grade": "C",
      "result": "MISS",
      "severity_or_note": "",
      "defect": "The async-ification in #25352 DELAYS the producer-creation callbacks. When a client-side createProducer times out, the client sends CloseProducer then a RETRY createProducer with the SAME producerId. The fix PR's own race table: 'The delaye",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 5,
      "batch": "n=1-10 (2026-07-16/17)",
      "repo": "netty/netty",
      "key": "netty-12709",
      "introducing_pr": 12709,
      "fixing_pr": 12762,
      "lane": "correctness",
      "review_grade": "C",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#12709 removed the generic post-encode release that MessageToMessageEncoder.write() provided. HttpClientCodec.Encoder.encode (UNCHANGED file, HttpClientCodec.java:194) still does out.add(ReferenceCountUtil.retain(msg)); return; in its `upgr",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 6,
      "batch": "n=1-10 (2026-07-16/17)",
      "repo": "apache/pulsar",
      "key": "pulsar-22908",
      "introducing_pr": 22908,
      "fixing_pr": 22966,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ConcurrentRoaringBitSet's read methods (get, nextSetBit, ...) use rwLock.tryOptimisticRead() and call super.<read>() on the RoaringBitmap with NO lock held, concurrently with a writer holding writeLock. This optimistic-read pattern is safe ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 7,
      "batch": "n=1-10 (2026-07-16/17)",
      "repo": "apache/pulsar",
      "key": "pulsar-25984",
      "introducing_pr": 25984,
      "fixing_pr": 26080,
      "lane": "data",
      "review_grade": "C",
      "result": "MISS",
      "severity_or_note": "off-target (found deeper)",
      "defect": "THE RECALL TARGET (what #26080 fixed): nextDeliveryTime() falls through to lastMutableBucket.nextDeliveryTime()/sharedBucketPriorityQueue.peekN1() when both queues are empty (which #25984's trimming can produce while numberDelayedMessages>0",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 8,
      "batch": "n=1-10 (2026-07-16/17)",
      "repo": "apache/pulsar",
      "key": "pulsar-25087",
      "introducing_pr": 25087,
      "fixing_pr": 25110,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#25087 replaced an in-memory-only cursor-tracking reset with a real cursor.asyncMarkDelete(lastAckedPosition, cursor.getProperties(), ...) \u2014 but lastAckedPosition is derived from getPersistentMarkDeletedPosition() (which routinely LAGS the ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 9,
      "batch": "n=1-10 (2026-07-16/17)",
      "repo": "netty/netty",
      "key": "netty-15165",
      "introducing_pr": 15165,
      "fixing_pr": 15391,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "The added AdaptiveByteBuf.setCharSequence override guards with checkIndex(index, sequence.length()) \u2014 a CHAR count \u2014 then delegates the write to rootParent().setCharSequence(idx(index), ...), where the byte-length bounds check runs against ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 10,
      "batch": "n=1-10 (2026-07-16/17)",
      "repo": "apache/pulsar",
      "key": "pulsar-20990",
      "introducing_pr": 20990,
      "fixing_pr": 23796,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "target miss; defect-level hit #21126",
      "defect": "#20990's added conditional runs removePendingAcks (whose unblock check reads the unacked count) BEFORE addAndGetUnAckedMsgs decrements it, and gates the decrement on its return; with maxUnackedMessagesPerConsumer=1 the consumer stays blocke",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 11,
      "batch": "n=11-20 (2026-07-18)",
      "repo": "apache/pulsar",
      "key": "pulsar-22411",
      "introducing_pr": 22411,
      "fixing_pr": 25434,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "",
      "defect": "#22411 MOVED the optimistic-concurrency version snapshot 'final Stat lastCursorLedgerStat = this.cursorLedgerStat' from BEFORE updateFunction.apply(cursorProperties) to AFTER building the update copy (just before asyncUpdateCursorInfo). In ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 12,
      "batch": "n=11-20 (2026-07-18)",
      "repo": "netty/netty",
      "key": "netty-8939",
      "introducing_pr": 8939,
      "fixing_pr": 10247,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "",
      "defect": "addFlattenedComponents does 'final CompositeByteBuf from = (CompositeByteBuf) buffer;' and reads from's internal components. A WrappedCompositeByteBuf IS-A CompositeByteBuf (cast succeeds) but is a delegating wrapper whose own component arr",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 13,
      "batch": "n=11-20 (2026-07-18)",
      "repo": "netty/netty",
      "key": "netty-17007",
      "introducing_pr": 17007,
      "fixing_pr": 17074,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "weak target",
      "defect": "#17007's cached(String) does TWO passes over the input: (1) new AsciiString(string) internally converts every char to a byte (a full scan), then (2) an added explicit for-loop scans the whole string again to detect any char > MAX_CHAR_VALUE",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 14,
      "batch": "n=11-20 (2026-07-18)",
      "repo": "elastic/elasticsearch",
      "key": "es-105718",
      "introducing_pr": 105718,
      "fixing_pr": 136649,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "",
      "defect": "With allow_duplicates:false, appending a value that is already present (a no-op de-dup) still UPCASTS the existing scalar field into a single-element list, even though nothing changed. Correct behavior: leave the field as a scalar when the ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 15,
      "batch": "n=11-20 (2026-07-18)",
      "repo": "apache/pulsar",
      "key": "pulsar-16234",
      "introducing_pr": 16234,
      "fixing_pr": 18816,
      "lane": "correctness",
      "review_grade": "C",
      "result": "MISS",
      "severity_or_note": "near",
      "defect": "convertFrom() drops configuration data: it builds a NEW empty Properties from unknown DECLARED FIELDS only and never copies the source config's own getProperties() bag (properties loaded from the .conf file / set at runtime that are not dec",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 16,
      "batch": "n=11-20 (2026-07-18)",
      "repo": "apache/pulsar",
      "key": "pulsar-22521",
      "introducing_pr": 22521,
      "fixing_pr": 22576,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "under-rated LOW",
      "defect": "The hand-rolled Deflater loop + gzip framing in GzipByteBufferWriter mishandles buffer-full / finish boundaries: BufferOverflowException (the compressed output / 8-byte footer overruns the current buffer when the deflate output spans buffer",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 17,
      "batch": "n=11-20 (2026-07-18)",
      "repo": "apache/pulsar",
      "key": "pulsar-22789",
      "introducing_pr": 22789,
      "fixing_pr": 23903,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "getValue() guards the get() path with a REFERENCE comparison `if (valueWrapper.getKey() != key) return null;` (line 214). Correct for the getRange/removeEntry callers (they pass the map's own stored key reference) but WRONG for get(Key), wh",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 18,
      "batch": "n=11-20 (2026-07-18)",
      "repo": "apache/pulsar",
      "key": "pulsar-20158",
      "introducing_pr": 20158,
      "fixing_pr": 20170,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#20158's parse paths call ledgerEntry.getEntryBuffer() (returns the pooled direct ByteBuf, transfers no ownership) but never release() it, unlike the prior getEntry() which copied+released. A pooled direct-memory ByteBuf leaks on every snap",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 19,
      "batch": "n=11-20 (2026-07-18)",
      "repo": "elastic/elasticsearch",
      "key": "es-152748",
      "introducing_pr": 152748,
      "fixing_pr": 153584,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Math.clamp(value, min, max) requires min <= max; here min=4096, max=n, so when the vector count n < 4096 it throws IllegalArgumentException. The old Math.min(n, Math.max(...)) returned n in that case (capping the sample at corpus size). Rea",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 20,
      "batch": "n=11-20 (2026-07-18)",
      "repo": "netty/netty",
      "key": "netty-15533",
      "introducing_pr": 15533,
      "fixing_pr": 15630,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Reflecting BC SSLEngine ALPN methods against engine.getClass() (BouncyCastle's package-private impl, e.g. ProvSSLEngine) instead of the public BCSSLEngine interface: Method.invoke on a public method whose declaring class is non-public throw",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 21,
      "batch": "n=21-30 (2026-07-18)",
      "repo": "apache/druid",
      "key": "druid-17170",
      "introducing_pr": 17170,
      "fixing_pr": 19484,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "SinkQuerySegmentWalker.java line ~538: switch(metricName) over three cases has NO break statements => fall-through. The outer loop binds reportMetric.getValue() to one consumer per metricName; each consumer does metrics.put(name, value) (la",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 22,
      "batch": "n=21-30 (2026-07-18)",
      "repo": "apache/pulsar",
      "key": "pulsar-13157",
      "introducing_pr": 13157,
      "fixing_pr": 13463,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "The added validateNamespacePolicyOperation(...) is NOT equivalent to validateSuperUserAccess(): under the shipped default PulsarAuthorizationProvider it resolves to validateTenantAdminAccess(tenant), so any authenticated tenant admin now pa",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 23,
      "batch": "n=21-30 (2026-07-18)",
      "repo": "elastic/elasticsearch",
      "key": "es-138489",
      "introducing_pr": 138489,
      "fixing_pr": 139510,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "The live IndexService MapperService and the cluster-state IndexMetadata are updated NON-ATOMICALLY as cluster state is applied. The validation thread reads the live DocumentMapper while validating a (possibly different-version) IndexMetadat",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 24,
      "batch": "n=21-30 (2026-07-18)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-48153",
      "introducing_pr": 48153,
      "fixing_pr": 48393,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "DefaultTokenStateManager.java:84 appends the raw space-delimited access-token scope into the session cookie value, but the read path decodes it (base64UrlDecode), so under the supported token-state-manager.encryption-required=false a scope ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 25,
      "batch": "n=21-30 (2026-07-18)",
      "repo": "micronaut-projects/micronaut-core",
      "key": "micronaut-7635",
      "introducing_pr": 7635,
      "fixing_pr": 8156,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ConversionService.SHARED is a static final JVM-global shared by every bean context. reset() clears+rebuilds it on every context start/stop; in a multi-context JVM one context's shutdown wipes converters (incl. @PostConstruct-registered Nett",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 26,
      "batch": "n=21-30 (2026-07-18)",
      "repo": "apache/iceberg",
      "key": "iceberg-15297",
      "introducing_pr": 15297,
      "fixing_pr": 15726,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "getProjectedIds() omits list/map CONTAINER field IDs (only element/key/value IDs are added), whereas indexById() records every field ID. So allUsedFieldIds() under-reports used IDs; reassignConflictingIds walks candidate IDs from 1 and can ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 27,
      "batch": "n=21-30 (2026-07-18)",
      "repo": "apache/druid",
      "key": "druid-17394",
      "introducing_pr": 17394,
      "fixing_pr": 17403,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "workerExec is reused as the RPC connectExec. ServiceClientImpl completes response/service-location futures on connectExec, while verifyAndMergeCheckpoints submits per-task-group work to workerExec and then blocks that worker thread in coale",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 28,
      "batch": "n=21-30 (2026-07-18)",
      "repo": "apache/hbase",
      "key": "hbase-3230",
      "introducing_pr": 3230,
      "fixing_pr": 3775,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "",
      "defect": "HbckChore.java:226 -- relying on the in-memory RegionState alone. RegionState.isSplit() == (state == State.SPLIT); after a master restart/failover the in-memory assignment state resets (split parents load as CLOSED, not SPLIT), so isSplit()",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 29,
      "batch": "n=21-30 (2026-07-18)",
      "repo": "apache/ozone",
      "key": "ozone-9322",
      "introducing_pr": 9322,
      "fixing_pr": 9384,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "",
      "defect": "RDBStore.close() calls flushDB() unconditionally, but the store can be opened READ-ONLY; flushing a read-only RocksDB handle is illegal and throws (caught+logged as WARN, so the observable effect is a spurious error on every read-only store",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 30,
      "batch": "n=21-30 (2026-07-18)",
      "repo": "hibernate/hibernate-orm",
      "key": "hibernate-3590",
      "introducing_pr": 3590,
      "fixing_pr": 5261,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "",
      "defect": "The new OneToOneType.isDirty is correct for simple ids but throws IllegalArgumentException for a one-to-one whose target uses an @EmbeddedId (composite id): the identifier-type comparison on the embedded component with a null/other old valu",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 31,
      "batch": "n=31-40 (2026-07-18)",
      "repo": "apache/kafka",
      "key": "kafka-20334",
      "introducing_pr": 20334,
      "fixing_pr": 22269,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "connect/runtime/.../rest/util/SSLUtils.java configureSslContextFactoryAlgorithms: the removed `if (sslCipherSuites != null)` guard (now `if (!sslCipherSuites.isEmpty())`) dereferences sslConfigValues.get(SSL_CIPHER_SUITES_CONFIG), which is ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 32,
      "batch": "n=31-40 (2026-07-18)",
      "repo": "apache/camel",
      "key": "camel-22490",
      "introducing_pr": 22490,
      "fixing_pr": 22801,
      "lane": "security",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.4 slice",
      "defect": "NettyConverter.java + the DEFAULT_DESERIALIZATION_FILTER constant = \"java.**;javax.**;org.apache.camel.**;!*\". The recursive java.** allow admits java.net.URL / java.net.InetAddress (and other network-I/O types) as deserialization gadgets w",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 33,
      "batch": "n=31-40 (2026-07-18)",
      "repo": "apache/iceberg",
      "key": "iceberg-15150",
      "introducing_pr": 15150,
      "fixing_pr": 16521,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "",
      "defect": "SerializableTable.java new sortOrders(): `sortOrderAsJsonMap.forEach((id, json) -> sortOrders.put(id, SortOrderParser.fromJson(schema(), json)))`. fromJson(schema, json) does fromJson(json).bind(schema); binding a HISTORICAL sort order that",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 34,
      "batch": "n=31-40 (2026-07-18)",
      "repo": "apache/flink",
      "key": "flink-27861",
      "introducing_pr": 27861,
      "fixing_pr": 28605,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "LocalInputChannel.checkpointStarted() was changed from startPersisting(id, Collections.emptyList()) to eagerly persisting all recovered toBeConsumedBuffers. Because local channels ALSO persist on consumption (getBufferAndAvailability -> may",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 35,
      "batch": "n=31-40 (2026-07-18)",
      "repo": "apache/hadoop",
      "key": "hadoop-6748",
      "introducing_pr": 6748,
      "fixing_pr": 6772,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "PendingDataNodeMessages.removeQueuedBlock() (line ~111-133) obtains its queue via getBlockQueue(block) (lines 120/122), and getBlockQueue lazily allocates + inserts an empty LinkedList into the persistent queueByBlockId for any absent block",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 36,
      "batch": "n=31-40 (2026-07-18)",
      "repo": "apache/lucene",
      "key": "lucene-15722",
      "introducing_pr": 15722,
      "fixing_pr": 16156,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "OffHeapFloatVectorValues.prefetch (line ~100): loops for(i=0; i<numOrds; i++) reading ordsToPrefetch[i], using the unbounded numOrds instead of the computed clamp finalNumOrds=Math.min(numOrds, ordsToPrefetch.length) -> AIOOBE when numOrds ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 37,
      "batch": "n=31-40 (2026-07-18)",
      "repo": "apache/iceberg",
      "key": "iceberg-13507",
      "introducing_pr": 13507,
      "fixing_pr": 16695,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Tasks.run() with a non-null service takes runParallel: it submits the single task and then blocks the caller in waitFor(futures), which busy-polls Thread.sleep(10) until completion. So report() still blocks the caller for the full HTTP POST",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 38,
      "batch": "n=31-40 (2026-07-18)",
      "repo": "eclipse/jetty.project",
      "key": "jetty-14400",
      "introducing_pr": 14400,
      "fixing_pr": 14524,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ImmutableHttpFields/MutableHttpFields newQuotedCSV/newQuotedQualityCSV overrides call _listenerSupplier.get() with no null guard. _listenerSupplier is null for instances from the public HttpFields.from(HttpField...) factory (2-arg ctor dele",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 39,
      "batch": "n=31-40 (2026-07-18)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-20921",
      "introducing_pr": 20921,
      "fixing_pr": 21830,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "NonClosingReaderWrapper (FilterDirectoryReader) overrides only doClose() (no-op for the delegate) but not close(), so the base close() still sets closed=true. Caching + sharing one instance across searchers means that once one wrapped searc",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 40,
      "batch": "n=31-40 (2026-07-18)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-21305",
      "introducing_pr": 21305,
      "fixing_pr": 21456,
      "lane": "correctness",
      "review_grade": "C",
      "result": "MISS",
      "severity_or_note": "cross-file",
      "defect": "The added `listener.onResponse(null)` completes the replica listener with SUCCESS on the closed-primary path. ReplicationOperation counts that as successful=1, failures=[], so the overall write is acknowledged to the client -- but the stale",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 41,
      "batch": "n=41-50 (2026-07-18)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-2701",
      "introducing_pr": 2701,
      "fixing_pr": 4196,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "DigestManager.computeDigestAndPackageForSending and ByteBufList.add/prepend compute `final ByteBuf unwrapped = data.unwrap() != null && data.unwrap() instanceof CompositeByteBuf ? data.unwrap() : data;` then digest/store the unwrapped buffe",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 42,
      "batch": "n=41-50 (2026-07-18)",
      "repo": "FasterXML/jackson-databind",
      "key": "jackson-5012",
      "introducing_pr": 5012,
      "fixing_pr": 5099,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ObjectNode.with(String) create path was rewritten from `_children.put(exprOrProperty, result); return result;` to `return _put(exprOrProperty, result);`. But _put returns `this` (the parent ObjectNode), not the value it stored. So on the pr",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 43,
      "batch": "n=41-50 (2026-07-18)",
      "repo": "FasterXML/jackson-databind",
      "key": "jackson-4008",
      "introducing_pr": 4008,
      "fixing_pr": 4230,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "The three LIST-returning finders (findValues, findValuesAsText, findParents) were rewritten to `_children.get(propertyName)` and, on a direct hit, add the match and `return foundSoFar;` immediately -- never recursing into the node's OTHER c",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 44,
      "batch": "n=41-50 (2026-07-18)",
      "repo": "apache/cassandra",
      "key": "cassandra-3641",
      "introducing_pr": 3641,
      "fixing_pr": 4096,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "under-rated LOW",
      "defect": "parseAndPrepare unconditionally runs `res.pstmntSize = measurePstmnt(res)` (QueryProcessor.java:475), where measurePstmnt is ObjectSizes.measureDeep -- an expensive deep object-graph walk. Unprepared batches route through parseAndPrepare on",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 45,
      "batch": "n=41-50 (2026-07-18)",
      "repo": "apache/calcite",
      "key": "calcite-688",
      "introducing_pr": 688,
      "fixing_pr": 747,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "",
      "defect": "simplifyAndTerms/simplifyOrTerms (RexSimplify.java) loop over every term and for each perform simplify.predicates.union(...) + withPredicates(...) -- repeated predicate-list unions/rebuilds per term, ~O(n^2) in term count, which drives RelM",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 46,
      "batch": "n=41-50 (2026-07-18)",
      "repo": "apache/solr",
      "key": "solr-3851",
      "introducing_pr": 3851,
      "fixing_pr": 4176,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "",
      "defect": "triggerCollectionRefresh dedups via collectionRefreshes.computeIfAbsent(key, ...). There is a race window between a refresh future COMPLETING and its whenCompleteAsync callback REMOVING it from the map. A second triggerCollectionRefresh in ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 47,
      "batch": "n=41-50 (2026-07-18)",
      "repo": "apache/solr",
      "key": "solr-1501",
      "introducing_pr": 1501,
      "fixing_pr": 3477,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "perSegmentFingerprintCache is a shared field on SolrCore read/written by getIndexFingerprint (get/put/size) on concurrent distributed-search/peersync threads. Guava's MapMaker().makeMap() is a thread-safe ConcurrentMap; the replacement plai",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 48,
      "batch": "n=41-50 (2026-07-18)",
      "repo": "apache/paimon",
      "key": "paimon-7175",
      "introducing_pr": 7175,
      "fixing_pr": 8623,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "For DecimalType precision > 18, ParquetFilters builds the predicate literal via Binary.fromConstantByteArray(decimal.toUnscaledBytes()) -- the MINIMAL-length two's-complement bytes -- but the writer (ParquetRowDataWriter.UnscaledBytesWriter",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 49,
      "batch": "n=41-50 (2026-07-18)",
      "repo": "apache/paimon",
      "key": "paimon-2572",
      "introducing_pr": 2572,
      "fixing_pr": 7906,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "under-rated MEDIUM",
      "defect": "FieldProductAgg.agg() computes the running product with unchecked arithmetic for TINYINT/SMALLINT/INTEGER/BIGINT (e.g. `(int) accumulator * (int) inputField`). A product accumulated across rows overflows the type range and silently WRAPS to",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 50,
      "batch": "n=41-50 (2026-07-18)",
      "repo": "debezium/debezium",
      "key": "debezium-7065",
      "introducing_pr": 7065,
      "fixing_pr": 7606,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "RowIdCodec.encode() loops over all 18 base-64 ROWID chars doing `result = (result << 6) | value` = 18*6 = 108 bits into a 64-bit long, so the high 44 bits (the object#/file# portion of an extended ROWID) are silently dropped; decode() refil",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 51,
      "batch": "n=51-60 (2026-07-19)",
      "repo": "elastic/elasticsearch",
      "key": "es-87735",
      "introducing_pr": 87735,
      "fixing_pr": 88340,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "evidence-bar suppressed as constant-factor",
      "defect": "tierNodesPresent replaced an explicit `for (DiscoveryNode n : nodes) if (allocationAllowed(...)) return true;` loop with `return nodes.stream().anyMatch(...)`, allocating a Spliterator/Stream pipeline + lambda per call on a per-shard alloca",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 52,
      "batch": "n=51-60 (2026-07-19)",
      "repo": "apache/hadoop",
      "key": "hadoop-1932",
      "introducing_pr": 1932,
      "fixing_pr": 3411,
      "lane": "performance",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.5 slice",
      "defect": "ensureCapacity sizes the backing array to EXACTLY `capacity` (the immediate logical need) with no growth headroom on the array itself; the 1.5x term is on the logical length, so for chunked/large appends every append reallocates and re-copi",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 53,
      "batch": "n=51-60 (2026-07-19)",
      "repo": "apache/kafka",
      "key": "kafka-15105",
      "introducing_pr": 15105,
      "fixing_pr": 15393,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH (data+corr caught; perf lane missed WAL drop)",
      "defect": "DirectDBAccessor.put/delete/deleteRange use the WriteOptions-less RocksDB overloads, so RocksDB's default WriteOptions (WAL ENABLED) applies to every single-record state-store write; Kafka Streams deliberately disables the WAL (durability v",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 54,
      "batch": "n=51-60 (2026-07-19)",
      "repo": "apache/lucene",
      "key": "lucene-13199",
      "introducing_pr": 13199,
      "fixing_pr": 13498,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.5 slice",
      "defect": "The PointTree is materialized eagerly in the NumericLeafComparator constructor for every comparator x segment x sort field, even when dynamic pruning never activates and the tree is never used \u2014 moving a lazily-paid cost to an unconditional",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 55,
      "batch": "n=51-60 (2026-07-19)",
      "repo": "netty/netty",
      "key": "netty-14127",
      "introducing_pr": 14127,
      "fixing_pr": 14144,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "SSLEngine.getSSLParameters() returns a defensive COPY; mutating it and discarding it is a no-op, so for SslProvider.JDK the newly-defaulted hostname (endpoint) verification is never applied and clients stay open to certificate MITM despite ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 56,
      "batch": "n=51-60 (2026-07-19)",
      "repo": "apache/httpcomponents-client",
      "key": "httpclient-643",
      "introducing_pr": 643,
      "fixing_pr": 848,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Dropping scheme from the same-authority check means an https->http downgrade to the same host and coinciding effective port is treated as same-origin, so the redirect header-strip is skipped and Authorization/Cookie are forwarded over clear",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 57,
      "batch": "n=51-60 (2026-07-19)",
      "repo": "apache/pulsar",
      "key": "pulsar-25564",
      "introducing_pr": 25564,
      "fixing_pr": 25635,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "handleCommandScalableTopicSubscribe registers a consumer and handleCommandScalableTopicLookup resolves DAG/broker topology with NO authorization check (only connection-level auth), while handleLookup/handleSubscribe/handleProducer all gate ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 58,
      "batch": "n=51-60 (2026-07-19)",
      "repo": "apache/avro",
      "key": "avro-3126",
      "introducing_pr": 3126,
      "fixing_pr": 3537,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "Arrays.compare(byte[]...) compares elements SIGNED (Byte.compare), but the old code and the Avro spec require UNSIGNED (0..255) lexicographic order. Any byte >= 0x80 (all non-ASCII UTF-8, most binary payloads) now sorts BEFORE 0x00-0x7F \u2014 i",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 59,
      "batch": "n=51-60 (2026-07-19)",
      "repo": "apache/orc",
      "key": "orc-581",
      "introducing_pr": 581,
      "fixing_pr": 672,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "parseName treats '.' as a nested-field separator and interprets backtick-quoting, but the writer stores names verbatim -> read/write asymmetry. A stored column named 'col.dot' is silently truncated to 'col' (wrong schema, unfindable column ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 60,
      "batch": "n=51-60 (2026-07-19)",
      "repo": "apache/pulsar",
      "key": "pulsar-26025",
      "introducing_pr": 26025,
      "fixing_pr": 26132,
      "lane": "concurrency",
      "review_grade": "C",
      "result": "HIT",
      "severity_or_note": "MEDIUM (grade-C on-family)",
      "defect": "The reader-close (AlreadyClosedException) branch in readMorePoliciesAsync stayed on the namespace-keyed cleanup (not identity-guarded), so a superseded reader R1's late async close (on the pulsar-client executor, not the per-namespace order",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 61,
      "batch": "n=61-70 (2026-07-19)",
      "repo": "apache/lucene",
      "key": "lucene-13408",
      "introducing_pr": 13408,
      "fixing_pr": 14543,
      "lane": "performance",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "leadCost overwrite buried in a 27-file refactor",
      "defect": "For a conjunction, leadCost must be the min cost() over ALL required clauses (MUST+FILTER) since iteration is led by the cheapest DISI. The intro overwrites the MUST-min with the FILTER-min whenever any FILTER clause exists, discarding a sm",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 62,
      "batch": "n=61-70 (2026-07-19)",
      "repo": "trinodb/trino",
      "key": "trino-15369",
      "introducing_pr": 15369,
      "fixing_pr": 22039,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH (O(n^2) LinkedList.contains hot loop)",
      "defect": "scheduleRequestIfNecessary() runs on hot paths (pollPage() per page consumed, requestComplete() per HTTP response). The added filter does queuedClients.contains(client) on a LinkedList (O(Q)) for each of N allClients entries -> O(N*Q) ~ O(N",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 63,
      "batch": "n=61-70 (2026-07-19)",
      "repo": "apache/druid",
      "key": "druid-2753",
      "introducing_pr": 2753,
      "fixing_pr": 2841,
      "lane": "performance",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "second-order: reorder defeats ConciseSet.add fast-path",
      "defect": "ConciseSet.add() has a fast append path taken only when the added element is greater than the current last. OR-ing the null-rows bitmap in FIRST pushes last to the maximum row id, so every subsequent bitset.add(row) misses the append fast-p",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 64,
      "batch": "n=61-70 (2026-07-19)",
      "repo": "prestodb/presto",
      "key": "presto-21236",
      "introducing_pr": 21236,
      "fixing_pr": 22661,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "fold-quadratic immutable rebuild; perf near-miss (adjacent MEDIUM)",
      "defect": "FilterStatsCalculator folds a large IN (...) list via reduce(), one addDisjunction per element. Because the histogram is immutable, each addDisjunction rebuilds the internal TreeRangeSet from scratch over the growing range set (1,2,...,N) -",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 65,
      "batch": "n=61-70 (2026-07-19)",
      "repo": "apache/cassandra",
      "key": "cassandra-20090",
      "introducing_pr": "f33267c8",
      "fixing_pr": "0b6ae26",
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "assumed-cache: missed uncached 3.0/3.11 isSuper disk read",
      "defect": "On 3.0/3.11 (no role-metadata cache), user.isSuper() reads from disk. The new guard evaluates isSuper() on EVERY DataResource authorization check (unconditional hot path), so every authz call now hits disk. The permissions_validity cache co",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 66,
      "batch": "n=61-70 (2026-07-19)",
      "repo": "netty/netty",
      "key": "netty-13233",
      "introducing_pr": 13233,
      "fixing_pr": 13237,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "BORDERLINE: cleared the cross-thread clobber; 2/3 convergent adjacent",
      "defect": "Cross-thread clobber: an exiting/rescheduling thread's unconditional `executingThread = null` store can land AFTER a concurrent run() on another pool thread has already published itself into executingThread, clobbering it back to null -> in",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 67,
      "batch": "n=61-70 (2026-07-19)",
      "repo": "apache/hbase",
      "key": "hbase-7089",
      "introducing_pr": 7089,
      "fixing_pr": 7107,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL 2/3 blind-convergent (lock-inversion deadlock)",
      "defect": "flush()/close() are synchronized(this) and call internalFlush(), which blocks on CompletableFuture.allOf(toWait).join() while HOLDING the this monitor. The listeners (FutureUtils.addListener/whenComplete) fire on RPC/netty completion thread",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 68,
      "batch": "n=61-70 (2026-07-19)",
      "repo": "apache/parquet-java",
      "key": "parquet-3197",
      "introducing_pr": 3197,
      "fixing_pr": 3576,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM (wire-format charset; data lane perceived+deferred)",
      "defect": "The Variant spec mandates UTF-8; the write path uses StandardCharsets.UTF_8, but the read path decodes with the JVM platform default. On a non-UTF-8-default JVM (JDK<=17, or file.encoding overridden, or LC_ALL=C) multi-byte UTF-8 in previou",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 69,
      "batch": "n=61-70 (2026-07-19)",
      "repo": "apache/parquet-java",
      "key": "parquet-3202",
      "introducing_pr": 3202,
      "fixing_pr": 3626,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "test-trust masking; convergent adjacent appendFloat overrun",
      "defect": "Duplicate-key resolution keeps the LAST-written value (greater offset), whose size can differ from the first occurrence. Because dataSize is accumulated from first-occurrence sizes before/while dedup, when a key is written twice with differ",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 70,
      "batch": "n=61-70 (2026-07-19)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-6912",
      "introducing_pr": 6912,
      "fixing_pr": 50486,
      "lane": "security",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.6 slice",
      "defect": "addChild authorizes requireManage on the PARENT (destination) but performs no manage check on the CHILD being moved. An admin who manages one low-privilege parent group can reparent a highly-privileged group (e.g. realm-admin) under it, inh",
      "finder_model": "Opus 4.8",
      "scoring": "opus-manual",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 71,
      "batch": "n=71-80 (2026-07-20)",
      "repo": "apache/kafka",
      "key": "kafka-20097",
      "introducing_pr": 20097,
      "fixing_pr": 21058,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM (design; perf+corr CLEARED modernization)",
      "defect": "MemberAssignmentImpl unmodifiableMap forces assignor deep-clone on every mutation",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 72,
      "batch": "n=71-80 (2026-07-20)",
      "repo": "apache/pinot",
      "key": "pinot-9667",
      "introducing_pr": 9667,
      "fixing_pr": 9688,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "ArrayDeque\u2192LinkedList BFS queue on star-tree hot path",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 73,
      "batch": "n=71-80 (2026-07-20)",
      "repo": "apache/pulsar",
      "key": "pulsar-23611",
      "introducing_pr": 23611,
      "fixing_pr": 24430,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "getNumberOfDelayedMessages full stream walk on hot path",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 74,
      "batch": "n=71-80 (2026-07-20)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-53885",
      "introducing_pr": 53885,
      "fixing_pr": 55176,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "eager getResource declined as cold-path cost",
      "defect": "eager Class.getResource always evaluated as resolveJarPath arg",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 75,
      "batch": "n=71-80 (2026-07-20)",
      "repo": "apache/pulsar",
      "key": "pulsar-25565",
      "introducing_pr": 25565,
      "fixing_pr": 25618,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "ScalableTopics/Segments admin REST missing authz",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 76,
      "batch": "n=71-80 (2026-07-20)",
      "repo": "apache/camel",
      "key": "camel-24180",
      "introducing_pr": 24180,
      "fixing_pr": 24377,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH 3/3",
      "defect": "jail startsWith without path-segment boundary",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 77,
      "batch": "n=71-80 (2026-07-20)",
      "repo": "hazelcast/hazelcast",
      "key": "hazelcast-25509",
      "introducing_pr": 25509,
      "fixing_pr": 25529,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent CacheLoadAll underpermission; missed wrong-type targets",
      "defect": "Wrong permission types ConfigPermission / SemaphorePermission ACTION_READ",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 78,
      "batch": "n=71-80 (2026-07-20)",
      "repo": "apache/kafka",
      "key": "kafka-16914",
      "introducing_pr": 16914,
      "fixing_pr": 17078,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "CountDownLatch released before setState(RUNNING)",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 79,
      "batch": "n=71-80 (2026-07-20)",
      "repo": "apache/paimon",
      "key": "paimon-7295",
      "introducing_pr": 7295,
      "fixing_pr": 7920,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "empty listFileDirs promotes partitions into recursive orphan delete",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 80,
      "batch": "n=71-80 (2026-07-20)",
      "repo": "apache/iceberg",
      "key": "iceberg-6570",
      "introducing_pr": 6570,
      "fixing_pr": 10069,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "e.getMessage().contains NPE skips checkCommitStatus",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 81,
      "batch": "n=81-90 (2026-07-20)",
      "repo": "apache/pinot",
      "key": "pinot-15641",
      "introducing_pr": 15641,
      "fixing_pr": 16230,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "AdminClient created per offset fetch via try-with-resources in KafkaStreamMetadataProvider.fetchStreamPartitionOffset",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 82,
      "batch": "n=81-90 (2026-07-20)",
      "repo": "apache/pinot",
      "key": "pinot-15335",
      "introducing_pr": 15335,
      "fixing_pr": 18905,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "PooledByteBufAllocatorWithLimits creates new PooledByteBufAllocator per ServerChannel instead of sharing DEFAULT",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 83,
      "batch": "n=81-90 (2026-07-20)",
      "repo": "apache/kafka",
      "key": "kafka-12049",
      "introducing_pr": 12049,
      "fixing_pr": 12365,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent ready() allocs; missed time-under-lock + ProducerRecord pin",
      "defect": "time.milliseconds() under per-partition queue lock in appendNewBatch and AppendCallbacks holds full ProducerRecord",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 84,
      "batch": "n=81-90 (2026-07-20)",
      "repo": "elastic/elasticsearch",
      "key": "es-148833",
      "introducing_pr": 148833,
      "fixing_pr": 148858,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "findLastRecordBoundary default replaced O(1) reverse newline scan with forward per-record ByteArrayInputStream loop (NDJSON regression)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 85,
      "batch": "n=81-90 (2026-07-20)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-45562",
      "introducing_pr": 45562,
      "fixing_pr": 49590,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent hierarchical authz; missed getMembers view-users",
      "defect": "OrganizationGroupResource.getMembers missing auth.users().requireQuery / view-users permission check",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 86,
      "batch": "n=81-90 (2026-07-20)",
      "repo": "apache/camel",
      "key": "camel-19324",
      "introducing_pr": 19324,
      "fixing_pr": 23958,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (empty-roles skip; also CRITICAL no signature verify)",
      "defect": "KeycloakSecurityProcessor only validates token when requiredRoles non-empty; empty defaults accept any non-null token string",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 87,
      "batch": "n=81-90 (2026-07-20)",
      "repo": "apache/knox",
      "key": "knox-876",
      "introducing_pr": 876,
      "fixing_pr": 1039,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent cache/secret-query; missed ignored client_id",
      "defect": "parseFromClientCredentialsFlow ignores client_id; only client_secret/tokenId used so mismatched client_id still authenticates",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 88,
      "batch": "n=81-90 (2026-07-20)",
      "repo": "apache/kafka",
      "key": "kafka-12397",
      "introducing_pr": 12397,
      "fixing_pr": 13167,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Tasks maps dropped Collections.synchronizedSortedMap for plain unsynchronized TreeMap shared StreamThread/StateUpdater",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 89,
      "batch": "n=81-90 (2026-07-20)",
      "repo": "debezium/debezium",
      "key": "debezium-3938",
      "introducing_pr": 3938,
      "fixing_pr": 4298,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "LogMinerQueryBuilder PDB SRC_CON_NAME applied to all OPERATION_CODE including START/COMMIT/ROLLBACK so CDB$ROOT txn boundaries dropped",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 90,
      "batch": "n=81-90 (2026-07-20)",
      "repo": "elastic/elasticsearch",
      "key": "es-145376",
      "introducing_pr": 145376,
      "fixing_pr": 153043,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent empty-array fidelity; missed per-call context flush",
      "defect": "FlattenedFieldArrayContext created and flushed per parseCreateField call instead of document-scoped; array-of-objects offset ordinals wrong",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 91,
      "batch": "n=91-100 (2026-07-20)",
      "repo": "apache/beam",
      "key": "beam-37355",
      "introducing_pr": 37355,
      "fixing_pr": 39310,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM (blind re-score 07-22; was self-scored MISS \u2014 per-call TypeDescriptor cost named)",
      "defect": "newByteBuddyInvoker resolves input/output TypeDescriptors before cache lookup on every call including cache hits",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 92,
      "batch": "n=91-100 (2026-07-20)",
      "repo": "elastic/elasticsearch",
      "key": "es-130857",
      "introducing_pr": 130857,
      "fixing_pr": 138126,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "TransportIndicesStatsAction always calls getSharedRamSizeForShard causing O(N^2) full shard walk even when query-cache stats not requested",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 93,
      "batch": "n=91-100 (2026-07-20)",
      "repo": "apache/knox",
      "key": "knox-1039",
      "introducing_pr": 1039,
      "fixing_pr": 1170,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM (missing client_id fail-open)",
      "defect": "validateClientCredentialsFlow skips client_id match when client_id is null; client_secret alone still authenticates",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 94,
      "batch": "n=91-100 (2026-07-20)",
      "repo": "apache/struts",
      "key": "struts-1592",
      "introducing_pr": 1592,
      "fixing_pr": 1690,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "methodSpecified=true for wildcard methods makes HttpMethodInterceptor skip class-level AllowedHttpMethod annotations",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 95,
      "batch": "n=91-100 (2026-07-20)",
      "repo": "netty/netty",
      "key": "netty-7800",
      "introducing_pr": 7800,
      "fixing_pr": 17063,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH 3/3",
      "defect": "CorsHandler getForOrigin uses || for null-origin check allowing Origin:null when isNullOriginAllowed is false (should be &&)",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 96,
      "batch": "n=91-100 (2026-07-20)",
      "repo": "apache/kafka",
      "key": "kafka-17957",
      "introducing_pr": 17957,
      "fixing_pr": 18053,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.7 slice",
      "defect": "SharePartition completes CompletableFuture while holding writeLock in whenComplete (deadlock risk)",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 97,
      "batch": "n=91-100 (2026-07-20)",
      "repo": "hazelcast/hazelcast",
      "key": "hazelcast-20419",
      "introducing_pr": 20419,
      "fixing_pr": 25700,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "EventListenerCounter shared by map name only races concurrent create/destroy of same-named IMap (assert count>=0 / orphaned counter)",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 98,
      "batch": "n=91-100 (2026-07-20)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-22249",
      "introducing_pr": 22249,
      "fixing_pr": 22358,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "all 3 CLEARED double-close as intentional",
      "defect": "FlightTransportResponse prefetch finally re-reads closed and double-closes Flight stream racing close()",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 99,
      "batch": "n=91-100 (2026-07-20)",
      "repo": "datahub-project/datahub",
      "key": "datahub-17206",
      "introducing_pr": 17206,
      "fixing_pr": 18401,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "getLatestAspects sorts keys then batchGet(new HashSet<>(keys)) erases order for FOR UPDATE deadlocks",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 100,
      "batch": "n=91-100 (2026-07-20)",
      "repo": "apache/druid",
      "key": "druid-18589",
      "introducing_pr": 18589,
      "fixing_pr": 18948,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "found NONE encoding fidelity; missed isNumeric NestedArrayElement",
      "defect": "CompressedNestedDataComplexColumn.isNumeric returns true for NestedArrayElement fall-through",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 101,
      "batch": "n=101-110 (2026-07-20)",
      "repo": "apache/solr",
      "key": "solr-2363",
      "introducing_pr": 2363,
      "fixing_pr": 2463,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (forceUpdateCollection on alias)",
      "defect": "ZkClientClusterStateProvider forceUpdateCollection on every alias request after missing CollectionRef; aliases never resolve via getCollectionRef so every alias forces ZK refresh",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 102,
      "batch": "n=101-110 (2026-07-20)",
      "repo": "apache/hbase",
      "key": "hbase-7477",
      "introducing_pr": 7477,
      "fixing_pr": 8353,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent pool/equals; missed Path ctor hot-path cost",
      "defect": "BlockCacheKey(Path) constructor does path.getParent walks and isHFileArchived on every block read hot path",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 103,
      "batch": "n=101-110 (2026-07-20)",
      "repo": "elastic/elasticsearch",
      "key": "es-112173",
      "introducing_pr": 112173,
      "fixing_pr": 112480,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.8 slice",
      "defect": "SourceLoader synthetic write calls advanceToDoc on every storedFieldLoader even when empty O(fields) per synthesize",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 104,
      "batch": "n=101-110 (2026-07-20)",
      "repo": "lettuce-io/lettuce-core",
      "key": "lettuce-2961",
      "introducing_pr": 2961,
      "fixing_pr": 3640,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (per-instance ThreadLocal expunge)",
      "defect": "SharedLock per-instance ThreadLocal threadWriters leaks under connection pooling causing ThreadLocalMap.expungeStaleEntries CPU",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 105,
      "batch": "n=101-110 (2026-07-20)",
      "repo": "apache/flink",
      "key": "flink-18991",
      "introducing_pr": 18991,
      "fixing_pr": 19398,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM (unconditional mailbox latency probe)",
      "defect": "Unconditional scheduleMailboxMetrics/measureMailboxLatency enqueues mailbox work every ~1s even on empty mailboxes",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 106,
      "batch": "n=101-110 (2026-07-20)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-47636",
      "introducing_pr": 47636,
      "fixing_pr": 50961,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (SCIM members missing isAdminUser)",
      "defect": "SCIM group members adder/remover checkRequireManageGroupMembership missing isAdminUser so admin-role users can be mutated via Groups PATCH",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 107,
      "batch": "n=101-110 (2026-07-20)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-25647",
      "introducing_pr": 25647,
      "fixing_pr": 50026,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (SecureRedirectUris skips AUTHORIZATION_REQUEST)",
      "defect": "SecureRedirectUrisEnforcerExecutor only handles REGISTER/UPDATE/PRE_AUTHORIZATION_REQUEST not AUTHORIZATION_REQUEST so secure redirect checks skip on real auth requests",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 108,
      "batch": "n=101-110 (2026-07-20)",
      "repo": "apache/nifi",
      "key": "nifi-10393",
      "introducing_pr": 10393,
      "fixing_pr": 11179,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (registry verify READ-only)",
      "defect": "Registry client config verification authorized with READ only instead of WRITE plus CS READ via AuthorizeConfigVerification",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 109,
      "batch": "n=101-110 (2026-07-20)",
      "repo": "apache/struts",
      "key": "struts-1674",
      "introducing_pr": 1674,
      "fixing_pr": 1774,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH (Jackson creator bypasses @StrutsParameter)",
      "defect": "@StrutsParameter enforcement on setter/field path does not cover Jackson creator-bound constructor parameters",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 110,
      "batch": "n=101-110 (2026-07-20)",
      "repo": "netty/netty",
      "key": "netty-16053",
      "introducing_pr": 16053,
      "fixing_pr": 16767,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL (BuddyChunk.remainingCapacity freeList drain)",
      "defect": "BuddyChunk.remainingCapacity drains freeList mutating buddies as side effect of capacity query under concurrent allocate",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 111,
      "batch": "n=111-120 (2026-07-20)",
      "repo": "elastic/elasticsearch",
      "key": "es-149926",
      "introducing_pr": 149926,
      "fixing_pr": 152838,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (hasNext threshold before rowsRemaining)",
      "defect": "OptimizedParquetColumnIterator.hasNext checks dynamicThreshold.noFurtherCandidates before serving already-materialized rowsRemainingInGroup causing race NSE",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 112,
      "batch": "n=111-120 (2026-07-20)",
      "repo": "apache/pulsar",
      "key": "pulsar-24363",
      "introducing_pr": 24363,
      "fixing_pr": 25988,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (updateAndGet null wipe eviction marker)",
      "defect": "triggerEvictionWhenNeeded updateAndGet returns null for losers which stores null wiping owner in-progress eviction marker",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 113,
      "batch": "n=111-120 (2026-07-20)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-21756",
      "introducing_pr": 21756,
      "fixing_pr": 21771,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL (SEARCH pool self-deadlock)",
      "defect": "reduce stage and fragment execution both use SEARCH thread pool causing self-deadlock",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 114,
      "batch": "n=111-120 (2026-07-20)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-4730",
      "introducing_pr": 4730,
      "fixing_pr": 4830,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "CRITICAL (async listener + maxReads default deadlock)",
      "defect": "read-path deadlock from async ChannelFutureListener plus maxReadsInProgressLimit default change",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 115,
      "batch": "n=111-120 (2026-07-20)",
      "repo": "apache/iceberg",
      "key": "iceberg-12105",
      "introducing_pr": 12105,
      "fixing_pr": 15087,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL (shreddedFields shadow data loss)",
      "defect": "local variable shreddedFields shadows instance field causing permanent data loss of unshredded fields",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 116,
      "batch": "n=111-120 (2026-07-20)",
      "repo": "apache/iceberg",
      "key": "iceberg-13302",
      "introducing_pr": 13302,
      "fixing_pr": 16324,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL (ListMetadataFiles no table.refresh)",
      "defect": "ListMetadataFiles never table.refresh so snapshots after open missing from referenced set orphan-deletes live metadata",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 117,
      "batch": "n=111-120 (2026-07-20)",
      "repo": "debezium/debezium",
      "key": "debezium-6726",
      "introducing_pr": 6726,
      "fixing_pr": 6791,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "CRITICAL (LOB eventIndex skip drops events)",
      "defect": "TransactionCommitConsumer eventIndex LOB skip regression DBZ-8060 loses events",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 118,
      "batch": "n=111-120 (2026-07-20)",
      "repo": "apache/hbase",
      "key": "hbase-3786",
      "introducing_pr": 3786,
      "fixing_pr": 6308,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL (BrokenStoreFileCleaner region-close race)",
      "defect": "BrokenStoreFileCleaner may delete live files during region close race without isAvailable guard",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 119,
      "batch": "n=111-120 (2026-07-20)",
      "repo": "apache/zookeeper",
      "key": "zookeeper-2152",
      "introducing_pr": 2152,
      "fixing_pr": 2254,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "CRITICAL (processTxn skips committedLog)",
      "defect": "Learner processTxn path leaves committedLog untouched causing data loss after ZOOKEEPER-4394",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 120,
      "batch": "n=111-120 (2026-07-20)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-35899",
      "introducing_pr": 35899,
      "fixing_pr": 50451,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH (ScopeMapped missing requireMapClientScope)",
      "defect": "ScopeMappedResource add/delete missing requireMapClientScope after FGAP role scopes shipped",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 121,
      "batch": "n=121-130 (2026-07-20)",
      "repo": "elastic/elasticsearch",
      "key": "es-150052",
      "introducing_pr": 150052,
      "fixing_pr": 151201,
      "lane": "performance",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "all 3 cleared megamorphic advanceExact as refactor-neutral",
      "defect": "megamorphic advanceExact after #150052; fix reverts/restores monomorphic path",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 122,
      "batch": "n=121-130 (2026-07-20)",
      "repo": "apache/lucene",
      "key": "lucene-13221",
      "introducing_pr": 13221,
      "fixing_pr": 13971,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH (competitive int[] disjunction / lost density gate)",
      "defect": "competitive iterator disjunction cost; fix restores prior competitive path",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 123,
      "batch": "n=121-130 (2026-07-20)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-22319",
      "introducing_pr": 22319,
      "fixing_pr": 22335,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH (correctness; continuous throttle via pending overcount)",
      "defect": "continuous merge throttle; fix reverts #22319",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 124,
      "batch": "n=121-130 (2026-07-20)",
      "repo": "micrometer-metrics/micrometer",
      "key": "micrometer-4857",
      "introducing_pr": 4857,
      "fixing_pr": 5750,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM (remove O(n) under meterMapLock)",
      "defect": "MeterRegistry.remove scans preFilterIdToMeterMap O(n) under meterMapLock",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 125,
      "batch": "n=121-130 (2026-07-20)",
      "repo": "apache/flink",
      "key": "flink-10358",
      "introducing_pr": 10358,
      "fixing_pr": 10529,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "perf cleared bulk-buffer as intentional win; missed alloc regression",
      "defect": "StringValue writeString/readString allocates fresh byte[] per string",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 126,
      "batch": "n=121-130 (2026-07-20)",
      "repo": "redis/jedis",
      "key": "jedis-4504",
      "introducing_pr": 4504,
      "fixing_pr": 4537,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM (TSElement ArrayList thrash on single-value path)",
      "defect": "TSElement single-value ctor always new ArrayList + List storage",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 127,
      "batch": "n=121-130 (2026-07-20)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-2962",
      "introducing_pr": 2962,
      "fixing_pr": 3454,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (correctness; forceWriteMarkerSent per-loop reset)",
      "defect": "forceWriteMarkerSent declared inside while loop so grouping fails open / excess fsyncs",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 128,
      "batch": "n=121-130 (2026-07-20)",
      "repo": "elastic/elasticsearch",
      "key": "es-152050",
      "introducing_pr": 152050,
      "fixing_pr": 152433,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM (lost TermsSortedDocsProducer + disjunction rebuild)",
      "defect": "SegmentOrdinalValuesSource null sorted-docs producer + remapSlots every leaf + no parallel collection",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 129,
      "batch": "n=121-130 (2026-07-20)",
      "repo": "hazelcast/hazelcast",
      "key": "hazelcast-6735",
      "introducing_pr": 6735,
      "fixing_pr": 7045,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM (Externalizable/Enum serializer path loss)",
      "defect": "ExternalizableSerializer removed so Externalizable falls to slow default path",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 130,
      "batch": "n=121-130 (2026-07-20)",
      "repo": "apache/flink",
      "key": "flink-6417",
      "introducing_pr": 6417,
      "fixing_pr": 6833,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM (per-record hasRemaining/mustCommit)",
      "defect": "SpanningRecordSerializer per-record hasRemaining/mustCommit checks on hot path",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 131,
      "batch": "n=131-140 (2026-07-20)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-49344",
      "introducing_pr": 49344,
      "fixing_pr": 50729,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (blank authenticatorAttachment early-return)",
      "defect": "PolicyVerifier.verifyAuthenticatorAttachment early-returns when attachment blank so policy skipped",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 132,
      "batch": "n=131-140 (2026-07-20)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-41688",
      "introducing_pr": 41688,
      "fixing_pr": 48729,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (self-signed x5c skips PKIX)",
      "defect": "verifierFromX5CChain skips PKIX when x5c[0] self-signed (no runtime test gate)",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 133,
      "batch": "n=131-140 (2026-07-20)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-46811",
      "introducing_pr": 46811,
      "fixing_pr": 47616,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (SCIM groups missing membership authz)",
      "defect": "SCIM User groups attribute joinGroup/leaveGroup without manage-group-membership authz",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 134,
      "batch": "n=131-140 (2026-07-20)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-47632",
      "introducing_pr": 47632,
      "fixing_pr": 50567,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (AuthZEN any bearer token)",
      "defect": "AuthZEN Evaluation API accepts any valid bearer token including user tokens",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 135,
      "batch": "n=131-140 (2026-07-20)",
      "repo": "apache/cxf",
      "key": "cxf-3154",
      "introducing_pr": 3154,
      "fixing_pr": 3256,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (correctness; ProxySelector without doPrivileged)",
      "defect": "ProxyFactory.getSystemProxy calls ProxySelector.getDefault without doPrivileged",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 136,
      "batch": "n=131-140 (2026-07-20)",
      "repo": "apache/dubbo",
      "key": "dubbo-15352",
      "introducing_pr": 15352,
      "fixing_pr": 16374,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (AuthPolicy.NONE plaintext hang)",
      "defect": "port-unification TLS detect short-circuits AuthPolicy.NONE plaintext so clients hang",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 137,
      "batch": "n=131-140 (2026-07-20)",
      "repo": "apache/dubbo",
      "key": "dubbo-11418",
      "introducing_pr": 11418,
      "fixing_pr": 15997,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL (SecurityContext never cleared on provider thread)",
      "defect": "ContextHolderAuthenticationResolverFilter sets SecurityContextHolder without clearContext finally",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 138,
      "batch": "n=131-140 (2026-07-20)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-40526",
      "introducing_pr": 40526,
      "fixing_pr": 49070,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM (org invitations missing org-scoped authz)",
      "defect": "Organization invitation endpoints missing org-scoped requireManage checks",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 139,
      "batch": "n=131-140 (2026-07-20)",
      "repo": "apache/flink",
      "key": "flink-10009",
      "introducing_pr": 10009,
      "fixing_pr": 10177,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM (createBatch locks empty mailbox)",
      "defect": "TaskMailboxImpl.hasMail locks even when empty after volatile count removed",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 140,
      "batch": "n=131-140 (2026-07-20)",
      "repo": "apache/ozone",
      "key": "ozone-9813",
      "introducing_pr": 9813,
      "fixing_pr": 10692,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH (correctness; 60s wait under bootstrap lock)",
      "defect": "60s wait under BOOTSTRAP_LOCK after RocksDB 10 upgrade path",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 141,
      "batch": "n=141-150 (2026-07-20)",
      "repo": "apache/pulsar",
      "key": "pulsar-25038",
      "introducing_pr": 25038,
      "fixing_pr": 26143,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM (lookup semaphore timeout double-release)",
      "defect": "lookup semaphore timeout ownership / double-release",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 142,
      "batch": "n=141-150 (2026-07-20)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-52715",
      "introducing_pr": 52715,
      "fixing_pr": 52866,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH (WorkspaceLoader thenLoad/GAV race)",
      "defect": "WorkspaceLoader GAV race",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 143,
      "batch": "n=141-150 (2026-07-20)",
      "repo": "apache/pulsar",
      "key": "pulsar-25625",
      "introducing_pr": 25625,
      "fixing_pr": 25767,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (readEntriesFailed early-return leaves InFlightTask)",
      "defect": "readEntriesFailed returns early when state!=Started without completing InFlightTask",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 144,
      "batch": "n=141-150 (2026-07-20)",
      "repo": "apache/flink",
      "key": "flink-23988",
      "introducing_pr": 23988,
      "fixing_pr": 26204,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM (removeTransientMetrics full-map removeIf)",
      "defect": "MetricStore.removeTransientMetrics full-map removeIf scan on REST/UI path",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 145,
      "batch": "n=141-150 (2026-07-20)",
      "repo": "redisson/redisson",
      "key": "redisson-e3e3c41",
      "introducing_pr": "e3e3c41",
      "fixing_pr": 7221,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (registerMasterEntry under lazyConnectLatch)",
      "defect": "registerMasterEntry inline on connecting thread under lazyConnectLatch self-deadlock",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 146,
      "batch": "n=141-150 (2026-07-20)",
      "repo": "redisson/redisson",
      "key": "redisson-2ddc4a",
      "introducing_pr": "2ddc4a",
      "fixing_pr": 7206,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (AsyncSemaphore double-increment on cancel)",
      "defect": "AsyncSemaphore dead-waiter branch increments then falls through to trailing increment (+2)",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 147,
      "batch": "n=141-150 (2026-07-20)",
      "repo": "apache/flink",
      "key": "flink-11687",
      "introducing_pr": 11687,
      "fixing_pr": 12231,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM (requestPartitions on every getNextRecord)",
      "defect": "requestPartitions on every getNextRecord",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 148,
      "batch": "n=141-150 (2026-07-20)",
      "repo": "apache/lucene",
      "key": "lucene-13568",
      "introducing_pr": 13568,
      "fixing_pr": 13656,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH (CollectorOwner synchronizedList on every search)",
      "defect": "CollectorOwner synchronizedList on IndexSearcher.search CollectorManager path",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 149,
      "batch": "n=141-150 (2026-07-20)",
      "repo": "apache/hbase",
      "key": "hbase-7993",
      "introducing_pr": 7993,
      "fixing_pr": 8442,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "CRITICAL (isRedundantDelete visibility-blind)",
      "defect": "isRedundantDelete visibility-blind on minor compact can resurrect labeled cells",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 150,
      "batch": "n=141-150 (2026-07-20)",
      "repo": "debezium/debezium",
      "key": "debezium-7536",
      "introducing_pr": 7536,
      "fixing_pr": 7569,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH (deferred offset ignores minCacheScn)",
      "defect": "deferred txn offset uses only oldestDeferred SCN ignoring minCacheScn",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 151,
      "batch": "n=151-160 (2026-07-20)",
      "repo": "apache/hbase",
      "key": "hbase-3359",
      "introducing_pr": 3359,
      "fixing_pr": 6040,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH (BackupLogCleaner multi-root min not applied)",
      "defect": "BackupLogCleaner multi-root min not considered; cleans WALs needed by other root",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 152,
      "batch": "n=151-160 (2026-07-20)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-21803",
      "introducing_pr": 21803,
      "fixing_pr": 22281,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent get-by-id gaps; missed version-map restore gate",
      "defect": "version-map restore gated by persistedCheckpoint < maxSeqNo never true; duplicate rows",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 153,
      "batch": "n=151-160 (2026-07-20)",
      "repo": "debezium/debezium",
      "key": "debezium-7415",
      "introducing_pr": 7415,
      "fixing_pr": 7605,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (DATETIME hardcodes millis Timestamp)",
      "defect": "ZeroDateFallbackConverter hardcodes Timestamp millis for every DATETIME truncating micros",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 154,
      "batch": "n=151-160 (2026-07-20)",
      "repo": "apache/flink",
      "key": "flink-26245",
      "introducing_pr": 26245,
      "fixing_pr": 28762,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "CRITICAL (ForSt MapState putAll missing null flag)",
      "defect": "ForStMapState null flag not used by BunchPutRequest buildSerializedValue",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 155,
      "batch": "n=151-160 (2026-07-20)",
      "repo": "apache/iceberg",
      "key": "iceberg-12979",
      "introducing_pr": 12979,
      "fixing_pr": 17210,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (TableMaintenance UUID uidSuffix breaks savepoint)",
      "defect": "TableMaintenance uidSuffix defaults UUID.randomUUID so savepoints cannot restore",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 156,
      "batch": "n=151-160 (2026-07-20)",
      "repo": "netty/netty",
      "key": "netty-12898",
      "introducing_pr": 12898,
      "fixing_pr": 17063,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "CRITICAL (OCSP missing CertID match)",
      "defect": "OCSP CertID validation defect surface from #12898 (CVE family)",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 157,
      "batch": "n=151-160 (2026-07-20)",
      "repo": "micronaut-projects/micronaut-security",
      "key": "micronaut-security-456",
      "introducing_pr": 456,
      "fixing_pr": "CVE-2023-36820",
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (OIDC iss||aud short-circuit)",
      "defect": "OIDC aud validation short-circuits with || so wrong audience can pass",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "skipped",
      "attribution_verdict": "SKIP-commit-based"
    },
    {
      "n": 158,
      "batch": "n=151-160 (2026-07-20)",
      "repo": "spring-projects/spring-boot",
      "key": "spring-boot-withHttpMethod",
      "introducing_pr": "996ee243a3",
      "fixing_pr": 49885,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (excluding drops withHttpMethod)",
      "defect": "EndpointRequest.withHttpMethod lost when excluding() rebuilds matcher",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 159,
      "batch": "n=151-160 (2026-07-20)",
      "repo": "apache/camel",
      "key": "camel-secureProcessing",
      "introducing_pr": "0c3b02a2e3",
      "fixing_pr": 24777,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "saw insecure=false path; missed no-op without Saxon extensions",
      "defect": "secureProcessing no-op without Saxon extensions enabled",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 160,
      "batch": "n=151-160 (2026-07-20)",
      "repo": "netty/netty",
      "key": "netty-simple-tm-wrap",
      "introducing_pr": "0b7bf49",
      "fixing_pr": 16868,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (plain TM wrap drops hostname verify)",
      "defect": "plain TrustManager wrap drops hostname verification",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 161,
      "batch": "n=161-170 (2026-07-21)",
      "repo": "apache/ozone",
      "key": "ozone-9718",
      "introducing_pr": 9718,
      "fixing_pr": 10747,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "perf CLEARED close-path sleep as cold; missed clientCache monitor hold",
      "defect": "close() graceful shutdown sleep holds clientCache monitor \u2265100ms",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 162,
      "batch": "n=161-170 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-150240",
      "introducing_pr": 150240,
      "fixing_pr": 151393,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "max_record_size CSV/TSV char-by-char StringBuilder + re-tokenize; NDJSON double-scan",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 163,
      "batch": "n=161-170 (2026-07-21)",
      "repo": "apache/beam",
      "key": "beam-33293",
      "introducing_pr": 33293,
      "fixing_pr": 33575,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "parseTableIdentifier try Jackson first forces exception on common non-JSON path",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 164,
      "batch": "n=161-170 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-150906",
      "introducing_pr": 150906,
      "fixing_pr": 151518,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent float COSINE fallback; missed castShape part-split cost",
      "defect": "Panama bulk byte-vector castShape part-splitting regresses scoring",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 165,
      "batch": "n=161-170 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-149223",
      "introducing_pr": 149223,
      "fixing_pr": 150276,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "ArrayOrder adjacent; missed megamorphic shared read()",
      "defect": "generic AbstractNumericBlockLoader shared read() megamorphic numeric loaders",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 166,
      "batch": "n=161-170 (2026-07-21)",
      "repo": "apache/druid",
      "key": "druid-12315",
      "introducing_pr": 12315,
      "fixing_pr": 15614,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "getColumnCapabilities only checks virtualColumns \u2192 expression filters skip bitmaps",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 167,
      "batch": "n=161-170 (2026-07-21)",
      "repo": "netty/netty",
      "key": "netty-10267",
      "introducing_pr": 10267,
      "fixing_pr": 10825,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "SizeClasses rewrite broke PoolThreadCache normal-cache indexing (~3\u00d7)",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 168,
      "batch": "n=161-170 (2026-07-21)",
      "repo": "apache/flink",
      "key": "flink-16556",
      "introducing_pr": 16556,
      "fixing_pr": 16710,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "unconditional throughputCalculationSetup for 0-input-gate sources",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 169,
      "batch": "n=161-170 (2026-07-21)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-18110",
      "introducing_pr": 18110,
      "fixing_pr": 18267,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Results.NotFound interface+factories replace NOT_FOUND singleton \u2192 alloc thrash",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 170,
      "batch": "n=161-170 (2026-07-21)",
      "repo": "hazelcast/hazelcast",
      "key": "hazelcast-19474",
      "introducing_pr": 19474,
      "fixing_pr": 21323,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "CLEARED as intentional local-read opt (sold-as-faster)",
      "defect": "local map read on cooperative thread via recordStore.fetchEntries",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 171,
      "batch": "n=171-180 (2026-07-21)",
      "repo": "apache/activemq-artemis",
      "key": "artemis-1577",
      "introducing_pr": 1577,
      "fixing_pr": 2514,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "offer() always false \u2192 create threads instead of reusing idle",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 172,
      "batch": "n=171-180 (2026-07-21)",
      "repo": "apache/maven-resolver",
      "key": "maven-resolver-1902",
      "introducing_pr": 1902,
      "fixing_pr": 1937,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "synchronized(versionCache)/WeakInternPool \u2192 2\u00d7 Quarkus build",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 173,
      "batch": "n=171-180 (2026-07-21)",
      "repo": "apache/hudi",
      "key": "hudi-13976",
      "introducing_pr": 13976,
      "fixing_pr": 17477,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "plain coalesce fails to cut Spark DAG for streaming MDT writes",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 174,
      "batch": "n=171-180 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-134701",
      "introducing_pr": 134701,
      "fixing_pr": 147357,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "CLEARED as intentional over-estimate; missed TEXT page-size blow",
      "defect": "TEXT estimate 50\u21921024 blows enrich/lookup page size",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 175,
      "batch": "n=171-180 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-140843",
      "introducing_pr": 140843,
      "fixing_pr": 141980,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Arena.ofConfined 'opt' fails EA \u2192 young GC regression",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 176,
      "batch": "n=171-180 (2026-07-21)",
      "repo": "apache/druid",
      "key": "druid-16775",
      "introducing_pr": 16775,
      "fixing_pr": 16928,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "SuperSorter stores writable channels \u2192 1MB/channel waste",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 177,
      "batch": "n=171-180 (2026-07-21)",
      "repo": "apache/beam",
      "key": "beam-15637",
      "introducing_pr": 15637,
      "fixing_pr": 33521,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "GlobalWindows GBK preempts memory-sensitive path \u2192 OOM risk",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 178,
      "batch": "n=171-180 (2026-07-21)",
      "repo": "netty/netty",
      "key": "netty-10226",
      "introducing_pr": 10226,
      "fixing_pr": 10623,
      "lane": "performance",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "treated as correctness win; missed offer-buf allocator cost",
      "defect": "multipart uses offer-buf allocator \u2192 direct buffer 100\u00d7 slow",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 179,
      "batch": "n=171-180 (2026-07-21)",
      "repo": "trinodb/trino",
      "key": "trino-26225",
      "introducing_pr": 26225,
      "fixing_pr": 30245,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "addBytes adds delta to rounded currentBytes \u2192 memory accounting drift",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 180,
      "batch": "n=171-180 (2026-07-21)",
      "repo": "redis/jedis",
      "key": "jedis-3848",
      "introducing_pr": 3848,
      "fixing_pr": 4205,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "replicaSlots never cleared on reset \u2192 unbounded heap under topology refresh",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 181,
      "batch": "n=181-190 (2026-07-21)",
      "repo": "apache/knox",
      "key": "knox-1175",
      "introducing_pr": 1175,
      "fixing_pr": 1176,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "cipherSuites used instead of tlsVersions for SSL protocols config",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 182,
      "batch": "n=181-190 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-49522",
      "introducing_pr": 49522,
      "fixing_pr": 50537,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "assert-only realm ownership check no-op without -ea",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 183,
      "batch": "n=181-190 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-8243",
      "introducing_pr": 8243,
      "fixing_pr": 50565,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "JWE fallthrough accepts unsigned JSON when signature required (CVE-2026-9793)",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 184,
      "batch": "n=181-190 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-49420",
      "introducing_pr": 49420,
      "fixing_pr": 50650,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "pre-auth UsernameScopeType user-store lookup enables username enum",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 185,
      "batch": "n=181-190 (2026-07-21)",
      "repo": "apache/hive",
      "key": "hive-1791",
      "introducing_pr": 1791,
      "fixing_pr": 6534,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "inverted !MessageDigest.isEqual in SAML signatureMatches \u2192 authn bypass",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 186,
      "batch": "n=181-190 (2026-07-21)",
      "repo": "datahub-project/datahub",
      "key": "datahub-9592",
      "introducing_pr": 9592,
      "fixing_pr": 16279,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "open redirect: scheme/authority check misses ///host",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 187,
      "batch": "n=181-190 (2026-07-21)",
      "repo": "datahub-project/datahub",
      "key": "datahub-14707",
      "introducing_pr": 14707,
      "fixing_pr": 18140,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "INFO logs full headers including bearer JWT",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 188,
      "batch": "n=181-190 (2026-07-21)",
      "repo": "apache/activemq-artemis",
      "key": "artemis-62",
      "introducing_pr": 62,
      "fixing_pr": 6275,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent MQTT authz; missed QoS2 PubRec-before-send",
      "defect": "QoS2 PubRec recorded before send \u2192 unauthorized retry ignored",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 189,
      "batch": "n=181-190 (2026-07-21)",
      "repo": "prestodb/presto",
      "key": "presto-3799",
      "introducing_pr": 3799,
      "fixing_pr": 28031,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "InitializingSystemAccessControl only overrides few SPI methods \u2192 allow-all during startup",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 190,
      "batch": "n=181-190 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-7412",
      "introducing_pr": 7412,
      "fixing_pr": 49512,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "CORS Allow-Origin from unverified JWT azp (UMA) CVE-2026-37977",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 191,
      "batch": "n=191-200 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-10603",
      "introducing_pr": 10603,
      "fixing_pr": 50910,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "rotated-secret export/JWT gaps; missed feature-off still accepts rotated",
      "defect": "rotated client secret still valid when CLIENT_SECRET_ROTATION disabled",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 192,
      "batch": "n=191-200 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-38322",
      "introducing_pr": 38322,
      "fixing_pr": 50824,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "FGAP partial-eval drops per-child canView on parent /children CVE-2026-14615",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 193,
      "batch": "n=191-200 (2026-07-21)",
      "repo": "apache/struts",
      "key": "struts-832",
      "introducing_pr": 832,
      "fixing_pr": 1681,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "cookie channel bypasses @StrutsParameter/requireAnnotations",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 194,
      "batch": "n=191-200 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-44600",
      "introducing_pr": 44600,
      "fixing_pr": 50374,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "jwks flag/use-filter; missed HMAC algorithm confusion",
      "defect": "JWT Authorization Grant algorithm confusion via HMAC in public-key loader",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 195,
      "batch": "n=191-200 (2026-07-21)",
      "repo": "hazelcast/hazelcast",
      "key": "hazelcast-5091",
      "introducing_pr": 5091,
      "fixing_pr": 25965,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "MapPermission instead of ReplicatedMapPermission on addEntryListener",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 196,
      "batch": "n=191-200 (2026-07-21)",
      "repo": "redisson/redisson",
      "key": "redisson-7032",
      "introducing_pr": 7032,
      "fixing_pr": 7162,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "password-masking toString used for cluster slave addresses \u2192 WRONGPASS",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 197,
      "batch": "n=191-200 (2026-07-21)",
      "repo": "eclipse/jetty.project",
      "key": "jetty-14859",
      "introducing_pr": 14859,
      "fixing_pr": 15115,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "treated as de-alias fix; missed LoaderHiding drop",
      "defect": "base-resource re-materialization drops LoaderHidingResource path hide",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 198,
      "batch": "n=191-200 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-10579",
      "introducing_pr": 10579,
      "fixing_pr": 17492,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "close() holds writeLock then join()s init thread needing same lock \u2192 deadlock",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 199,
      "batch": "n=191-200 (2026-07-21)",
      "repo": "netty/netty",
      "key": "netty-14818",
      "introducing_pr": 14818,
      "fixing_pr": 17087,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "IoUring multishot cancel clears readPending before re-schedule \u2192 permanent stall",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 200,
      "batch": "n=191-200 (2026-07-21)",
      "repo": "apache/hbase",
      "key": "hbase-5256",
      "introducing_pr": 5256,
      "fixing_pr": 7886,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "FlushRegionProcedure execute/complete race on unsync dispatched/succ",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 201,
      "batch": "n=201-210 (2026-07-21)",
      "repo": "apache/hbase",
      "key": "hbase-4115",
      "introducing_pr": 4115,
      "fixing_pr": 7084,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "snapshot shared table lock + holdLock deadlocks with Enable exclusive",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 202,
      "batch": "n=201-210 (2026-07-21)",
      "repo": "apache/hbase",
      "key": "hbase-4803",
      "introducing_pr": 4803,
      "fixing_pr": 7077,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "global queue cleanup helper never wired into completionCleanup \u2192 hang",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 203,
      "batch": "n=201-210 (2026-07-21)",
      "repo": "apache/hbase",
      "key": "hbase-7282",
      "introducing_pr": 7282,
      "fixing_pr": 7401,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "QuotaCache ConcurrentHashMap\u2192HashMap data race",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 204,
      "batch": "n=201-210 (2026-07-21)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-19403",
      "introducing_pr": 19403,
      "fixing_pr": 22244,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "removed synchronized from FlightServerChannel.close() \u2192 double-close race",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 205,
      "batch": "n=201-210 (2026-07-21)",
      "repo": "apache/flink",
      "key": "flink-23180",
      "introducing_pr": 23180,
      "fixing_pr": 23296,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "close vs request race on collect sink socket",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 206,
      "batch": "n=201-210 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-25581",
      "introducing_pr": 25581,
      "fixing_pr": 25589,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "expire path decrements unacked while redeliver is non-atomic",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 207,
      "batch": "n=201-210 (2026-07-21)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-34855",
      "introducing_pr": 34855,
      "fixing_pr": 55041,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "gRPC @RunOnVirtualThread half-close before message",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 208,
      "batch": "n=201-210 (2026-07-21)",
      "repo": "prestodb/presto",
      "key": "presto-23257",
      "introducing_pr": 23257,
      "fixing_pr": 27597,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "pruneFinished/expireQueue; missed queryScheduler.set(null) race",
      "defect": "pruneFinishedQueryInfo sets queryScheduler null without abort \u2192 race/leak",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 209,
      "batch": "n=201-210 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-20403",
      "introducing_pr": 20403,
      "fixing_pr": 22590,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "init commitNeeded; missed getStateStore context wipe",
      "defect": "getStateStore unconditionally resets live ProcessorRecordContext \u2192 timestamps wiped",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 210,
      "batch": "n=201-210 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-6962",
      "introducing_pr": 6962,
      "fixing_pr": 16435,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "INT96 dict decode setLong(idx) uses row index as byte offset \u2192 corruption",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 211,
      "batch": "n=211-220 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-14297",
      "introducing_pr": 14297,
      "fixing_pr": 17002,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Variant decimal shredding hardcodes .length(16) vs decimalRequiredBytes",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 212,
      "batch": "n=211-220 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-22625",
      "introducing_pr": 22625,
      "fixing_pr": 22710,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "txn buffer stages all CFs into pendingWrites \u2192 offset/Position leaks into data iteration",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 213,
      "batch": "n=211-220 (2026-07-21)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-18536",
      "introducing_pr": 18536,
      "fixing_pr": 20284,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "snapshot restore breaks for index-sort (parent field missing on prune)",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 214,
      "batch": "n=211-220 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-18814",
      "introducing_pr": 18814,
      "fixing_pr": 18940,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "epoch strings via strict Long.parseLong wrong codec/parse",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 215,
      "batch": "n=211-220 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-12836",
      "introducing_pr": 12836,
      "fixing_pr": 17039,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "row lineage uses fileSequenceNumber not dataSequenceNumber",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 216,
      "batch": "n=211-220 (2026-07-21)",
      "repo": "apache/hudi",
      "key": "hudi-13543",
      "introducing_pr": 13543,
      "fixing_pr": 19237,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "checkpoint serializes all-null write-metadata \u2192 failover data loss",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 217,
      "batch": "n=211-220 (2026-07-21)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-20551",
      "introducing_pr": 20551,
      "fixing_pr": 22099,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "segrep retry leaves replica behind (achieved vs target ckp)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 218,
      "batch": "n=211-220 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-16991",
      "introducing_pr": 16991,
      "fixing_pr": 17751,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "hybrid time-boundary filters not re-optimized after attach",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 219,
      "batch": "n=211-220 (2026-07-21)",
      "repo": "apache/accumulo",
      "key": "accumulo-5416",
      "introducing_pr": 5416,
      "fixing_pr": 5548,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "migration cleanup fetches PREV_ROW+MIGRATION but not LOCATION \u2192 null location",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 220,
      "batch": "n=211-220 (2026-07-21)",
      "repo": "trinodb/trino",
      "key": "trino-29643",
      "introducing_pr": 29643,
      "fixing_pr": 29877,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "flatHash equality-delete channel map misaligned with metadata columns",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 221,
      "batch": "n=221-230 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-151021",
      "introducing_pr": 151021,
      "fixing_pr": 151914,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "MEDIUM",
      "defect": "ArrayOrderInlineNull always constructed before maxValue\u22641 check; skipped OptionalColumnAtATimeReader bulk fast path",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 222,
      "batch": "n=221-230 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-86922",
      "introducing_pr": 86922,
      "fixing_pr": 87407,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "HIGH",
      "defect": "Removed Netty4WriteThrottlingHandler from HTTP pipeline; lost lower-level write throttling (sold-as-faster)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 223,
      "batch": "n=221-230 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-149176",
      "introducing_pr": 149176,
      "fixing_pr": 149341,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Default schema resolution FIRST_FILE_WINS\u2192UNION_BY_NAME bypassed schema cache on multi-file globs (~34\u00d7)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 224,
      "batch": "n=221-230 (2026-07-21)",
      "repo": "apache/flink",
      "key": "flink-25551",
      "introducing_pr": 25551,
      "fixing_pr": 25887,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "HIGH",
      "defect": "ConsumedSubpartitionContext.build O(n) iterates all partitions on scheduler hot path",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 225,
      "batch": "n=221-230 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-21897",
      "introducing_pr": 21897,
      "fixing_pr": 22199,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "collectFetch always waits on reconciliationCheckFuture even when not reconciling",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 226,
      "batch": "n=221-230 (2026-07-21)",
      "repo": "netty/netty",
      "key": "netty-14704",
      "introducing_pr": 14704,
      "fixing_pr": 14711,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "processOneNow linear-scans completion array on hot write path (10-15% drop; sold-as-safer)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 227,
      "batch": "n=221-230 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-19589",
      "introducing_pr": 19589,
      "fixing_pr": 20354,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Observer poll Math.min with expired updateVoterSet timer \u2192 busy-spin Raft client",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 228,
      "batch": "n=221-230 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-20175",
      "introducing_pr": 20175,
      "fixing_pr": 21027,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Per-handler LoggerFactory.getLogger(canonicalName) CPU cost on share-group persister path",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 229,
      "batch": "n=221-230 (2026-07-21)",
      "repo": "apache/beam",
      "key": "beam-31805",
      "introducing_pr": 31805,
      "fixing_pr": 31960,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Duplicate getTableToExtract lineage call starts extra BQ query job on export read",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 230,
      "batch": "n=221-230 (2026-07-21)",
      "repo": "spring-projects/spring-framework",
      "key": "spring-crhm-compute",
      "introducing_pr": "12dd758",
      "fixing_pr": 36293,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "MEDIUM",
      "defect": "ConcurrentReferenceHashMap.compute* always locks even for present read-only keys",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 231,
      "batch": "n=231-240 (2026-07-21)",
      "repo": "apache/hive",
      "key": "hive-1876",
      "introducing_pr": 1876,
      "fixing_pr": 4005,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "MapredContext.createDummy on every GenericUDF initialize bloated query compilation",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 232,
      "batch": "n=231-240 (2026-07-21)",
      "repo": "apache/lucene",
      "key": "lucene-672",
      "introducing_pr": 672,
      "fixing_pr": 12072,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "HIGH",
      "defect": "rewriteNoScoring re-enters ConstantScoreQuery.rewrite \u2192 exponential nested Boolean rewrite (sold-as-faster)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 233,
      "batch": "n=231-240 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-10528",
      "introducing_pr": 10528,
      "fixing_pr": 15878,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "ByteBufferUtil setAccessible(true) on every newDirectByteBuffer instead of once",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 234,
      "batch": "n=231-240 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-140475",
      "introducing_pr": 140475,
      "fixing_pr": 141229,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Time-series partitioner many fixed slices on high-CPU \u2192 scheduling overhead (sold-as-faster; full revert)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 235,
      "batch": "n=231-240 (2026-07-21)",
      "repo": "google/guava",
      "key": "guava-8258",
      "introducing_pr": 8258,
      "fixing_pr": 8545,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "MEDIUM",
      "defect": "ClosingFuture logging/close made closingFutureToString() eager instead of lazy",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 236,
      "batch": "n=231-240 (2026-07-21)",
      "repo": "apache/logging-log4j2",
      "key": "log4j2-2691",
      "introducing_pr": 2691,
      "fixing_pr": 3123,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Pattern Layout stack rewrite made %xEx extended stack rendering far slower",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 237,
      "batch": "n=231-240 (2026-07-21)",
      "repo": "apache/druid",
      "key": "druid-15757",
      "introducing_pr": 15757,
      "fixing_pr": 19518,
      "lane": "performance",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "HIGH",
      "defect": "Per-hydrant SpecificSegmentQueryRunner multiplies Thread.setName cost 50\u2013200\u00d7",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 238,
      "batch": "n=231-240 (2026-07-21)",
      "repo": "apache/ignite",
      "key": "ignite-11425",
      "introducing_pr": "2d69600",
      "fixing_pr": 11848,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "SQL plan history records plans synchronously on H2/Calcite query paths",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 239,
      "batch": "n=231-240 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-6093",
      "introducing_pr": 6093,
      "fixing_pr": 49089,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Account resources API never checks userManagedAccessAllowed (UMA config theater)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 240,
      "batch": "n=231-240 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-36880",
      "introducing_pr": 36880,
      "fixing_pr": 50780,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "FGAP v2 client-scope assign lacks manage-on-scope (CVE-2026-14614)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 241,
      "batch": "n=241-250 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-8589",
      "introducing_pr": 8589,
      "fixing_pr": 49474,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "reject-ropc-grant policy bypass when conditions fail to resolve client (CVE-2026-9792)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 242,
      "batch": "n=241-250 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-7286",
      "introducing_pr": 7286,
      "fixing_pr": 48715,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Versioned Account API path lacks checkAccountApiEnabled (CVE-2026-7500)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 243,
      "batch": "n=241-250 (2026-07-21)",
      "repo": "netty/netty",
      "key": "netty-14358",
      "introducing_pr": 14358,
      "fixing_pr": 16931,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ReferenceCountedOpenSslContext hard-codes startTls=false; SslContextBuilder.startTls(true) no-op",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 244,
      "batch": "n=241-250 (2026-07-21)",
      "repo": "hazelcast/hazelcast",
      "key": "hazelcast-25477",
      "introducing_pr": 25477,
      "fixing_pr": 26074,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "UpdatingEntryProcessor serializes Subject; client can tamper ExpressionEvalContext for GET_DDL",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 245,
      "batch": "n=241-250 (2026-07-21)",
      "repo": "apache/ranger",
      "key": "ranger-gds-download",
      "introducing_pr": "8c2363a",
      "fixing_pr": 1067,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "GDS secure download uses weaker isValidateHttpsAuthentication than sibling secure downloads",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 246,
      "batch": "n=241-250 (2026-07-21)",
      "repo": "redisson/redisson",
      "key": "redisson-config-endpoint-user",
      "introducing_pr": "2570af5",
      "fixing_pr": 7243,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Config endpoint password URL rebuild drops ACL username \u2192 WRONGPASS after topology discovery",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 247,
      "batch": "n=241-250 (2026-07-21)",
      "repo": "undertow-io/undertow",
      "key": "undertow-859",
      "introducing_pr": 859,
      "fixing_pr": 1943,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "AJP_ALLOWED_REQUEST_ATTRIBUTES_PATTERN not applied in setUndertowOptions (config theater)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 248,
      "batch": "n=241-250 (2026-07-21)",
      "repo": "spring-projects/spring-security",
      "key": "spring-security-16574",
      "introducing_pr": 16574,
      "fixing_pr": "462e38c0e3",
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "DPoP jkt uses PublicKey.getEncoded digest instead of JWK SHA-256 thumbprint (RFC 9449)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 249,
      "batch": "n=241-250 (2026-07-21)",
      "repo": "apache/ozone",
      "key": "ozone-8875",
      "introducing_pr": 8875,
      "fixing_pr": 10753,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "HIGH",
      "defect": "Lifecycle set/delete used ACLType.ALL; wrong under Ranger",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 250,
      "batch": "n=241-250 (2026-07-21)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-21660",
      "introducing_pr": 21660,
      "fixing_pr": 21917,
      "lane": "security",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "HIGH",
      "defect": "analytics executeWithProfile bypasses SecurityFilter/index permission path",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 251,
      "batch": "n=251-260 (2026-07-21)",
      "repo": "apache/zookeeper",
      "key": "zookeeper-2173",
      "introducing_pr": 2173,
      "fixing_pr": 2303,
      "lane": "security",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "HIGH",
      "defect": "ssl.clientHostnameVerification ignored when ssl.authProvider set (hardcoded false)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 252,
      "batch": "n=251-260 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-9695",
      "introducing_pr": 9695,
      "fixing_pr": 9887,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "createAndAddStreamThread outside changeThreadCount \u2192 duplicate StreamThread index",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 253,
      "batch": "n=251-260 (2026-07-21)",
      "repo": "netty/netty",
      "key": "netty-14334",
      "introducing_pr": 14334,
      "fixing_pr": 14495,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "AdaptivePoolingAllocator free/offerToQueue TOCTOU \u2192 chunk leak",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 254,
      "batch": "n=251-260 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-23761",
      "introducing_pr": 23761,
      "fixing_pr": 23853,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "HIGH",
      "defect": "Early closeAndClearPendingMessages races reconnect/resend of recycled messages",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 255,
      "batch": "n=251-260 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-14078",
      "introducing_pr": 14078,
      "fixing_pr": 15366,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "HIGH",
      "defect": "Proxy close during outbound connect leaks connections (port exhaustion)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 256,
      "batch": "n=251-260 (2026-07-21)",
      "repo": "apache/flink",
      "key": "flink-25732",
      "introducing_pr": 25732,
      "fixing_pr": 26053,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "HIGH",
      "defect": "ForSt close joins shared background threads used by other instances",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 257,
      "batch": "n=251-260 (2026-07-21)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-18754",
      "introducing_pr": 18754,
      "fixing_pr": 20918,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "asyncLoadIndexInput unconditional decRef after remove races re-insert",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 258,
      "batch": "n=251-260 (2026-07-21)",
      "repo": "netty/netty",
      "key": "netty-15369",
      "introducing_pr": 15369,
      "fixing_pr": 15743,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ReturnChunkEvent static INSTANCE wrong type \u2192 JFR class-init deadlock",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 259,
      "batch": "n=251-260 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-25573",
      "introducing_pr": 25573,
      "fixing_pr": 25778,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "eagerAttachInitialAsync vs onLayoutChange exclusive claim race",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 260,
      "batch": "n=251-260 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-152771",
      "introducing_pr": 152771,
      "fixing_pr": 153074,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Single esql_external_io pool for drain+parse + POISON readiness \u2192 deadlock",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 261,
      "batch": "n=261-270 (2026-07-21)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-19958",
      "introducing_pr": 19958,
      "fixing_pr": 22515,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "parseV1Mappings complete field replacement broke multi-template deep merge",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 262,
      "batch": "n=261-270 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-15475",
      "introducing_pr": 15475,
      "fixing_pr": 17194,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "AvroToRowDataConverters microsecond\u2192nano multiplies by 1e6 not 1000",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 263,
      "batch": "n=261-270 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-10891",
      "introducing_pr": 10891,
      "fixing_pr": 18952,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Reversed ByteArray.compare for raw BYTES min/max metadata",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 264,
      "batch": "n=261-270 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-12227",
      "introducing_pr": 12227,
      "fixing_pr": 16501,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "HIGH",
      "defect": "NestedField.from copies defaults onto FIXED physical type \u2192 castDefault fails for decimals",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 265,
      "batch": "n=261-270 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-16025",
      "introducing_pr": 16025,
      "fixing_pr": 16469,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "var-length dictionary validate rejects BIG_DECIMAL (STRING||BYTES only)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 266,
      "batch": "n=261-270 (2026-07-21)",
      "repo": "apache/hudi",
      "key": "hudi-7620",
      "introducing_pr": 7620,
      "fixing_pr": 8374,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "CkpMetadata.bootstrap stopped cleaning checkpoint-meta \u2192 stale ckp on JM restart",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 267,
      "batch": "n=261-270 (2026-07-21)",
      "repo": "apache/hudi",
      "key": "hudi-9755",
      "introducing_pr": 9755,
      "fixing_pr": 10923,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "getLastClusterCommit only sees completed CLUSTER; ignores pending clustering",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 268,
      "batch": "n=261-270 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-11220",
      "introducing_pr": 11220,
      "fixing_pr": 11621,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "MEDIUM",
      "defect": "TableMetadataParser double-closes stream in try-with-resources",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 269,
      "batch": "n=261-270 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-10771",
      "introducing_pr": 10771,
      "fixing_pr": 11858,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "HiveCatalog.close closes shared FileIO while tables still need it",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 270,
      "batch": "n=261-270 (2026-07-21)",
      "repo": "apache/paimon",
      "key": "paimon-4283",
      "introducing_pr": 4283,
      "fixing_pr": 4387,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Hive metastore proxy factory only tries first constructor param type \u2192 DLF catalog fail",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 271,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "apache/lucene",
      "key": "lucene-15021",
      "introducing_pr": 15021,
      "fixing_pr": 15183,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "bulkScore remainder maxScore uses scores[i+1] instead of scores[i+2] when remaining>2",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 272,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "netty/netty",
      "key": "netty-16844",
      "introducing_pr": 16844,
      "fixing_pr": 17037,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "HttpContentDecompressor passes maxAllocation as BrotliDecoder input size not output cap",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 273,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-18195",
      "introducing_pr": 18195,
      "fixing_pr": 20823,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "terms-lookup fetch uses unregistered indices.query.max_clause_count stuck at 1024",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 274,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-22368",
      "introducing_pr": 22368,
      "fixing_pr": 22849,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Share-group DLQ stamps records with hiResClockMs (nanoTime) so retention deletes immediately",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 275,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-150545",
      "introducing_pr": 150545,
      "fixing_pr": 153312,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "pointsInMemoryBytes required constructorArg breaks parse of older ShardFieldStats",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 276,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "apache/lucene",
      "key": "lucene-15760",
      "introducing_pr": 15760,
      "fixing_pr": 15817,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "NumericFieldStats.decodeLong only handles width 4/8; HalfFloat etc throw IAE",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 277,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "opensearch-project/OpenSearch",
      "key": "opensearch-19060",
      "introducing_pr": 19060,
      "fixing_pr": 19273,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "BooleanFlatteningRewriter flattens must_not of pure must_not collapsing double-negation",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 278,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "netty/netty",
      "key": "netty-13693",
      "introducing_pr": 13693,
      "fixing_pr": 15740,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "zeroTillAligned uses addr%8 as bytes-to-alignment (wrong for non-aligned addresses)",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 279,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-24938",
      "introducing_pr": 24938,
      "fixing_pr": 25037,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "getNumberOfEntries current-ledger branch misses toPosition same ledger as LAC with smaller entry",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 280,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-15435",
      "introducing_pr": 15435,
      "fixing_pr": 18818,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "BitRateUnit refactor dropped * nics.size() from getTotalNicLimitWithConfiguration",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 281,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-12591",
      "introducing_pr": 12591,
      "fixing_pr": 15752,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ioBuilder branch of newFileIO silently drops storageCredentials",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 282,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-16675",
      "introducing_pr": 16675,
      "fixing_pr": 18580,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "validate-only cluster checks wired into shared validateConfig used by create/update",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 283,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-3597",
      "introducing_pr": 3597,
      "fixing_pr": 3844,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "small-entry ReadResponse path writeBytes copy never rr.release() \u2192 ByteBuf leak",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 284,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "apache/maven-resolver",
      "key": "maven-resolver-1957",
      "introducing_pr": 1957,
      "fixing_pr": 1980,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "REPOSITORY_SYSTEM_CALL marker stamped as RequestTrace tip overwriting Artifact data \u2192 CCE",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 285,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "apache/ozone",
      "key": "ozone-8914",
      "introducing_pr": 8914,
      "fixing_pr": 10592,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "per-datanode getBlock loop ignores loop variable; all replicas report same blockData",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 286,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "apache/camel",
      "key": "camel-14062",
      "introducing_pr": 14062,
      "fixing_pr": 24859,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "HIGH",
      "defect": "multipart stream state.index=1 reset + maxRead not reset \u2192 orphaned parts / silent body truncation",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 287,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-3837",
      "introducing_pr": 3837,
      "fixing_pr": 3884,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "group-flush add responses never flush when writeDataToJournal is false \u2192 client timeouts",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 288,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-49579",
      "introducing_pr": 49579,
      "fixing_pr": 50426,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "isProxiable wrongly excludes abstract classes with !isAbstract \u2192 lazy proxy break",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 289,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "hibernate/hibernate-orm",
      "key": "hibernate-10530",
      "introducing_pr": 10530,
      "fixing_pr": 13065,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "null-discriminator subclass CHECK uses 'is' instead of 'is not' \u2192 inverted constraint",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 290,
      "batch": "n=271-290 (2026-07-21)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-52324",
      "introducing_pr": 52324,
      "fixing_pr": 53019,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "DevServices reallyStart stopped putAll into shared configs \u2192 dependent services miss prior config",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 291,
      "batch": "n=291-300 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-18806",
      "introducing_pr": 18806,
      "fixing_pr": 18863,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "DefaultSegmentDirectoryLoader dropped segmentLoaderContext so task.config.json never injected",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 292,
      "batch": "n=291-300 (2026-07-21)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-54343",
      "introducing_pr": 54343,
      "fixing_pr": 54769,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "null-key NPE missed",
      "defect": "excludedKeys.contains(key) NPE on null JBoss LogManager keys in nested JSON skip",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 293,
      "batch": "n=291-300 (2026-07-21)",
      "repo": "apache/camel",
      "key": "camel-20229",
      "introducing_pr": 20229,
      "fixing_pr": 24707,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "JdbcAggregationRepository.verifyTableName regex rejects schema-qualified table names",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 294,
      "batch": "n=291-300 (2026-07-21)",
      "repo": "apache/lucene",
      "key": "lucene-16081",
      "introducing_pr": 16081,
      "fixing_pr": 16256,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "RoaringDocIdSet appendRangeInCurrentBlock uses < instead of <= at MAX_ARRAY_LENGTH 4096",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 295,
      "batch": "n=291-300 (2026-07-21)",
      "repo": "apache/lucene",
      "key": "lucene-15603",
      "introducing_pr": 15603,
      "fixing_pr": 15995,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "TopGroupsCollectorManager hardcodes withinGroupOffset=0 ignoring pagination",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 296,
      "batch": "n=291-300 (2026-07-21)",
      "repo": "netty/netty",
      "key": "netty-16548",
      "introducing_pr": 16548,
      "fixing_pr": 16811,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "CompositeByteBuf component search fast path wrong after discardReadComponents with non-zero offsets",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 297,
      "batch": "n=291-300 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-18196",
      "introducing_pr": 18196,
      "fixing_pr": 22723,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "MetadataCache.toCluster filters fenced brokers then maps replicas through map causing NPE",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 298,
      "batch": "n=291-300 (2026-07-21)",
      "repo": "FasterXML/jackson-databind",
      "key": "jackson-5896",
      "introducing_pr": 5896,
      "fixing_pr": 5903,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "deserializeFromObjectId returns null early breaking forward refs when FAIL_ON_UNRESOLVED disabled",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 299,
      "batch": "n=291-300 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-152481",
      "introducing_pr": 152481,
      "fixing_pr": 153904,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "Removed IGNORED_SOURCE_AS_DOC_VALUES_FF without bumping index version gate for TSDB",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 300,
      "batch": "n=291-300 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-11322",
      "introducing_pr": 11322,
      "fixing_pr": 17014,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "CharSequenceSet contains(null) NPE after WrapperSet rebase",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 301,
      "batch": "n=301-310 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-25337",
      "introducing_pr": 25337,
      "fixing_pr": 26160,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "LightProto ByteBuf release missed",
      "defect": "LightProto parseSnapshotMetadataEntry releases ByteBuf before delayed_index_bit_map access",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 302,
      "batch": "n=301-310 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-18396",
      "introducing_pr": 18396,
      "fixing_pr": 18883,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "TIMESTAMP cast precision 0 truncates millis in binaryComparisonCoercion",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 303,
      "batch": "n=301-310 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-20749",
      "introducing_pr": 20749,
      "fixing_pr": 22490,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "initializeStartupStores close without unlock holds StateDirectory locks permanently",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 304,
      "batch": "n=301-310 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-21406",
      "introducing_pr": 21406,
      "fixing_pr": 24945,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "First txn buffer snapshot races concurrent first publishes after deferred snapshot",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 305,
      "batch": "n=301-310 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-14494",
      "introducing_pr": 14494,
      "fixing_pr": 25578,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "updateAutoScaleReceiverQueueHint races unlocked incomingMessages.size vs drain",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 306,
      "batch": "n=301-310 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-153092",
      "introducing_pr": 153092,
      "fixing_pr": 154316,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Search recovery wait metrics uses isCancelled race mislabeling TIMEOUT as WARMING_COMPLETE",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 307,
      "batch": "n=301-310 (2026-07-21)",
      "repo": "redis/jedis",
      "key": "jedis-4011",
      "introducing_pr": 4011,
      "fixing_pr": 4601,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "AuthXManager.authenticateConnections ConcurrentModificationException mid-iteration remove",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 308,
      "batch": "n=301-310 (2026-07-21)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-13977",
      "introducing_pr": 13977,
      "fixing_pr": 42260,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ReactiveDatasourceHealthCheck post-await UP overwrites concurrent DOWN",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 309,
      "batch": "n=301-310 (2026-07-21)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-3784",
      "introducing_pr": 3784,
      "fixing_pr": 4557,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "completeAdd callbacks on IO threads race PendingAddOp unsynchronized queue",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 310,
      "batch": "n=301-310 (2026-07-21)",
      "repo": "spring-projects/spring-framework",
      "key": "spring-cookie-locale",
      "introducing_pr": "e6c2d446",
      "fixing_pr": 36869,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "CookieLocaleResolver shared cookie field race on concurrent setLocaleContext",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "skipped",
      "attribution_verdict": "SKIP-commit-based"
    },
    {
      "n": 311,
      "batch": "n=311-320 (2026-07-21)",
      "repo": "redisson/redisson",
      "key": "redisson-renewal",
      "introducing_pr": "597d604a",
      "fixing_pr": 7070,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "RenewalTask non-atomic name2entry check-then-act drops live lock from watchdog",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 312,
      "batch": "n=311-320 (2026-07-21)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-21242",
      "introducing_pr": 21242,
      "fixing_pr": 22231,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "cancel-callback gap missed",
      "defect": "AnalyticsQueryTask cancel callback null gap before install",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 313,
      "batch": "n=311-320 (2026-07-21)",
      "repo": "apache/hbase",
      "key": "hbase-4577",
      "introducing_pr": 4577,
      "fixing_pr": 7465,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "suspend/wake race missed",
      "defect": "SplitWAL suspend/wake race leaves procedure WAITING forever",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 314,
      "batch": "n=311-320 (2026-07-21)",
      "repo": "apache/accumulo",
      "key": "accumulo-5335",
      "introducing_pr": 5335,
      "fixing_pr": 5342,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "TabletsMetadata.fetch iterates fetchedCols not colsToFetch",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 315,
      "batch": "n=311-320 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-9292",
      "introducing_pr": 9292,
      "fixing_pr": 23759,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Cursor individual-ack long-array serialize loses ranges when OpenCacheSet disabled",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 316,
      "batch": "n=311-320 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-10964",
      "introducing_pr": 10964,
      "fixing_pr": 18901,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "listConsumerGroupOffsets Map overload drops requireStable options",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 317,
      "batch": "n=311-320 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-19026",
      "introducing_pr": 19026,
      "fixing_pr": 22714,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "LATEST startOffset missed",
      "defect": "Share group new partitions always startOffset -1 LATEST skips existing records",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 318,
      "batch": "n=311-320 (2026-07-21)",
      "repo": "apache/flink",
      "key": "flink-27071",
      "introducing_pr": 27071,
      "fixing_pr": 28242,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "LinkedMultiSetState updates highestSqn on replace breaking monotonic SQN",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 319,
      "batch": "n=311-320 (2026-07-21)",
      "repo": "apache/paimon",
      "key": "paimon-7093",
      "introducing_pr": 7093,
      "fixing_pr": 8698,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "IncrementalSplit assignSuggestedTask returns raw postpone bucket -2 drops splits",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 320,
      "batch": "n=311-320 (2026-07-21)",
      "repo": "apache/paimon",
      "key": "paimon-8287",
      "introducing_pr": 8287,
      "fixing_pr": 8333,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Overwrite lookupEnabled gate also disables remote lookup file materialization",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 321,
      "batch": "n=321-330 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-11555",
      "introducing_pr": 11555,
      "fixing_pr": 15470,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "file_size_in_bytes missed",
      "defect": "RewriteTablePath keeps stale file_size_in_bytes for rewritten position deletes",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 322,
      "batch": "n=321-330 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-15685",
      "introducing_pr": 15685,
      "fixing_pr": 18738,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Utf8 desync missed",
      "defect": "Utf8.encodedLength throws mid-loop desyncing MutableJsonIndex docId mapping",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 323,
      "batch": "n=321-330 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-17308",
      "introducing_pr": 17308,
      "fixing_pr": 18503,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ExpressionTransformer null overwrite wipes existing BYTES on partial upsert",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 324,
      "batch": "n=321-330 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-18280",
      "introducing_pr": 18280,
      "fixing_pr": 18447,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "lengthOfLongestElement backfill skips dictionaryElementSize==0 empty strings",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 325,
      "batch": "n=321-330 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-49399",
      "introducing_pr": 49399,
      "fixing_pr": 49953,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "TokenManager.isValidScope drops AuthorizationRequestContext parameter",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 326,
      "batch": "n=321-330 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-44922",
      "introducing_pr": 44922,
      "fixing_pr": 50859,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Reset password action token reuse returns error without transaction rollback",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 327,
      "batch": "n=321-330 (2026-07-21)",
      "repo": "apache/knox",
      "key": "knox-1154",
      "introducing_pr": 1154,
      "fixing_pr": 1219,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "JWTFederationFilter grant_type param hidden by wrappers so Basic client_credentials no-op",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 328,
      "batch": "n=321-330 (2026-07-21)",
      "repo": "hazelcast/hazelcast",
      "key": "hazelcast-19850",
      "introducing_pr": 19850,
      "fixing_pr": 25508,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ExplainStatementPlan missing checkPermissions leaks plan/schema",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 329,
      "batch": "n=321-330 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-7586",
      "introducing_pr": 7586,
      "fixing_pr": 50463,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Client URI scheme validation case-sensitive allows JaVaSCript data URIs",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 330,
      "batch": "n=321-330 (2026-07-21)",
      "repo": "apache/ozone",
      "key": "ozone-10197",
      "introducing_pr": 10197,
      "fixing_pr": 10771,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "S3 actions attached to authorizer context even when STS feature flag off",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 331,
      "batch": "n=331-340 (2026-07-21)",
      "repo": "datahub-project/datahub",
      "key": "datahub-14588",
      "introducing_pr": 14588,
      "fixing_pr": 17904,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "SetLogicalParentResolver no authorization on dual-resource parent link",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 332,
      "batch": "n=331-340 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-19467",
      "introducing_pr": 19467,
      "fixing_pr": 19976,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Txn ownership check only principal omits dual proxy originalPrincipal",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 333,
      "batch": "n=331-340 (2026-07-21)",
      "repo": "apache/ozone",
      "key": "ozone-9445",
      "introducing_pr": 9445,
      "fixing_pr": 9602,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "STS revoke only checks session key not original permanent access key",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 334,
      "batch": "n=331-340 (2026-07-21)",
      "repo": "undertow-io/undertow",
      "key": "undertow-1702",
      "introducing_pr": 1702,
      "fixing_pr": 1908,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ServletCookieAdaptor setSameSite(true) always forces Lax ignoring mode",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 335,
      "batch": "n=331-340 (2026-07-21)",
      "repo": "apache/ranger",
      "key": "ranger-doas",
      "introducing_pr": "5bc3cb303e11",
      "fixing_pr": 915,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "JWT doAs replaces subject without impersonation authorization",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 336,
      "batch": "n=331-340 (2026-07-21)",
      "repo": "apache/ranger",
      "key": "ranger-jwt-log",
      "introducing_pr": "fb53a3dc0022",
      "fixing_pr": 1081,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "JWT validation failure logs full serialize bearer credential",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 337,
      "batch": "n=331-340 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-123610",
      "introducing_pr": 123610,
      "fixing_pr": 125916,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "TopHitsAggregationBuilder disables parallel collection for field sorts",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 338,
      "batch": "n=331-340 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-142047",
      "introducing_pr": 142047,
      "fixing_pr": 142363,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "cell-size rehash missed",
      "defect": "HLL LinearCounting starts all groups at size 32 causing rehash storm",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 339,
      "batch": "n=331-340 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-146433",
      "introducing_pr": 146433,
      "fixing_pr": 154519,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "NDJSON lenient decode allocates page-sized scratch builders per record",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 340,
      "batch": "n=331-340 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-148331",
      "introducing_pr": 148331,
      "fixing_pr": 152938,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "ImplicitPrivilegesProvider rebuilds StringMatcher every role build",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 341,
      "batch": "n=341-350 (2026-07-21)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-20857",
      "introducing_pr": 20857,
      "fixing_pr": 20915,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "sold-as-safer cleared",
      "defect": "SignificantTextAggregator disables concurrent segment search when filterDuplicateText",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 342,
      "batch": "n=341-350 (2026-07-21)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-11643",
      "introducing_pr": 11643,
      "fixing_pr": 20623,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Terms agg precompute via terms dictionary regresses high-cardinality fields",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 343,
      "batch": "n=341-350 (2026-07-21)",
      "repo": "apache/logging-log4j2",
      "key": "log4j2-2101",
      "introducing_pr": 2101,
      "fixing_pr": 2256,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "JdkMapAdapterStringMap probes immutability via replace throwing on hot path",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 344,
      "batch": "n=341-350 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-15609",
      "introducing_pr": 15609,
      "fixing_pr": 15977,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "OpChain cache retains MultiStageOperator trees with large maps after EOS",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 345,
      "batch": "n=341-350 (2026-07-21)",
      "repo": "spring-projects/spring-framework",
      "key": "spring-jackson3-recycler",
      "introducing_pr": "5cb2f870d047",
      "fixing_pr": 37059,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "AbstractJacksonEncoder acquires BufferRecycler never releaseToPool under Jackson 3",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 346,
      "batch": "n=341-350 (2026-07-21)",
      "repo": "apache/ignite",
      "key": "ignite-22375",
      "introducing_pr": "8f1d5a280c",
      "fixing_pr": 11797,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "sold-as-faster cleared",
      "defect": "writeUuidRaw bulk I/O cannot partial-progress on fragmented buffers sold-as-faster",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 347,
      "batch": "n=341-350 (2026-07-21)",
      "repo": "apache/logging-log4j2",
      "key": "log4j2-2301-tl",
      "introducing_pr": "b34d8cc585",
      "fixing_pr": 251,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "AsyncLoggerConfig ThreadLocal remove forces setInitialValue allocation hot path",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 348,
      "batch": "n=341-350 (2026-07-21)",
      "repo": "apache/avro",
      "key": "avro-2608",
      "introducing_pr": 2608,
      "fixing_pr": 3813,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "TimestampNanosConversion pre-epoch uses micros-scale constant instead of nanos",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 349,
      "batch": "n=341-350 (2026-07-21)",
      "repo": "apache/parquet-java",
      "key": "parquet-1111",
      "introducing_pr": 1111,
      "fixing_pr": 3543,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "LocalInputFile ByteBuffer read wrong offset and arrayOffset on direct buffers",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 350,
      "batch": "n=341-350 (2026-07-21)",
      "repo": "apache/solr",
      "key": "solr-2402",
      "introducing_pr": 2402,
      "fixing_pr": 3992,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "double-register missed",
      "defect": "HttpJettySolrClient double registers asyncTracker listeners on async requests",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 351,
      "batch": "n=351-360 (2026-07-21)",
      "repo": "apache/maven-resolver",
      "key": "maven-resolver-1896",
      "introducing_pr": 1896,
      "fixing_pr": 1904,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "PathConflictResolver cycle handling reuses residual cycle state wrong",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 352,
      "batch": "n=351-360 (2026-07-21)",
      "repo": "micronaut-projects/micronaut-core",
      "key": "micronaut-12086",
      "introducing_pr": 12086,
      "fixing_pr": 12796,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "DefaultReplacesDefinition getBeanType fails for AOP proxied default implementations",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 353,
      "batch": "n=351-360 (2026-07-21)",
      "repo": "hibernate/hibernate-orm",
      "key": "hibernate-5471",
      "introducing_pr": 5471,
      "fixing_pr": 5547,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "StandardForeignKeyExporter double i++ skips composite FK columns",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 354,
      "batch": "n=351-360 (2026-07-21)",
      "repo": "apache/rocketmq",
      "key": "rocketmq-9521",
      "introducing_pr": 9521,
      "fixing_pr": 10426,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "TopicConfigManager skips DataVersion nextVersion under enableSplitRegistration",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 355,
      "batch": "n=351-360 (2026-07-21)",
      "repo": "apache/rocketmq",
      "key": "rocketmq-7687",
      "introducing_pr": 7687,
      "fixing_pr": 8331,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "bornTime skew cleared",
      "defect": "Proxy stamps bornTime causing POLLING_TIMEOUT under clock skew",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 356,
      "batch": "n=351-360 (2026-07-21)",
      "repo": "apache/rocketmq",
      "key": "rocketmq-7694",
      "introducing_pr": 7694,
      "fixing_pr": 8209,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "FileRegionEncoder CompositeByteBuf wrap corrupts TLS queryMsgByUniqueKey",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 357,
      "batch": "n=351-360 (2026-07-21)",
      "repo": "apache/rocketmq",
      "key": "rocketmq-10204",
      "introducing_pr": 10204,
      "fixing_pr": 10254,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "unmarkWildcardGroupIfNecessary splits on whitespace not @",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 358,
      "batch": "n=351-360 (2026-07-21)",
      "repo": "hazelcast/hazelcast",
      "key": "hazelcast-19304",
      "introducing_pr": 19304,
      "fixing_pr": 19468,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "SingleProtocolEncoder signalProtocolLoaded races setupNextEncoder NPE",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 359,
      "batch": "n=351-360 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-1521",
      "introducing_pr": 1521,
      "fixing_pr": 1548,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "asyncAddEntry enqueue vs send split across threads races writers",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 360,
      "batch": "n=351-360 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-115017",
      "introducing_pr": 115017,
      "fixing_pr": 115127,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "EsqlSession runPhase before updateExecutionInfoAtEndOfPlanning race",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 361,
      "batch": "n=361-370 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-21135",
      "introducing_pr": 21135,
      "fixing_pr": 21279,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "backoff race cleared",
      "defect": "ProducerIdManager request-path clears backoff racing handleUnsuccessfulResponse",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 362,
      "batch": "n=361-370 (2026-07-21)",
      "repo": "spring-projects/spring-kafka",
      "key": "spring-kafka-2613",
      "introducing_pr": 2613,
      "fixing_pr": 2629,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH (blind re-score 07-22; was self-scored MISS \u2014 childStopped/lifecycleMonitor deadlock named 3/3)",
      "defect": "childStopped synchronized lifecycleMonitor then doStart deadlock",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 363,
      "batch": "n=361-370 (2026-07-21)",
      "repo": "trinodb/trino",
      "key": "trino-14644",
      "introducing_pr": 14644,
      "fixing_pr": 22302,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "EvictableCache token revive races concurrent invalidation",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 364,
      "batch": "n=361-370 (2026-07-21)",
      "repo": "apache/hudi",
      "key": "hudi-9936",
      "introducing_pr": 9936,
      "fixing_pr": 13650,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "ComplexAvroKeyGenerator single-field bare value breaks key encoding upgrade",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 365,
      "batch": "n=361-370 (2026-07-21)",
      "repo": "debezium/debezium",
      "key": "debezium-7269",
      "introducing_pr": 7269,
      "fixing_pr": 7350,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ChangeEventSourceCoordinator never sets streaming from streamingConnected",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 366,
      "batch": "n=361-370 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-13804",
      "introducing_pr": 13804,
      "fixing_pr": 14270,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "optional-path residual cleared",
      "defect": "Accessor hasOptionalFieldInPath incomplete for nested nullability binding",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 367,
      "batch": "n=361-370 (2026-07-21)",
      "repo": "apache/druid",
      "key": "druid-13653",
      "introducing_pr": 13653,
      "fixing_pr": 13714,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "SimpleDictionaryMergingIterator drops values on equal heads without advance",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 368,
      "batch": "n=361-370 (2026-07-21)",
      "repo": "apache/hudi",
      "key": "hudi-17994",
      "introducing_pr": 17994,
      "fixing_pr": 18738,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Flink getRecordKeyStr always requires PK blocking append-only tables",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 369,
      "batch": "n=361-370 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-40938",
      "introducing_pr": 40938,
      "fixing_pr": 50211,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ExternalToInternalTokenExchangeProvider missing canExchangeTo IdP permission",
      "finder_model": "Grok 4.5",
      "scoring": "blind-rescored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 370,
      "batch": "n=361-370 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-13185",
      "introducing_pr": 13185,
      "fixing_pr": 50841,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "BruteForceUsersResource prefix search skips canView FGAP filter",
      "finder_model": "Grok 4.5",
      "scoring": "self-scored",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 371,
      "batch": "n=371-380 (2026-07-21)",
      "repo": "apache/activemq-artemis",
      "key": "artemis-4583",
      "introducing_pr": 4583,
      "fixing_pr": 6480,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "MQTTStateManager.getSessionState (new in #4583) uses non-atomic ConcurrentHashMap",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 372,
      "batch": "n=371-380 (2026-07-21)",
      "repo": "apache/curator",
      "key": "curator-297",
      "introducing_pr": 297,
      "fixing_pr": 1278,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "CURATOR-495 / #297 added `runSafeService` (default",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 373,
      "batch": "n=371-380 (2026-07-21)",
      "repo": "apache/curator",
      "key": "curator-171",
      "introducing_pr": 171,
      "fixing_pr": 1264,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "PersistentTtlNode (CURATOR-351 / #171) creates an internal",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 374,
      "batch": "n=371-380 (2026-07-21)",
      "repo": "apache/solr",
      "key": "solr-3349",
      "introducing_pr": 3349,
      "fixing_pr": 4189,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#3349 switched globalCircuitBreakerMap to ConcurrentHashMap but left map values as plain ArrayLists mutated via computeIfAbsent + list.add with no extra sync \u2014 concurrent core-load races list growth \u2192 AIOOBE.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 375,
      "batch": "n=371-380 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-19885",
      "introducing_pr": 19885,
      "fixing_pr": 21253,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "#19885 made OffsetFetch use topic IDs; response parsing resolves topicId \u2192 name via",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 376,
      "batch": "n=371-380 (2026-07-21)",
      "repo": "apache/paimon",
      "key": "paimon-4328",
      "introducing_pr": 4328,
      "fixing_pr": 8684,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#4328 replaced atomic `connections.computeIfAbsent(...)` in",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 377,
      "batch": "n=371-380 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-13976",
      "introducing_pr": 13976,
      "fixing_pr": 14237,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "IdealStateGroupCommit (new in #13976) batches concurrent IdealState updaters then blindly writes a precomputed IdealState via updateIdealState\u2019s lambda, racing ZK version: a concurrent write between local batch application and the CAS set c",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 378,
      "batch": "n=371-380 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-26051",
      "introducing_pr": 26051,
      "fixing_pr": 26075,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#26051 made `NonPersistentTopic.internalSubscribe` migration redirect async/fire-and-forget: `getMigratedClusterUrlAsync().thenAccept(consumer::topicMigrated)` races with immediate `addConsumerToSubscription(...)`. `topicMigrated` (s",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 379,
      "batch": "n=371-380 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-26044",
      "introducing_pr": 26044,
      "fixing_pr": 26110,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#26044 adds `TopicPolicyListenerWrapper` that buffers live topic-policy updates until `completeInitialization`. `PersistentTopic.initialize()` logs-and-continues when the *initial* policy load fails, but never completes the wrapper \u2014 so lat",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 380,
      "batch": "n=371-380 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-11389",
      "introducing_pr": 11389,
      "fixing_pr": 17056,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "ManagedLedgerImpl.internalTrimLedgers (added invalidateReadHandle call when ledger is retained for retention but durable cursors are drained) races with non-durable cursor reads. A reader can obtain a BlobStoreBackedReadHandleImpl from ledg",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 381,
      "batch": "n=381-390 (2026-07-21)",
      "repo": "apache/rocketmq",
      "key": "rocketmq-10239",
      "introducing_pr": 10239,
      "fixing_pr": 10267,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "BatchSplittingMetricExporter.export() (added in #10239) splits large metric batches and fires N concurrent delegate.export() calls via CompletableResultCode.ofAll without serializing against OTel\u2019s REUSABLE_DATA marshaler pool. The pool use",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 382,
      "batch": "n=381-390 (2026-07-21)",
      "repo": "apache/solr",
      "key": "solr-3398",
      "introducing_pr": 3398,
      "fixing_pr": 3843,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent only",
      "defect": "ParallelHttpShardHandler wraps `super.makeShardRequest` in a `FutureTask`",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 383,
      "batch": "n=381-390 (2026-07-21)",
      "repo": "apache/accumulo",
      "key": "accumulo-6484",
      "introducing_pr": 6484,
      "fixing_pr": 6485,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "design only",
      "defect": "New `FileOperations.openFile(FileSystem, Path, FileStatus)` awaits Hadoop's `FutureDataInputStreamBuilder` and, on `ExecutionException`, always wraps the cause in a fresh `IOException(\"Error trying to open file\u2026\")`. Callers / tests that mat",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 384,
      "batch": "n=381-390 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-6811",
      "introducing_pr": 6811,
      "fixing_pr": 8470,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#6811 adds lazy snapshot loading in `TableMetadata` so a metadata",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 385,
      "batch": "n=381-390 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-7581",
      "introducing_pr": 7581,
      "fixing_pr": 8969,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#7581 rewrote the partitions metadata table to scan `ManifestEntry` (not just live files) so it could expose `last_updated_ms` / `last_updated_snapshot_id`. The new `readEntries()` helper used `ManifestReader.entries()` instead of `liveEntr",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 386,
      "batch": "n=381-390 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-10547",
      "introducing_pr": 10547,
      "fixing_pr": 13435,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#10547 added `calculateMetadataSchema()` to reassign field IDs for the `_partition` metadata column when the table has >1k columns. The new `Schema(metaColumnFields, table.schema().identifierFieldIds(), \u2026)` constructor copies the **parent t",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 387,
      "batch": "n=381-390 (2026-07-21)",
      "repo": "apache/ozone",
      "key": "ozone-9115",
      "introducing_pr": 9115,
      "fixing_pr": 10545,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "HDDS-13756 (#9115) switched FSO/key delete quota accounting to `decrUsedNamespace(1L, isKeyNonEmpty)` where `isKeyNonEmpty = !OmKeyInfo.isKeyEmpty(omKeyInfo)`, so snapshotUsedNamespace is only incremented for non-empty keys. FSO **directori",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 388,
      "batch": "n=381-390 (2026-07-21)",
      "repo": "apache/paimon",
      "key": "paimon-4246",
      "introducing_pr": 4246,
      "fixing_pr": 8708,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "#4246 adds complex-type JSON parsing in `TypeUtils` for CDC (MAP/ROW/",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 389,
      "batch": "n=381-390 (2026-07-21)",
      "repo": "apache/paimon",
      "key": "paimon-7330",
      "introducing_pr": 7330,
      "fixing_pr": 8676,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Lumina vector-index options (#7330) persist `lumina.distance.metric` into durable index meta via the raw options map. Users may configure enum-form names (`L2`, `COSINE`, `INNER_PRODUCT`) which `parseMetric()` accepts, but the read path `Lu",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 390,
      "batch": "n=381-390 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-10978",
      "introducing_pr": 10978,
      "fixing_pr": 18813,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "In `BaseSingleSegmentConversionExecutor.executeTask`, #10978 wrapped segment upload in try/catch to meter `SEGMENT_UPLOAD_FAIL_COUNT` and log, but unlike the download path it never rethrew. After a failed upload the method still returns `se",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 391,
      "batch": "n=391-400 (2026-07-21)",
      "repo": "trinodb/trino",
      "key": "trino-26405",
      "introducing_pr": 26405,
      "fixing_pr": 26806,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "#26405 introduces `RowBlock.startOffset` so `getRegion` can share nested",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 392,
      "batch": "n=391-400 (2026-07-21)",
      "repo": "trinodb/trino",
      "key": "trino-21070",
      "introducing_pr": 21070,
      "fixing_pr": 21073,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#21070 \"Reduce redundant TrinoInputFile.length call\" threads a `length`",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 393,
      "batch": "n=391-400 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-13080",
      "introducing_pr": 13080,
      "fixing_pr": 16011,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "Dynamic Iceberg Sink (#13080) has `DynamicWriteResultAggregator.open()`",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 394,
      "batch": "n=391-400 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-10351",
      "introducing_pr": 10351,
      "fixing_pr": 16237,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "Kafka Connect `Coordinator.commit` (#10351) wraps `doCommit` in `catch (Exception e) { LOG.warn(\"Commit failed, will try again next cycle\", e); }` and always runs `commitState.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 395,
      "batch": "n=391-400 (2026-07-21)",
      "repo": "FasterXML/jackson-databind",
      "key": "jackson-5639",
      "introducing_pr": 5639,
      "fixing_pr": 5858,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "PR #5639 taught `TypeFactory._fromParamType` to resolve unbounded wildcards to the type variable's declared upper bound (`[databind#5285]`). The self-referential guard `_isSelfReferentialTypeParameter` only caught *direct* `T ext",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 396,
      "batch": "n=391-400 (2026-07-21)",
      "repo": "apache/camel",
      "key": "camel-23121",
      "introducing_pr": 23121,
      "fixing_pr": 23130,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#23121 (watch mode) adds a field `final AtomicBoolean running = new AtomicBoolean(true)` and `waitForUserEnter()` that sets **the field** false, but `doCall()` still declares `final AtomicBoolean running = new AtomicBoolean(true)` (local). ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 397,
      "batch": "n=391-400 (2026-07-21)",
      "repo": "apache/camel",
      "key": "camel-20100",
      "introducing_pr": 20100,
      "fixing_pr": 24255,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent only",
      "defect": "#20100 (CAMEL-22740) introduced `SmbOperations.atomicRenameFile` calling `src.rename(to)` with the path as-is. smbj `DiskEntry.rename()` does **not** normalize `/`\u2192`\\\\` (unlike `DiskShare.openFile` / `SmbPath.rewritePath`), so Windows SMB r",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 398,
      "batch": "n=391-400 (2026-07-21)",
      "repo": "apache/commons-lang",
      "key": "commons-lang-1561",
      "introducing_pr": 1561,
      "fixing_pr": 1749,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent only",
      "defect": "`BitField.getValue(int|long)` shifts with arithmetic `>>`. When the field mask sits on the top bit of the holder (bit 31 / bit 63), `getRawValue` yields a negative masked value and `>>` sign-ext",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 399,
      "batch": "n=391-400 (2026-07-21)",
      "repo": "apache/flink",
      "key": "flink-24812",
      "introducing_pr": 24812,
      "fixing_pr": 28762,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "`ForStDBBunchPutRequest.buildSerializedValue` (new in #24812 Map Async State API) serializes user values with bare `userValueSerializer.serialize(...)` and no leading null boolean. `ForStMapState.serializeValue` / single-put path write `wri",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 400,
      "batch": "n=391-400 (2026-07-21)",
      "repo": "apache/kafka",
      "key": "kafka-18115",
      "introducing_pr": 18115,
      "fixing_pr": 21167,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#18115 (KAFKA-18015 / byDuration auto.offset.reset) on `TimeoutException` during duration seek does `task.maybeInitTaskTimeoutOrThrow(...); stateUpdater.add(task)`. Handing the active task back to the state-updater during reset-by-duration ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 401,
      "batch": "n=401-410 (2026-07-21)",
      "repo": "apache/logging-log4j2",
      "key": "log4j2-319",
      "introducing_pr": 319,
      "fixing_pr": 4125,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#319 added app",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 402,
      "batch": "n=401-410 (2026-07-21)",
      "repo": "apache/lucene",
      "key": "lucene-15171",
      "introducing_pr": 15171,
      "fixing_pr": 16377,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent only",
      "defect": "Default `VectorScorer.bulk(matchingDocs)` (added in #15171) calls `iterator.nextDoc()` during construction when `docID() == -1`. `Bulk.fromRandomScorerDense/Sparse` defer positioning to the first `nextDocsAndScores`. Eager advance breaks co",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 403,
      "batch": "n=401-410 (2026-07-21)",
      "repo": "apache/lucene",
      "key": "lucene-13032",
      "introducing_pr": 13032,
      "fixing_pr": 15702,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#13032 rewrote the constructor to avoid a double `bytesStartArray.bytesUsed()` call: `final Counter bytesUsed = bytesStartArray.bytesUsed(); this.bytesUsed = bytesUsed == null ? Counter.newCounter() : bytesUsed;` then calls `bytesUsed.addAn",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 404,
      "batch": "n=401-410 (2026-07-21)",
      "repo": "apache/ozone",
      "key": "ozone-10469",
      "introducing_pr": 10469,
      "fixing_pr": 10756,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "#10469 removes `OMClientRequest.getUserIfNotExists` (the getCurrentUser / OM-address fallback) and routes `preExecute` through `getUserInfo()` only, int",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 405,
      "batch": "n=401-410 (2026-07-21)",
      "repo": "apache/camel",
      "key": "camel-24557",
      "introducing_pr": 24557,
      "fixing_pr": 24695,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "CAMEL-23974 / #24557 \u201cPass OAuth credentials from ZeebeComponent to ZeebeService\u201d makes `clientId`/`clientSecret`/`oAuthAPI` reach `ZeebeService` so **ZeebeClient** ops (`startProcess`, job worker) authenticate \u2014 but 7/9 operations still us",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 406,
      "batch": "n=401-410 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-14059",
      "introducing_pr": 14059,
      "fixing_pr": 16023,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "Deprecation cleanup (#14059) inlined 6-arg `fetchToken(...)` on non-exchange refresh paths with `ImmutableMap.of()` instead of forwarding `optionalOAuthParams` (audience / resource / scope). Initial token fetch still passes optional params;",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 407,
      "batch": "n=401-410 (2026-07-21)",
      "repo": "apache/james-project",
      "key": "james-2985",
      "introducing_pr": 2985,
      "fixing_pr": 3029,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent only",
      "defect": "JAMES-4193 / #2985 introduces `TCNativeEncryptionFactory` (BoringSSL via Netty tcnative). When `enabledCipherSuites` is set it calls `builder.ciphers(Arrays.asList(...))` **without** `IdentityCipherSuiteFilter`. Netty\u2019s default `SupportedCi",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 408,
      "batch": "n=401-410 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-17238",
      "introducing_pr": 17238,
      "fixing_pr": 18252,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#17238 adds admin `updateProperties` and gates it with `validateTopicOperationAsync(topicName, TopicOperation.PRODUCE)`. Any principal with produce permission can mutate topic metadata; only tenant-admin / super-user should (wrong permissio",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 409,
      "batch": "n=401-410 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-58942",
      "introducing_pr": 58942,
      "fixing_pr": 59693,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#58942 changes submit-async-search authorization to always succeed with `IndexAuthorizationResult(true, IndicesAccessControl.ALLOW_NO_INDICES)` so CCS remote-only searches work without local index privileges. That fills the thread-context *",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 410,
      "batch": "n=401-410 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-48320",
      "introducing_pr": 48320,
      "fixing_pr": 49613,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent only",
      "defect": "ORGANIZATIONS FGAP resource type (#48320) wired `OrganizationMemberResource.getOrganizations` with `auth.users().requireView(member)` and a non-FGAP early-return, but when FGAP is enabled it returns `provider.getByMember(member)` **without*",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 411,
      "batch": "n=411-420 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-37038",
      "introducing_pr": 37038,
      "fixing_pr": 50914,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent only",
      "defect": "Groups resource type / FGAP evaluation (#37038) left `GroupResource.getSubGroups` gated only by `auth.groups().requireView(group)` (+ child `canView` stream filter) and **never** `auth.groups().requireList()`. CVE-2026-14615 / #50617: with ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 412,
      "batch": "n=411-420 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-49653",
      "introducing_pr": 49653,
      "fixing_pr": 50538,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "CACHELESS single-use object JPA provider (#49653) implements `put()` with `lifespanSeconds > 0` validation but `putIfAbsent()` inserts with `expire = currentTime + lifespanInSeconds` **without** that guard. Non-positive lifespan yields a bo",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 413,
      "batch": "n=411-420 (2026-07-21)",
      "repo": "apache/flink",
      "key": "flink-19701",
      "introducing_pr": 19701,
      "fixing_pr": 28489,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "RocksDB native Statistics metrics (#19701 / FLINK-24786) construct a Java `Statistics` wrapper and null it on monitor close **without** `statistics.close()`. JNI shared_ptr never released; with frocksdb 8.10+ finalizers gone, TaskManager na",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 414,
      "batch": "n=411-420 (2026-07-21)",
      "repo": "apache/flink",
      "key": "flink-24880",
      "introducing_pr": 24880,
      "fixing_pr": 28251,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent only",
      "defect": "Manual SST compaction Compactor (#24880 / FLINK-26050) calls `cfName.getDescriptor().getOptions().numLevels()` and never closes the returned native `ColumnFamilyOptions`. Leaked options retain shared block-cache `shared_ptr` \u2192 block cache n",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 415,
      "batch": "n=411-420 (2026-07-21)",
      "repo": "apache/lucene",
      "key": "lucene-15971",
      "introducing_pr": 15971,
      "fixing_pr": 16316,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "#15971 \u201cEliminate redundant cardinality() pass\u201d moves `docAndScoreAccBuffer.growNoCopy(INNER_WINDOW_SIZE)` into the `MaxScoreBulkScorer` constructor (sold as faster by dropping a bitset count pass). That eagerly grows ~48KB int+double buffe",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 416,
      "batch": "n=411-420 (2026-07-21)",
      "repo": "apache/lucene",
      "key": "lucene-15592",
      "introducing_pr": 15592,
      "fixing_pr": 15687,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#15592 \u201cOptimize DocIdSetIteratorAcceptDocs#cost\u201d (sold-as-faster filtered search) stops materializing the accept BitSet inside `cost()` and instead returns `iterator().cost()` when the bitset has not been built yet. That makes `cost()` dep",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 417,
      "batch": "n=411-420 (2026-07-21)",
      "repo": "apache/paimon",
      "key": "paimon-8567",
      "introducing_pr": 8567,
      "fixing_pr": 8691,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "#8567's `AvroBytesArray` \"optimize\" does not keep the original Avro payload; it decodes every element and re-encodes into a new buffer with offsets, then re-decodes the entire array on any element access \u2014 leaving both raw and decoded repre",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 418,
      "batch": "n=411-420 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-16344",
      "introducing_pr": 16344,
      "fixing_pr": 17489,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent only",
      "defect": "Commit-time compaction (#16344) teaches `SizeBasedSegmentFlushThresholdComputer` to prefer `preCommitRows` from `CommittingSegmentDescriptor` (filled from `reqParams.getNumRows()`) over post-commit totalDocs so thresholds track pre-compacti",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 419,
      "batch": "n=411-420 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-127849",
      "introducing_pr": 127849,
      "fixing_pr": 130576,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "#127849 \u201cOptimize ordinal inputs in Values aggregation\u201d (sold-as-faster; 461ms\u2192192ms for 10k groups) adds `ValuesBytesRefAggregators.wrapAddInput` ordinal fast-path into VALUES grouping. With ordinals grouping, intermediate merge of VALUES ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 420,
      "batch": "n=411-420 (2026-07-21)",
      "repo": "google/guava",
      "key": "guava-7181",
      "introducing_pr": 7181,
      "fixing_pr": 7198,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "#7181's latest `Iterators.singletonIterator` micro-optimization (rewritten state machine / allocation shape) regressed real workloads; Bazel reported a performance regression. Pointable change is confined to `Iterators.java` singletonIterat",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 421,
      "batch": "n=421-430 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-11200",
      "introducing_pr": 11200,
      "fixing_pr": 12611,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent: double-count stats, not CME on shared _docIdSets",
      "defect": "AndDocIdSet/OrDocIdSet.iterator() mutates shared _docIdSets list while getNumEntriesScannedInFilter iterates it \u2192 ConcurrentModificationException under early termination",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 422,
      "batch": "n=421-430 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-24551",
      "introducing_pr": 24551,
      "fixing_pr": 24569,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via concurrency: Case 5 recursive cancel does not release reentran",
      "defect": "pendingReadOpMutex cancelPendingReadRequest recursion / concurrent cancel vs delay-task \u2192 infinite recursive cancels",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 423,
      "batch": "n=421-430 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-15067",
      "introducing_pr": 15067,
      "fixing_pr": 15971,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent: non-monotonic persistent mark-delete, not triggerComplete deadlock",
      "defect": "internalMarkDelete skip path calls mdEntry.triggerComplete() synchronously \u2192 re-enter dispatcher locks \u2192 deadlock",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 424,
      "batch": "n=421-430 (2026-07-21)",
      "repo": "hazelcast/hazelcast",
      "key": "hazelcast-8269",
      "introducing_pr": 8269,
      "fixing_pr": 8318,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via concurrency: cleanWaitersAndSignalsFor NPEs after forceUnlock ",
      "defect": "LockStoreImpl.cleanWaitersAndSignalsFor NPE when lock removed by LocalLockCleanupOperation on same thread",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 425,
      "batch": "n=421-430 (2026-07-21)",
      "repo": "trinodb/trino",
      "key": "trino-26602",
      "introducing_pr": 26602,
      "fixing_pr": 26708,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via concurrency: removeTask check-then-act on isDestroyed races; d",
      "defect": "removeTask destroy() outside global lock without idempotent destroy \u2192 concurrent cancel double-destroy Unknown group",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 426,
      "batch": "n=421-430 (2026-07-21)",
      "repo": "apache/dubbo",
      "key": "dubbo-16014",
      "introducing_pr": 16014,
      "fixing_pr": 16039,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via concurrency: streamChannelFuture demoted from final without vo",
      "defect": "TripleClientCall.start initStream before this.stream assign \u2192 onReady race sees null stream",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 427,
      "batch": "n=421-430 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-149319",
      "introducing_pr": 149319,
      "fixing_pr": 152031,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent: cancel/queue cleanup, not STOPPED/onRecoveryComplete race",
      "defect": "peer-recovery pending queue drain after STOPPED; onRecoveryComplete can start recovery against stopped service",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 428,
      "batch": "n=421-430 (2026-07-21)",
      "repo": "debezium/debezium",
      "key": "debezium-4877",
      "introducing_pr": 4877,
      "fixing_pr": 7000,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via concurrency: stop() closes Redis client before draining offset",
      "defect": "RedisOffsetBackingStore reconnect nulls client while load/save use it \u2192 NPE infinite loop (non-volatile client)",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 429,
      "batch": "n=421-430 (2026-07-21)",
      "repo": "apache/druid",
      "key": "druid-11492",
      "introducing_pr": 11492,
      "fixing_pr": 19446,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via concurrency: locationIterators HashMap and cyclic iterators sh",
      "defect": "LocalIntermediaryDataManager locationIterators plain HashMap raced by concurrent BatchAppenderator threads",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 430,
      "batch": "n=421-430 (2026-07-21)",
      "repo": "apache/pulsar",
      "key": "pulsar-19817",
      "introducing_pr": 19817,
      "fixing_pr": 19844,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "target recall via concurrency: revalidate queues on itself when a pending op is ",
      "defect": "ResourceLock pendingOperationFuture incompletable / revalidation race under concurrent invalidation",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 431,
      "batch": "n=431-440 (2026-07-21)",
      "repo": "apache/helix",
      "key": "helix-1753",
      "introducing_pr": 1753,
      "fixing_pr": 3052,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via concurrency: synchronized on Optional field that is reassigned",
      "defect": "Optional.empty() used as synchronized monitor \u2014 JVM singleton locks all DistClusterControllerStateModel instances",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 432,
      "batch": "n=431-440 (2026-07-21)",
      "repo": "apache/helix",
      "key": "helix-1564",
      "introducing_pr": 1564,
      "fixing_pr": 2698,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent: latch/preemption issues, not DEFAULT_PRIORITY_INT=-1",
      "defect": "DEFAULT_PRIORITY_INT=-1 causes false preemption and CountDownLatch(-1) non-owner unlock path",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 433,
      "batch": "n=431-440 (2026-07-21)",
      "repo": "eclipse-vertx/vert.x",
      "key": "vertx-5084",
      "introducing_pr": 5084,
      "fixing_pr": 6112,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via concurrency: Treiber-stack push CASes head before linking next",
      "defect": "HybridJacksonPool CAS-publishes stack node before newHead.next = next \u2192 concurrent pop detaches stack",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 434,
      "batch": "n=431-440 (2026-07-21)",
      "repo": "alibaba/nacos",
      "key": "nacos-10555",
      "introducing_pr": 10555,
      "fixing_pr": 14927,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent: multiTaskExecutor leak/sync notify, not HashMap TOCTOU",
      "defect": "multiTaskExecutor HashMap containsKey/put TOCTOU \u2192 duplicate executors / thread leak",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 435,
      "batch": "n=431-440 (2026-07-21)",
      "repo": "apache/rocketmq",
      "key": "rocketmq-4313",
      "introducing_pr": 4313,
      "fixing_pr": 10614,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via concurrency: Async request fires RequestCallback from send suc",
      "defect": "async request callback executeRequestCallback on send success \u2192 premature null + double-fire with timeout",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 436,
      "batch": "n=431-440 (2026-07-21)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-2842",
      "introducing_pr": 2842,
      "fixing_pr": 3503,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "adjacent: election lifecycle races, not dual close of ledgerAuditorManager",
      "defect": "ledgerAuditorManager closed in both shutdown() and submitShutdownTask() \u2192 repeated concurrent close",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 437,
      "batch": "n=431-440 (2026-07-21)",
      "repo": "apache/paimon",
      "key": "paimon-2568",
      "introducing_pr": 2568,
      "fixing_pr": 8684,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "target recall via concurrency: establishConnection aborts after close and leaves",
      "defect": "NetworkClient.sendRequest non-atomic CHM get/put orphans concurrent ServerConnection \u2192 Netty channel leak",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 438,
      "batch": "n=431-440 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-13400",
      "introducing_pr": 13400,
      "fixing_pr": 14824,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "target recall via concurrency: ScanTaskIterable.close() is a no-op; workers keep",
      "defect": "ScanTaskIterable workers race on queue empty / activeWorkers termination without poison pill",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 439,
      "batch": "n=431-440 (2026-07-21)",
      "repo": "eclipse-vertx/vert.x",
      "key": "vertx-3731",
      "introducing_pr": 3731,
      "fixing_pr": 6170,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via concurrency: Waiter remove leaves links live; cancel can reviv",
      "defect": "SimpleConnectionPool Recycle/ConnectSuccess poll waiters without disposed=true \u2192 Cancel double-completes promise",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 440,
      "batch": "n=431-440 (2026-07-21)",
      "repo": "apache/helix",
      "key": "helix-2560",
      "introducing_pr": 2560,
      "fixing_pr": 3058,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no finding names maintainer defect",
      "defect": "subscribeLeadershipChanges missing re-register of listeners after expire before leader recreate",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 441,
      "batch": "n=441-450 (2026-07-21)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-1722",
      "introducing_pr": 1722,
      "fixing_pr": 4829,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no finding names maintainer defect",
      "defect": "TxnImpl reuses one TxnRequest ByteBuf across silent gRPC retries \u2192 drained slices corrupt protobuf on retry",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 442,
      "batch": "n=441-450 (2026-07-21)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-2457",
      "introducing_pr": 2457,
      "fixing_pr": 4731,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via data: List-ledgers scan stops after first metadata range",
      "defect": "SyncLedgerIterator.hasNext returns false when currentRange exhausted without checking next ZK ledger range",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 443,
      "batch": "n=441-450 (2026-07-21)",
      "repo": "debezium/debezium",
      "key": "debezium-3982",
      "introducing_pr": 3982,
      "fixing_pr": 7654,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via data: Reconnect path abandons Jedis clients under indefinite o",
      "defect": "RedisSchemaHistory.recoverRecords returns early on first deserialize IOException \u2192 silent schema-history tail truncation",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 444,
      "batch": "n=441-450 (2026-07-21)",
      "repo": "debezium/debezium",
      "key": "debezium-4201",
      "introducing_pr": 4201,
      "fixing_pr": 7640,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "target recall via data: recoveryAttempts never resets after successful polls",
      "defect": "RocketMQ schema history recoveryAttempts never resets after progress \u2192 false abort on large/slow history",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 445,
      "batch": "n=441-450 (2026-07-21)",
      "repo": "debezium/debezium",
      "key": "debezium-7052",
      "introducing_pr": 7052,
      "fixing_pr": 7591,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no finding names maintainer defect",
      "defect": "rowCountForTableChunked uses unquoted getQualifiedTableName \u2192 crash on names needing quotes",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 446,
      "batch": "n=441-450 (2026-07-21)",
      "repo": "apache/paimon",
      "key": "paimon-4380",
      "introducing_pr": 4380,
      "fixing_pr": 6173,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via data: One physical file backs many buckets\u2019 changelog metas",
      "defect": "precommit-compact invents fake segment filenames; checkFilesExistence fails recovery on non-existent paths",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 447,
      "batch": "n=441-450 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-23665",
      "introducing_pr": 23665,
      "fixing_pr": 23832,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via performance: Every primary index now prepares/parses the docum",
      "defect": "TransportShardBulkAction always double-parses on primary after mapping update split (#23665); fix re-parses only when mapping update applied",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 448,
      "batch": "n=441-450 (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-18852",
      "introducing_pr": 18852,
      "fixing_pr": 18930,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "target recall via data: HNSW extract leaves docId mapping inside Lucene director",
      "defect": "storeInSegmentFile=true probes legacy on-disk vector index; non-local segment dirs fail instead of consolidated columns.psf",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 449,
      "batch": "n=441-450 (2026-07-21)",
      "repo": "apache/iceberg",
      "key": "iceberg-12672",
      "introducing_pr": 12672,
      "fixing_pr": 16263,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "target recall via data: first_row_id assignment corrupts under projected reuseCo",
      "defect": "Manifest merge reassigns firstRowId on EXISTING entries instead of preserving them (v3 row-lineage)",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 450,
      "batch": "n=441-450 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-80286",
      "introducing_pr": 80286,
      "fixing_pr": 90017,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no finding names maintainer defect",
      "defect": "Fields API shared cache checked per-doc not per-segment \u2192 text fields latency regression",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 451,
      "batch": "n=451-460 (2026-07-21)",
      "repo": "apache/logging-log4j2",
      "key": "log4j2-1203",
      "introducing_pr": 1203,
      "fixing_pr": 4089,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via correctness: inUse left true when isEnabled rejects \u2014 breaks s",
      "defect": "SLF4JLogger.atFatal() copy-pasted as atLevel(Level.TRACE) instead of FATAL",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 452,
      "batch": "n=451-460 (2026-07-21)",
      "repo": "apache/commons-lang",
      "key": "commons-lang-1650",
      "introducing_pr": 1650,
      "fixing_pr": 1747,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via correctness: register() before hashCode() zeroes nested reflec",
      "defect": "HashCodeBuilder.append(Object) shares ThreadLocal REGISTRY with reflectionAppend \u2192 cycle guard drops content",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 453,
      "batch": "n=451-460 (2026-07-21)",
      "repo": "netty/netty",
      "key": "netty-15413",
      "introducing_pr": 15413,
      "fixing_pr": 16188,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via correctness: ReadOnlyAbstractByteBuf CCE when Duplicated/ReadO",
      "defect": "ReadOnlyAbstractByteBuf route uses instanceof AbstractByteBuf alone \u2192 CCE on custom unwrap non-AbstractByteBuf",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 454,
      "batch": "n=451-460 (2026-07-21)",
      "repo": "redis/jedis",
      "key": "jedis-4405",
      "introducing_pr": 4405,
      "fixing_pr": 4575,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no finding names maintainer defect",
      "defect": "Combiner.addParams counts only getOwnArgs size then appends YIELD_SCORE_AS outside count \u2192 Redis rejects alias hybrid queries",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 455,
      "batch": "n=451-460 (2026-07-21)",
      "repo": "alibaba/fastjson2",
      "key": "fastjson2-3340",
      "introducing_pr": 3340,
      "fixing_pr": 7617,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no finding names maintainer defect",
      "defect": "JSONB ASM minCapacity inverted (group.start/end) under-counts BC_OBJECT frame \u2192 AIOOBE on large UTF-16 strings",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 456,
      "batch": "n=451-460 (2026-07-21)",
      "repo": "apache/camel",
      "key": "camel-17352",
      "introducing_pr": 17352,
      "fixing_pr": 24745,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "target recall via correctness: Eager idempotent remove omits isIdempotent() chec",
      "defect": "eager idempotent key drain only on Deque overload; List overload leaves keys after poll exception \u2192 permanent skip",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 457,
      "batch": "n=451-460 (2026-07-21)",
      "repo": "apache/flink",
      "key": "flink-27655",
      "introducing_pr": 27655,
      "fixing_pr": 28226,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via design: ApplicationExceptionsMessageParameters is unused by he",
      "defect": "ApplicationExceptionsMessageParameters maxExceptions never read \u2014 handler typed on parent params (orphaned scaffolding)",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 458,
      "batch": "n=451-460 (2026-07-21)",
      "repo": "hibernate/hibernate-orm",
      "key": "hibernate-6814",
      "introducing_pr": 6814,
      "fixing_pr": 6996,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via correctness: Treated path copies keep pre-reparent NavigablePa",
      "defect": "getNavigablePathCopy misses EntityIdentifierNavigablePath peel/rebuild \u2192 wrong SQM path for id joins",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 459,
      "batch": "n=451-460 (2026-07-21)",
      "repo": "debezium/debezium",
      "key": "debezium-5437",
      "introducing_pr": 5437,
      "fixing_pr": 7624,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no finding names maintainer defect",
      "defect": "provide.transaction.metadata=true mid-tx restart BEGIN replay wipes restored offset counters",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 460,
      "batch": "n=451-460 (2026-07-21)",
      "repo": "apache/paimon",
      "key": "paimon-7860",
      "introducing_pr": 7860,
      "fixing_pr": 8232,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "target recall via data: stageReplace mutates live table with no-op abort",
      "defect": "REPLACE truncate then self-ref RTAS plans against empty live table \u2192 commits empty (data loss)",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 461,
      "batch": "n=461-470 (2026-07-21)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-42134",
      "introducing_pr": 42134,
      "fixing_pr": 55308,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no finding names maintainer defect",
      "defect": "PulsarClientConfigCustomizer never calls enableTlsHostnameVerification \u2014 silently skipped despite TLS registry algorithm",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 462,
      "batch": "n=461-470 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-40006",
      "introducing_pr": 40006,
      "fixing_pr": 50699,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "target recall via security: email_verified claim applied without requiring a non",
      "defect": "OIDC broker trustEmail reads email_verified only from ID token while email may come from userinfo (CVE-2026-14781)",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 463,
      "batch": "n=461-470 (2026-07-21)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-47029",
      "introducing_pr": 47029,
      "fixing_pr": 50744,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via security: Temp-client policy conversion omits service-account ",
      "defect": "Client Admin API v2 getProposedOldRepresentation realm.addClient temp without manage-clients authorization",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 464,
      "batch": "n=461-470 (2026-07-21)",
      "repo": "netty/netty",
      "key": "netty-15919",
      "introducing_pr": 15919,
      "fixing_pr": 16990,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no finding names maintainer defect",
      "defect": "addCredentials dropped on default OPENSSL server branch \u2014 dual-cert config silently no-ops",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 465,
      "batch": "n=461-470 (2026-07-21)",
      "repo": "apache/knox",
      "key": "knox-1265",
      "introducing_pr": 1265,
      "fixing_pr": 1307,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via security: Iceberg REST SSL keyed off HiveServer2 flag, not Met",
      "defect": "Iceberg REST scheme uses hiveserver2_enable_ssl instead of hive_metastore_enable_ssl \u2192 wrong-resource TLS flag",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 466,
      "batch": "n=461-470 (2026-07-21)",
      "repo": "apache/shiro",
      "key": "shiro-2711",
      "introducing_pr": 2711,
      "fixing_pr": 2807,
      "lane": "security",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "adjacent: session attribute migration, not getSession(false) null NPE on login(n",
      "defect": "session-fixation beforeSuccessfulLogin getSession(false) without null guard \u2192 login(null, token) NPE",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 467,
      "batch": "n=461-470 (2026-07-21)",
      "repo": "apache/flink",
      "key": "flink-24079",
      "introducing_pr": 24079,
      "fixing_pr": 25509,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via correctness: seek() skips available() on the compression deleg",
      "defect": "CompressibleFSDataInputStream.seek always skip(available) even uncompressed \u2192 multi-second S3 restore reads",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 468,
      "batch": "n=461-470 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-60196",
      "introducing_pr": 60196,
      "fixing_pr": 60276,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "changeCollector gated on supportsIncrementalBucketUpdate so date-histogram-only pivots full-rescan each checkpoint",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 469,
      "batch": "n=461-470 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-57241",
      "introducing_pr": 57241,
      "fixing_pr": 57438,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via performance: No-filter path always wraps FilteredOrdinals; los",
      "defect": "global-ords terms rewrite drops single-valued-ords + no-filter specializations \u2192 multi-valued path slowdown",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 470,
      "batch": "n=461-470 (2026-07-21)",
      "repo": "elastic/elasticsearch",
      "key": "es-101538",
      "introducing_pr": 101538,
      "fixing_pr": 112558,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "target recall via design: Identical health-support gate repeated in three servic",
      "defect": "expensive clusterHasFeature(SUPPORTS_HEALTH) ahead of cheap local-master checks on HealthNodeTaskExecutor.startTask",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 471,
      "batch": "n=471-474 incomplete-wiring validation (2026-07-21)",
      "repo": "AsyncHttpClient/async-http-client",
      "key": "ahc-2104",
      "introducing_pr": 2104,
      "fixing_pr": 2243,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "incomplete-wiring fresh-pair HIT (endpoint ID JSSE arm)",
      "defect": "#2104 removes shared setEndpointIdentificationAlgorithm from SslEngineFactoryBase and restores it only on DefaultSslEngineFactory; JsseSslEngineFactory never sets endpoint ID \u2192 hostname verification no-op on pure JSSE path",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 472,
      "batch": "n=471-474 incomplete-wiring validation (2026-07-21)",
      "repo": "apache/ozone",
      "key": "ozone-10111",
      "introducing_pr": 10111,
      "fixing_pr": 10165,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "incomplete-wiring fresh-pair HIT (DEFAULT protocol gate)",
      "defect": "setEnabledProtocols only applies setIncludeProtocols when value != SSL_ENABLED_PROTOCOLS_DEFAULT; default TLSv1.2 path never applies protocol control to Jetty",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 473,
      "batch": "n=471-474 incomplete-wiring validation (2026-07-21)",
      "repo": "apache/camel",
      "key": "camel-20912",
      "introducing_pr": 20912,
      "fixing_pr": 24690,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "incomplete-wiring fresh-pair HIT (MSK callback omitted)",
      "defect": "saslAuthType convenience never sets OAuth/MSK callback handlers on the default path (AWS_MSK_IAM omits client callback handler)",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 474,
      "batch": "n=471-474 incomplete-wiring validation (2026-07-21)",
      "repo": "redis/jedis",
      "key": "jedis-4263",
      "introducing_pr": 4263,
      "fixing_pr": 4424,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "incomplete-wiring fresh-pair MISS (fromURI credential wipe)",
      "defect": "StandaloneClientBuilder.fromURI overwrites clientConfig, wiping credentials so default builder never AUTH",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 475,
      "batch": "n=475-480 OPENSSL multi-provider incomplete-wiring (2026-07-21)",
      "repo": "netty/netty",
      "key": "netty-10296",
      "introducing_pr": 10296,
      "fixing_pr": 10401,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "OPENSSL tickets only on REFCNT not default OPENSSL",
      "defect": "#10296 wires session-ticket enablement via setTicketKeys only on OPENSSL_REFCNT constructors; OpenSslClient/ServerContext (SslProvider.OPENSSL) never enable tickets \u2014 silent no-op on default OPENSSL",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 476,
      "batch": "n=475-480 OPENSSL multi-provider incomplete-wiring (2026-07-21)",
      "repo": "apache/pinot",
      "key": "pinot-8207",
      "introducing_pr": 8207,
      "fixing_pr": 17760,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "server GrpcSslContexts.configure wipes sslProvider",
      "defect": "Server sets .sslProvider then GrpcSslContexts.configure(builder) without provider \u2014 silently forces default OPENSSL; configured JDK provider no-ops. Client path passes provider correctly",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 477,
      "batch": "n=475-480 OPENSSL multi-provider incomplete-wiring (2026-07-21)",
      "repo": "apache/ratis",
      "key": "ratis-1462",
      "introducing_pr": 1462,
      "fixing_pr": 1511,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "TlsConf provider/ciphers ignored on Netty DataStream",
      "defect": "#1462 adds TlsConf SslProvider/protocols/ciphers applied only via GrpcUtil; DataStream NettyUtils never applies them \u2014 OPENSSL/JDK provider + ciphers silent defaults on Netty path",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 478,
      "batch": "n=475-480 OPENSSL multi-provider incomplete-wiring (2026-07-21)",
      "repo": "apache/zookeeper",
      "key": "zookeeper-2009",
      "introducing_pr": 2009,
      "fixing_pr": 2270,
      "lane": "security",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "adjacent SSL; not OCSP un-gated on JDK",
      "defect": "#2009 multi-provider OpenSSL support calls enableOcsp unconditionally; JDK default + ocsp=true throws. Control not gated to OPENSSL arm that supports stapling",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 479,
      "batch": "n=475-480 OPENSSL multi-provider incomplete-wiring (2026-07-21)",
      "repo": "fabric8io/kubernetes-client",
      "key": "fabric8-7875",
      "introducing_pr": 7875,
      "fixing_pr": 7908,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "Vert.x 5.1 WebSocket TLS arm drops trust/key material; HTTP path still applies TLS",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 480,
      "batch": "n=475-480 OPENSSL multi-provider incomplete-wiring (2026-07-21)",
      "repo": "streamthoughts/jikkou",
      "key": "jikkou-427",
      "introducing_pr": 427,
      "fixing_pr": 761,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent SSL password NPE; not authMethod trust gate",
      "defect": "SSLConfig applied only when authMethod=SSL; basicAuth/none leaves sslTrustStoreLocation configured but never on the SSL context",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 481,
      "batch": "n=481-490 (2026-07-22)",
      "repo": "apache/camel",
      "key": "camel-23771",
      "introducing_pr": 23771,
      "fixing_pr": 23777,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "CAMEL-23686 \"lighten\" DefaultUnitOfWork replaced ConcurrentLinkedDeque<Route>",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 482,
      "batch": "n=481-490 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-7707",
      "introducing_pr": 7707,
      "fixing_pr": 13916,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#7707 made LiteralTransformFunction cache result arrays and explicitly left them non-volatile (\"assignment races are benign\"). #7720 then memoizes/shares those instances across segments/threads. Concurrent transform threads can observe a no",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 483,
      "batch": "n=481-490 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-8083",
      "introducing_pr": 8083,
      "fixing_pr": 8160,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#8083 moved Thrift serialization out of the per-channel synchronized send path: added a single ServerChannels-level TSerializer field and called serialize() before acquiring the channel lock, so concurrent broker threads share one non-threa",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 484,
      "batch": "n=481-490 (2026-07-22)",
      "repo": "apache/camel",
      "key": "camel-11243",
      "introducing_pr": 11243,
      "fixing_pr": 24717,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "CAMEL-19811 restore multi-shard handling switched currentShardIterator to",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 485,
      "batch": "n=481-490 (2026-07-22)",
      "repo": "apache/flink",
      "key": "flink-22987",
      "introducing_pr": 22987,
      "fixing_pr": 28315,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "FLINK-32583 \"fix deadlock\" introduced responseChannelFutures",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 486,
      "batch": "n=481-490 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-149987",
      "introducing_pr": 149987,
      "fixing_pr": 150789,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Single async cancel/complete race in StreamingHttpResultPublisher.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 487,
      "batch": "n=481-490 (2026-07-22)",
      "repo": "hazelcast/hazelcast",
      "key": "hazelcast-7635",
      "introducing_pr": 7635,
      "fixing_pr": 7806,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#7635 stopped cleaning dead-connection invocations synchronously on channel close and moved cleanup to a periodic CleanResourcesTask on the response thread so a close/complete race would no longer drop notifications. On ClientInvocationServ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 488,
      "batch": "n=481-490 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-12292",
      "introducing_pr": 12292,
      "fixing_pr": 16339,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#12292 adds a process-wide ServerRateLimiter that all realtime consumers share, wrapping a single MetricEmitter with mutable per-minute aggregation fields (_previousMinute, _aggregateNumMessages). Partition-level limiters each own a MetricE",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 489,
      "batch": "n=481-490 (2026-07-22)",
      "repo": "apache/pulsar",
      "key": "pulsar-7255",
      "introducing_pr": 7255,
      "fixing_pr": 26046,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#7255 introduced FunctionMetaDataManager.exclusiveLeaderProducer as a plain (non-volatile) Producer field written by acquireLeadership() without holding the monitor (tailer drain would deadlock if synchronized) and read by synchronized upda",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 490,
      "batch": "n=481-490 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-16848",
      "introducing_pr": 16848,
      "fixing_pr": 18997,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#16848 (KAFKA-17305) adds kraft.version to finalized features and reads",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 491,
      "batch": "n=491-500 (2026-07-22)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-52632",
      "introducing_pr": 52632,
      "fixing_pr": 54588,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#52632 (\"Vert.x 4.5.25 optimizations\") loads `VertxServiceProvider` / `VerticleFactory` at build time via `loadServices(...)` that **instantiates** implementations and passes the live objects into `VertxCoreRecorder.configureVertx`, which b",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 492,
      "batch": "n=491-500 (2026-07-22)",
      "repo": "apache/pulsar",
      "key": "pulsar-25211",
      "introducing_pr": 25211,
      "fixing_pr": 25223,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#25211 rewrote `AdminProxyHandler#createHttpClient` to `super.createHttpClient()` + thin `customizeHttpClient` (Expect:100-continue / package-upload work). The parent call resets request timeout, and the new customize path never re-applied ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 493,
      "batch": "n=491-500 (2026-07-22)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-22404",
      "introducing_pr": 22404,
      "fixing_pr": 22486,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#22404 added recursion depth guards *and* lowered Jackson `StreamReadConstraints` / `XContentConstraints.DEFAULT_MAX_DEPTH` from 1000 to 100 (shared property `opensearch.xcontent.depth.max`). Previously valid JSON/XContent with nesting dept",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 494,
      "batch": "n=491-500 (2026-07-22)",
      "repo": "micrometer-metrics/micrometer",
      "key": "micrometer-4867",
      "introducing_pr": 4867,
      "fixing_pr": 7657,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#4867 added `DefaultExemplarSamplerFactory` with `ConcurrentMap<double[], ExemplarSamplerConfig> exemplarSamplerConfigsByHistogramUpperBounds`. Array identity is used for equals/hashCode, so two equal bound arrays never hit the cache (`@Sup",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 495,
      "batch": "n=491-500 (2026-07-22)",
      "repo": "apache/lucene",
      "key": "lucene-16177",
      "introducing_pr": 16177,
      "fixing_pr": 16253,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#16177 unified doc-values range evaluation onto a single two-phase `DocValuesRangeIterator` with bulk `intoMaybeBlock` that calls `numericValues.rangeIntoBitSet(blockStart, \u2026)`. `numericValues` is the same instance as the two-phase DISI; a ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 496,
      "batch": "n=491-500 (2026-07-22)",
      "repo": "apache/maven-resolver",
      "key": "maven-resolver-435",
      "introducing_pr": 435,
      "fixing_pr": 1915,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "IPC named locks (#435, MRESOLVER-499) register a SIGTSTP ignore handler under `if (IpcClient.IS_WINDOWS)` \u2014 inverted. On Windows (no SIGTSTP) the daemon tries to register and can crash; on Unix (where Ctrl-Z delivers SIGTSTP to the process ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 497,
      "batch": "n=491-500 (2026-07-22)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-54991",
      "introducing_pr": 54991,
      "fixing_pr": 55227,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Gizmo 2 migration (#54991) left `RepositoryMethodsImplementor.implementIterable()` generating `list(Page, Sort, String, Map)` for any CrudRepository that is not PagingAndSortingRepository. `ListCrudRepository` subtypes also hit `implementLi",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 498,
      "batch": "n=491-500 (2026-07-22)",
      "repo": "apache/camel",
      "key": "camel-22300",
      "introducing_pr": 22300,
      "fixing_pr": 24823,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#22300 (CAMEL-23264) stores `SplitFailureTracker` as a plain exchange property (`CamelSplitFailureTracker`). `exchange.copy()` shallow-copies the properties map, so the tracker leaks into nested splitters. An inner splitter with no threshol",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 499,
      "batch": "n=491-500 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-12766",
      "introducing_pr": 12766,
      "fixing_pr": 12791,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#12766 made `PinotTaskManager` multi-database-aware and added",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 500,
      "batch": "n=491-500 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-16730",
      "introducing_pr": 16730,
      "fixing_pr": 19507,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "KAFKA-17203 / #16730 fixed producer leaks by routing more close paths",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 501,
      "batch": "n=501-510 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-12502",
      "introducing_pr": 12502,
      "fixing_pr": 18952,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "#12502 added `addColumnMinMaxValueWithoutDictionary` for raw (no-dictionary) columns. For BYTES it updates min when `ByteArray.compare(value, min) > 0` and max when `ByteArray.compare(value, max) < 0` \u2014 **argument order is reversed** relati",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 502,
      "batch": "n=501-510 (2026-07-22)",
      "repo": "apache/paimon",
      "key": "paimon-6804",
      "introducing_pr": 6804,
      "fixing_pr": 8500,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#6804 renames GlobalIndexBatchScan \u2192 DataEvolutionBatchScan and adds `withShard(...)` that **returns** `batchScan.withShard(...)` (the inner scan) instead of `this`. Chained calls `withShard(...).withFilter(...)` / `.plan()` leave the data-",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 503,
      "batch": "n=501-510 (2026-07-22)",
      "repo": "apache/paimon",
      "key": "paimon-7305",
      "introducing_pr": 7305,
      "fixing_pr": 7953,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "#7305 optimizes data-evolution scan with large rowRanges and rewrites `wrap` to derive the split range from **first and last** data files only (`files.get(0).nonNullFirstRowId()` \u2026 `files.get(files.size()-1)`). That assumes `dataFiles()` ar",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 504,
      "batch": "n=501-510 (2026-07-22)",
      "repo": "trinodb/trino",
      "key": "trino-24172",
      "introducing_pr": 24172,
      "fixing_pr": 29212,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#24172 added Iceberg `$entries` / `$all_entries` system tables and wrote",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 505,
      "batch": "n=501-510 (2026-07-22)",
      "repo": "apache/druid",
      "key": "druid-18053",
      "introducing_pr": 18053,
      "fixing_pr": 18059,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#18053 added `getFieldLogicalType` for nested JSON/complex columns to",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 506,
      "batch": "n=501-510 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-16307",
      "introducing_pr": 16307,
      "fixing_pr": 16835,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent dangling-task gate; not IdealState delete retry",
      "defect": "#16307 added task-data cleanup as part of table deletion and removes",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 507,
      "batch": "n=501-510 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-16254",
      "introducing_pr": 16254,
      "fixing_pr": 17218,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Record-transform refactor #16254 changed continue-on-error behavior for",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 508,
      "batch": "n=501-510 (2026-07-22)",
      "repo": "apache/druid",
      "key": "druid-19193",
      "introducing_pr": 19193,
      "fixing_pr": 19238,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Optional MSQ groupBy row combiner #19193 built dimension/value selectors",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 509,
      "batch": "n=501-510 (2026-07-22)",
      "repo": "apache/hudi",
      "key": "hudi-6847",
      "introducing_pr": 6847,
      "fixing_pr": 8658,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#6847 multi-table `InProcessLockProvider` stores base-path\u2192lock in a",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 510,
      "batch": "n=501-510 (2026-07-22)",
      "repo": "apache/paimon",
      "key": "paimon-7121",
      "introducing_pr": 7121,
      "fixing_pr": 7409,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Row-tracking commit path `RowTrackingCommitUtils.assignSnapshotId` (#7121) only special-cases `minSequenceNumber == 0` (assign snapshotId for both min/max); otherwise it leaves the ManifestEntry unchanged. After compaction/update sequences ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 511,
      "batch": "n=511-520 (2026-07-22)",
      "repo": "AsyncHttpClient/async-http-client",
      "key": "ahc-2203",
      "introducing_pr": 2203,
      "fixing_pr": 2244,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "PR #2203 escapes `\"` / CR / LF only in multipart Content-Disposition `name` and `filename`, leaving `dispositionType`, `contentType`, `contentTransferEncoding`, `contentId`, and custom part-header name/value written raw \u2014 so CR/LF in those ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 512,
      "batch": "n=511-520 (2026-07-22)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-41501",
      "introducing_pr": 41501,
      "fixing_pr": 55211,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "PR #41501 adds `HttpCertificateUpdateEventListener` that on certificate reload calls `server.updateSSLOptions(event.tlsConfiguration().getSSLOptions())` without re-applying `quarkus.http.ssl.client-auth` / `ClientAuth`. After the first TLS ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 513,
      "batch": "n=511-520 (2026-07-22)",
      "repo": "redis/jedis",
      "key": "jedis-3980",
      "introducing_pr": 3980,
      "fixing_pr": 4495,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "PR #3980 adds `SslOptions` with default `SslVerifyMode.FULL` (endpoint identification) but refactors `DefaultJedisSocketFactory` into a dual path: when `sslOptions != null` use options SSLContext/params; else legacy `ssl=true` only applies ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 514,
      "batch": "n=511-520 (2026-07-22)",
      "repo": "AsyncHttpClient/async-http-client",
      "key": "ahc-2154",
      "introducing_pr": 2154,
      "fixing_pr": 2235,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "PR #2154 implements RFC 7804 SCRAM-SHA-256 and adds `processScramAuthenticationInfo` that verifies ServerSignature but on mismatch only `LOGGER.warn`s \u2014 the response is still delivered as success, voiding mutual authentication. Invalid/unpa",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 515,
      "batch": "n=511-520 (2026-07-22)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-38608",
      "introducing_pr": 38608,
      "fixing_pr": 45578,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#38608 adds TlsCertificateReloader for quarkus.http.ssl.certificate.reload-period.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 516,
      "batch": "n=511-520 (2026-07-22)",
      "repo": "apache/nifi",
      "key": "nifi-11257",
      "introducing_pr": 11257,
      "fixing_pr": 11396,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent HTTPS fail-open; not non-token factory wiring",
      "defect": "#11257 (NIFI-15948) switches HashiCorp Vault TLS to SSLContextProvider and",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 517,
      "batch": "n=511-520 (2026-07-22)",
      "repo": "apache/hadoop",
      "key": "hadoop-8300",
      "introducing_pr": 8300,
      "fixing_pr": 8357,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "PR #8300 (YARN-11937) adds reverse-proxy redirect support so Yarn Proxy can 302 to Knox tracking URLs without forwarding JWT: `if (!redirectFlagName.isBlank() && toFetch.getQuery().equals(redirectFlagName + \"=true\"))`. Equality against the ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 518,
      "batch": "n=511-520 (2026-07-22)",
      "repo": "AsyncHttpClient/async-http-client",
      "key": "ahc-2148",
      "introducing_pr": 2148,
      "fixing_pr": 2236,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "PR #2148 rewrites Digest to RFC 7616, replacing `match()` with `matchParam()` that returns unquoted challenge values (nonce/opaque/realm) including embedded `\"`. Existing `append()` wraps quoted params without backslash-escaping, so a serve",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 519,
      "batch": "n=511-520 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-12611",
      "introducing_pr": 12611,
      "fixing_pr": 15756,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#12611 rewrote OrDocIdSet/AndDocIdSet iterator collection to fix ConcurrentModificationException (separate scan-based lists, stop mutating the shared list). In OrDocIdSet, the BitmapBasedDocIdIterator branch kept the stats aggregate but **d",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 520,
      "batch": "n=511-520 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-90612",
      "introducing_pr": 90612,
      "fixing_pr": 90804,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#90612 made knn/vector searches cancellable via ExitableDirectoryReader. ExitableVectorValues called `queryCancellation.checkCancelled()` on **every** `vectorValue()` and `binaryValue()` \u2014 once per matched vector on the knn hot path (Rally ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 522,
      "batch": "n=521-530 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-58744",
      "introducing_pr": 58744,
      "fixing_pr": 60591,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#58744 extracted continuous-transform change collection into CompositeBucketsChangeCollector. For date_histogram groups it decided whether to inject the incremental range filter with `entry.getKey().equals(synchronizationField)` (output/tar",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 523,
      "batch": "n=521-530 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-25726",
      "introducing_pr": 25726,
      "fixing_pr": 25872,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#25726 refactors field expansion for match / multi_match / query_string (`default_field: *` / all-fields). On the 5.x line, a bare `\"*\"` query_string still expanded onto `_field_names` / all queryable fields instead of short-circuiting to M",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 524,
      "batch": "n=521-530 (2026-07-22)",
      "repo": "apache/flink",
      "key": "flink-25859",
      "introducing_pr": 25859,
      "fixing_pr": 26180,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "AdaptiveSkewedJoinOptimizationStrategy (#25859 / FLINK-36629) retains fine-grained AllToAllBlockingResultInfo subpartition byte maps for skew decisions. When AdaptiveBroadcastJoinOptimizationStrategy also runs, the aggregate/clear path is n",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 525,
      "batch": "n=521-530 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-139973",
      "introducing_pr": 139973,
      "fixing_pr": 144863,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#139973 \u201cESQL: Split aggs results\u201d emits hash-agg results in maxPageSize chunks (safer vs giant wire pages / OOM). Because ordinals \u201ctake\u201d the keyword values when building a page, the PR comments out / disables `buildOrdinalOutputBlock` on ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 526,
      "batch": "n=521-530 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-6832",
      "introducing_pr": 6832,
      "fixing_pr": 7671,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "KIP-392 fetch-from-followers (#6832) introduced follower last-seen highwatermark handling that called `maybeUpdateHwAndSendResponse` on the fetch response path. That helper re-looks up partition+replica for every partition being fetched \u2014 e",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 527,
      "batch": "n=521-530 (2026-07-22)",
      "repo": "apache/hbase",
      "key": "hbase-3807",
      "introducing_pr": 3807,
      "fixing_pr": 7629,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent sink races; not null-on-drop NPE",
      "defect": "#3807 (HBASE-26407) introduces RegionReplicaSinkWriter for sinking WAL",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 528,
      "batch": "n=521-530 (2026-07-22)",
      "repo": "apache/iceberg",
      "key": "iceberg-12197",
      "introducing_pr": 12197,
      "fixing_pr": 13718,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent ClassCast SigV4; not OAuth scope order",
      "defect": "Auth Manager enablement #12197 rewrote `S3V4RestSignerClient.authSession()`",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 529,
      "batch": "n=521-530 (2026-07-22)",
      "repo": "netty/netty",
      "key": "netty-8393",
      "introducing_pr": 8393,
      "fixing_pr": 8484,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Optimization #8393 (\"Exploit PlatformDependent.allocateUninitializedArray",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 530,
      "batch": "n=521-530 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-19802",
      "introducing_pr": 19802,
      "fixing_pr": 20600,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#19802 (KAFKA-17747 [5/N]) moves creation of the soft-state configured",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 531,
      "batch": "n=531-540 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-18337",
      "introducing_pr": 18337,
      "fixing_pr": 18669,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "v2 files isolation/offset/timeout residuals",
      "defect": "#18337 rewrote `KafkaPartitionLevelConsumer.fetchMessages` (kafka 3.0 + 4.0) to skip re-seek when the caller repeats the same `startOffset` (read_committed empty-poll progress). The seek-skip is also applied after a *non-empty* poll whose r",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 532,
      "batch": "n=531-540 (2026-07-22)",
      "repo": "apache/camel",
      "key": "camel-19376",
      "introducing_pr": 19376,
      "fixing_pr": 22520,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Findings flag toStreamCache NPE on null entity and narrow StreamCache ",
      "defect": "#19376 (CAMEL-22414) added `CxfConverter.toStreamCache(Response)` that converts the entity via `toInputStream` + type converter and never copies `Response.getMediaType()` / protocol headers onto the exchange before the `Response` is consume",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 533,
      "batch": "n=531-540 (2026-07-22)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-19006",
      "introducing_pr": 19006,
      "fixing_pr": 21534,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#19006 changed `ScriptedMetricAggregator.buildAggregation` from `StreamOutput.checkWriteable(result)` to `if (result.getClass() != ScriptedAvg.class) StreamOutput.checkWriteable(result)` so `ScriptedAvg` can bypass the writeable check. When",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 534,
      "batch": "n=531-540 (2026-07-22)",
      "repo": "apache/rocketmq",
      "key": "rocketmq-9566",
      "introducing_pr": 9566,
      "fixing_pr": 10616,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#9566 moved `notifyMessageArriveInBatch=true` from `RocksDBMessageStore` ctor into `RocksDBConsumeQueueStore` ctor via `messageStore.setNotifyMessageArriveInBatch(true)`. The flag lives on shared `DefaultMessageStore`. `CombineConsumeQueueS",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 535,
      "batch": "n=531-540 (2026-07-22)",
      "repo": "apache/logging-log4j2",
      "key": "logging-log4j2-2853",
      "introducing_pr": 2853,
      "fixing_pr": 4074,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)",
      "defect": "#2853 migrated `Rfc5424Layout` configuration to the builder pattern (`@PluginBuilderAttribute`) while adding `useFqdn`. Documented XML attribute `newLine` (and related names) stopped binding; the builder field became `includeNL`. Configs wi",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 536,
      "batch": "n=531-540 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-18621",
      "introducing_pr": 18621,
      "fixing_pr": 18842,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)",
      "defect": "#18621 adds `mergeDataTablesOnly` / `mergeOnDataTable` that must keep aggregate state intermediate for re-merge. Single-server / key-unpartitioned paths can still set `SERVER_RETURN_FINAL_RESULT` (or key-unpartitioned final), so merge-only ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 537,
      "batch": "n=531-540 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-11839",
      "introducing_pr": 11839,
      "fixing_pr": 11971,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "EPOCH WEEKS NPE and Object return-type discussion are adjacent",
      "defect": "dateTimeConvert return type cast regression from #11839.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 538,
      "batch": "n=531-540 (2026-07-22)",
      "repo": "apache/paimon",
      "key": "paimon-4177",
      "introducing_pr": 4177,
      "fixing_pr": 8611,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Migrate action factories parse optional `--parallelism` with unguarded Integer.parseInt(null).",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 539,
      "batch": "n=531-540 (2026-07-22)",
      "repo": "redisson/redisson",
      "key": "redisson-348f78a1",
      "introducing_pr": "348f78a1",
      "fixing_pr": 7158,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)",
      "defect": "Direct commit \"Fixed - UUID serialization by Jackson codecs. #6828\" (2026-01-21, no PR) adds `UuidMixin` with `@JsonTypeInfo(use = Id.CLASS)` and registers it in `JsonJacksonCodec.init()`. `TypedJsonJacksonCodec` no-ops `initTypeInclusion()",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 540,
      "batch": "n=531-540 (2026-07-22)",
      "repo": "redisson/redisson",
      "key": "redisson-a46673c1",
      "introducing_pr": "a46673c1",
      "fixing_pr": 7229,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Commit \"Fixed - RMultimap.fastRemoveValue() method added. #5064\" (2023-05-25, no PR) adds `fastRemoveValueAsync` Lua that accumulates `size = size + redis.call(srem, \u2026)` then ends with `return 0;` instead of `return size;`. Callers always o",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 541,
      "batch": "n=541-550 (2026-07-22)",
      "repo": "apache/accumulo",
      "key": "accumulo-5357",
      "introducing_pr": 5357,
      "fixing_pr": 5366,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "UpgradeCoordinator progress tracking (added in #5357) compared stored ZooKeeper/root/metadata progress against the loop-invariant `currentVersion` instead of the per-step `upgradeVersion`. Every upgrader after the first is treated as alread",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 542,
      "batch": "n=541-550 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-13843",
      "introducing_pr": 13843,
      "fixing_pr": 14457,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)",
      "defect": "AbstractFetcherThread was changed so partition fetch state (including lag) still updates when `validBytes == 0` (idle partition). That path also rewrote `lastFetchedEpoch` from `logAppendInfo.lastLeaderEpoch` (empty when no records), wiping",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 543,
      "batch": "n=541-550 (2026-07-22)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-3205",
      "introducing_pr": 3205,
      "fixing_pr": 3998,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)",
      "defect": "TriggerGCService (force GC HTTP API on ledger storage) was extended to accept optional `forceMajor`/`forceMinor` JSON. On the common empty/blank PUT body path used by `curl -XPUT \u2026/api/v1/bookie/gc`, the service still called `JsonUtil.fromJ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 544,
      "batch": "n=541-550 (2026-07-22)",
      "repo": "apache/hudi",
      "key": "hudi-10173",
      "introducing_pr": 10173,
      "fixing_pr": 10379,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "`HoodieConversionUtils.fromProperties` was changed from mapping each entry with `k.toString`/`v.toString` to bare `props.asScala.toMap`. Schema-evolution / writer-schema deduction paths that expect `Map[String,String]` then receive non-Stri",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 545,
      "batch": "n=541-550 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-22593",
      "introducing_pr": 22593,
      "fixing_pr": 56527,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)",
      "defect": "Source-filtering in `XContentMapValues` (document `_source` transform on read path) was changed so array items are only accepted when a previous include pattern matches. That change also dropped empty arrays after exclusion filtering, while",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 546,
      "batch": "n=541-550 (2026-07-22)",
      "repo": "apache/druid",
      "key": "druid-18095",
      "introducing_pr": 18095,
      "fixing_pr": 18557,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "MSQ worker cancellation switched to interrupts (#18095). `RunWorkOrder.stop` / `stopUnchecked` could surface `InterruptedException` while still awaiting the stop latch, returning before cleanup finished. Interrupted stop therefore skipped r",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 547,
      "batch": "n=541-550 (2026-07-22)",
      "repo": "apache/druid",
      "key": "druid-16911",
      "introducing_pr": 16911,
      "fixing_pr": 17088,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Findings are limitHint int overflow / SuperSorter hard-enforce",
      "defect": "FrameChannelMerger (MSQ global-sort / frame merge path) used `remainingChannels` as a count of non-null current frames. Between `nextFrame()` and the next await/populate, a blocked channel nulled its frame entry so `finished()` could spurio",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 548,
      "batch": "n=541-550 (2026-07-22)",
      "repo": "apache/flink",
      "key": "flink-15495",
      "introducing_pr": 15495,
      "fixing_pr": 27501,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Findings about window property grouping ordinals and late-slice timers",
      "defect": "`TimeWindowUtils.getNextTriggerWatermark()` (event-time window aggregate state/timer path) was introduced/optimized without accounting for non-zero window offsets. Cascaded event-time WindowAggregate with offset never registers the correct ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 549,
      "batch": "n=541-550 (2026-07-22)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-12503",
      "introducing_pr": 12503,
      "fixing_pr": 13486,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Only design@LOW on hasInnerHits lazy alloc",
      "defect": "\"Removing unused fetch sub phase processor initialization\" skipped initializing fetch sub-phase processors (InnerHits / ScriptFields) in cases still required when nested inner hits appear under aggregations' top_hits. After 2.13.0, top_hits",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 550,
      "batch": "n=541-550 (2026-07-22)",
      "repo": "apache/pulsar",
      "key": "pulsar-23931",
      "introducing_pr": 23931,
      "fixing_pr": 24089,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Managed-ledger entry-count estimation was made \"more accurate\" (#23931) but used `currentLedger` / `getNextValidPosition` in ways that NPE on `ReadOnlyManagedLedgerImpl` (null current ledger) and mis-estimate positions for cache/read sizing",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 551,
      "batch": "n=551-560 (2026-07-22)",
      "repo": "alibaba/nacos",
      "key": "nacos-11536",
      "introducing_pr": 11536,
      "fixing_pr": 14750,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)",
      "defect": "FailoverReactor.isFailoverSwitch(String) uses non-atomic containsKey(serviceName) then get(serviceName).ipCount() on ConcurrentHashMap serviceMap. FailoverSwitchRefresher can replace/clear serviceMap between the two calls \u2192 NPE on null.ipCo",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 552,
      "batch": "n=551-560 (2026-07-22)",
      "repo": "netty/netty",
      "key": "netty-13237",
      "introducing_pr": 13237,
      "fixing_pr": 15927,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.9 slice",
      "defect": "NonStickyEventExecutorGroup.NonStickyOrderedEventExecutor, when hitting maxTaskExecutePerRun, clears executingThread (CAS to null) then calls executor.execute(this) to reschedule. If execute throws, the catch only sets state back to RUNNING",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 553,
      "batch": "n=551-560 (2026-07-22)",
      "repo": "apache/camel",
      "key": "camel-14161",
      "introducing_pr": 14161,
      "fixing_pr": 24731,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "TemporaryQueueReplyManager.TemporaryReplyQueueDestinationResolver.resolveDestinationName check-then-act on queue/refreshWanted without synchronization after intro removed `synchronized (refreshWanted)`. Concurrent listener threads can each ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 554,
      "batch": "n=551-560 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-17562",
      "introducing_pr": 17562,
      "fixing_pr": 21279,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings focus on requestInFlight wedge on unexpected response types",
      "defect": "RPCProducerIdManager.maybeRequestNextBlock() calls sendRequest() then unconditionally backoffDeadlineMs.set(NO_RETRY). sendRequest is async; response-path handleUnsuccessfulResponse() may set backoffDeadlineMs = now+RETRY_BACKOFF first, the",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 555,
      "batch": "n=551-560 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-21279",
      "introducing_pr": 21279,
      "fixing_pr": 22204,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings note request-path backoff clear fixed and residual timeout/co",
      "defect": "Residual race in RPCProducerIdManager after #21279: maybeRequestNextBlock still reads backoffDeadlineMs *before* CAS on requestInFlight. Response handler sets backoff then clears requestInFlight; a racer can pass the backoff check, then CAS",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 556,
      "batch": "n=551-560 (2026-07-22)",
      "repo": "apache/helix",
      "key": "helix-2558",
      "introducing_pr": 2558,
      "fixing_pr": 2814,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings are HashSet races, close CME, isLeader NPE",
      "defect": "LeaderElectionClient ConnectStateListener only recreated participant ephemeral nodes on EXPIRED\u2192CONNECTED. Race with native ZooKeeper reconnect (session not yet expired) left participant ZNode missing while still claiming leadership (heap-d",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 557,
      "batch": "n=551-560 (2026-07-22)",
      "repo": "apache/camel",
      "key": "camel-14999",
      "introducing_pr": 14999,
      "fixing_pr": 24766,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "AbstractBeanProcessor.getCustomAdapter: non-volatile processor/lookupProcessorDone plus incomplete double-check \u2014 sets lookupProcessorDone=true *before* tryConvertTo and does not re-check under lock, so concurrent threads can miss conversio",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 558,
      "batch": "n=551-560 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-147691",
      "introducing_pr": 147691,
      "fixing_pr": 147796,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)",
      "defect": "PlainCompressionCodecFactory used plain HashMap + computeIfAbsent for lazy codec (de)compressors. #147691 holds one factory on ParquetFormatReader (\"Shared across all iterators\u2026 pays the per-codec init cost once\") so parallel driver threads",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 559,
      "batch": "n=551-560 (2026-07-22)",
      "repo": "apache/druid",
      "key": "druid-12663",
      "introducing_pr": 12663,
      "fixing_pr": 19497,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Lazy ORC init moved FileSystem classloader-sensitive init into OrcInputFormat.initialize(conf) and called it from every createReader(). Concurrent ParallelIndexTask subtasks in one JVM race Thread.currentThread().setContextClassLoader + Fil",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 560,
      "batch": "n=551-560 (2026-07-22)",
      "repo": "apache/ozone",
      "key": "ozone-6690",
      "introducing_pr": 6690,
      "fixing_pr": 10351,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "MappedBufferManager (new in HDDS-10488) caches mapped buffers as WeakReference<ByteBuffer> in a ConcurrentHashMap. computeIfAbsent reads refer.get() twice (null-check then return) \u2014 GC can clear between reads \u2192 null ByteBuffer / throw null.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 561,
      "batch": "n=561-570 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-141373",
      "introducing_pr": 141373,
      "fixing_pr": 152214,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings note system-user readiness privilege and prepareForShutdown s",
      "defect": "SigtermTerminationHandler.blockTermination registers cluster-state listener before seeding ReadyChecker.currentNodes; listener and shutdown threads race setCurrentNodes so a fresher node set is clobbered \u2192 readiness check dropped \u2192 hang. Fi",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 562,
      "batch": "n=561-570 (2026-07-22)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-49892",
      "introducing_pr": 49892,
      "fixing_pr": 50961,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)",
      "defect": "PR #49892 adds SCIM protection for administrative users/groups (`isAdminUser` / `isAdminGroup` on User and Group resource providers) and documents that admin membership must not be manipulated via SCIM. On the Groups resource, membership ad",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 563,
      "batch": "n=561-570 (2026-07-22)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-47838",
      "introducing_pr": 47838,
      "fixing_pr": 50567,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.9 slice",
      "defect": "PR #47838 adds the AuthZEN **Evaluations** (batch) endpoint and authenticates with `Tokens.getAccessToken(session)` only \u2014 any valid bearer including end-user tokens can query the PDP. Same fail-open auth as the single Evaluation API (#4763",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 564,
      "batch": "n=561-570 (2026-07-22)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-46561",
      "introducing_pr": 46561,
      "fixing_pr": 50872,
      "lane": "security",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings cover SCIM filter query",
      "defect": "PR #46561 adds SCIM PATCH support (`AbstractScimResourceTypeProvider.patch`) that iterates every operation without a size cap. `ServiceProviderConfig.Bulk.maxOperations` exists but is never enforced on PATCH \u2014 an attacker can send unbounded",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 565,
      "batch": "n=561-570 (2026-07-22)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-34568",
      "introducing_pr": 34568,
      "fixing_pr": 50486,
      "lane": "security",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings are ADMIN_FINE_GRAINED_AUTHZ_V2 feature-flag not consulted / ",
      "defect": "Under FGAP v2, `GroupResource.addChild` required manage on the **parent** only. When reparenting an existing group by id, it never called `auth.groups().requireManage(child)`. A delegated admin with manage on a low-privilege group can repar",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 566,
      "batch": "n=561-570 (2026-07-22)",
      "repo": "apache/ranger",
      "key": "ranger-29038c4f81",
      "introducing_pr": "29038c4f81",
      "fixing_pr": 1011,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Findings name download flag defaulting to general unauth boolean (wide",
      "defect": "Commit `29038c4f81` (RANGER-3623) adds `failUnauthenticatedDownloadIfNotAllowed()` and config `ranger.admin.allow.unauthenticated.download.access`, but wraps the session/flag check in `if (UserGroupInformation.isSecurityEnabled())`. Outside",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 567,
      "batch": "n=561-570 (2026-07-22)",
      "repo": "apache/hadoop",
      "key": "hadoop-c39e9fc9",
      "introducing_pr": "c39e9fc9",
      "fixing_pr": 8465,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Commit `c39e9fc9` (HADOOP-15169) adds `HttpServer2.setEnabledProtocols` but gates Jetty include/exclude protocol application behind `if (!enabledProtocols.equals(SSLFactory.SSL_ENABLED_PROTOCOLS_DEFAULT))`. When config is the advertised def",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 568,
      "batch": "n=561-570 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-16669",
      "introducing_pr": 16669,
      "fixing_pr": 17305,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "KIP-853 storage-tool flags PR stopped processing SCRAM bootstrap arguments.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 569,
      "batch": "n=561-570 (2026-07-22)",
      "repo": "apache/druid",
      "key": "druid-15287",
      "introducing_pr": 15287,
      "fixing_pr": 16525,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Azure client upgrade introduced AzureClientFactory with `cachedBlobServiceClients = new HashMap<>()` and check-then-act containsKey/put (later computeIfAbsent on same HashMap) for per-retry BlobServiceClient reuse. Concurrent MSQ shuffle wo",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 570,
      "batch": "n=561-570 (2026-07-22)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-22229",
      "introducing_pr": 22229,
      "fixing_pr": 22231,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings name incomplete parentTask wiring (QueryRequestContext",
      "defect": "Single async cancel race on AnalyticsQueryTask. Task is registered cancellable (taskManager.register) before setOnCancelCallback is wired (after async SEARCH planning). Cancel in that window runs onCancelled while callback still null \u2192 sile",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 571,
      "batch": "n=571-580 (2026-07-22)",
      "repo": "apache/lucene",
      "key": "lucene-14363",
      "introducing_pr": 14363,
      "fixing_pr": 16142,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Empty findings across performance/correctness/design",
      "defect": "#14363 implements `DisjunctionDISIApproximation.docIDRunEnd()` by calling `topList()`/`computeTopList()` then maxing `docIDRunEnd` across top clauses. For multi-clause MUST_NOT (interleaved keyword terms) `ReqExclBulkScorer` invokes this pe",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 572,
      "batch": "n=571-580 (2026-07-22)",
      "repo": "apache/iceberg",
      "key": "iceberg-15448",
      "introducing_pr": 15448,
      "fixing_pr": 16284,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)",
      "defect": "#15448 introduces `SerializableFileIOWithSize` to pass a serializable FileIO on Spark\u2019s read path but only overrides `newInputFile(String path)`. Callers that open with known length hit `FileIO`\u2019s default `newInputFile(path, length)` which ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 573,
      "batch": "n=571-580 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-110633",
      "introducing_pr": 110633,
      "fixing_pr": 136625,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)",
      "defect": "#110633 (manage_roles / regex has-privilege style checks) builds index-group automatons via `indexGroupAutomatons`. Expensive `Automatons.unionAndMinimize` combine path was left **outside** the `combine` conditional, so ordinary has-privile",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 574,
      "batch": "n=571-580 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-135886",
      "introducing_pr": 135886,
      "fixing_pr": 138711,
      "lane": "performance",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings are missingValue",
      "defect": "#135886 wires `index.sort.*` settings through `stringListSettingWithDefaultProvider` / listSetting default providers (`IndexSortConfigDefaults::getDefaultSort*`). The first cut rebuilt default lists / sort specs on the many-shards settings ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 575,
      "batch": "n=571-580 (2026-07-22)",
      "repo": "apache/paimon",
      "key": "paimon-3209",
      "introducing_pr": 3209,
      "fixing_pr": 7910,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Correctness flags LazyField unsynchronized concurrent first get (race ",
      "defect": "#3209 introduces `LazyField<T>` with `private final Supplier<T> supplier` retained forever after `get()` caches the value. Chained lazy computations (e.g. GlobalIndexResult.or/and) keep full supplier closure graphs alive \u2192 unbounded memory ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 576,
      "batch": "n=571-580 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-145676",
      "introducing_pr": 145676,
      "fixing_pr": 145779,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Sole finding is INT4 bulk-sparse query size check using packed length ",
      "defect": "BBQ/INT4 bulk scorers scored via `IndexInputUtils.withSlice(input, input.length(), \u2026)`, mapping (or heap-copying) the **entire** vector data file for every bulk scoring call when zero-copy mmap was unavailable. Fix #145779 rewrites scorers ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 577,
      "batch": "n=571-580 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-90672",
      "introducing_pr": 90672,
      "fixing_pr": 91462,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#90672 \u201cRefactor & tidy up uses of Strings class\u201d rewrites `hasText`/`validFileName` to `CharSequence.chars()` stream scans. Those helpers sit in many-shards hot loops (snapshotting); `hasText` went from near-zero to 2%+ CPU. Fix #91462 res",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 578,
      "batch": "n=571-580 (2026-07-22)",
      "repo": "micrometer-metrics/micrometer",
      "key": "micrometer-3959",
      "introducing_pr": 3959,
      "fixing_pr": 6363,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "v2 re-run MISS; sticky v1 HIT un-banked (07-22 audit)",
      "defect": "Incomplete ConcurrentHashMap migration: ExponentialHistogram OTLP support added IndexProviderFactory with static HashMap + computeIfAbsent (and emptySnapshotCache LinkedHashMap path) used during concurrent DistributionSummary registration \u2192",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 579,
      "batch": "n=571-580 (2026-07-22)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-4285",
      "introducing_pr": 4285,
      "fixing_pr": 4737,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings praise writeAndFlush failure calling errorOut (hang fix) and ",
      "defect": "PerChannelBookieClient.readV3Response does completionObjects.get(key), schedules async handler that may release/recycle the CompletionValue, then remove(key). Timeout scanner can observe a recycled entry still in the map \u2192 NPE on nulled fie",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 580,
      "batch": "n=571-580 (2026-07-22)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-54084",
      "introducing_pr": 54084,
      "fixing_pr": 55041,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Residual half-close vs onMessage race on gRPC @RunOnVirtualThread under unified HTTP transport. BlockingServerInterceptor defers startCall (and call.request(N)) onto a virtual/worker thread while onHalfClose is not gated \u2192 under load replay",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 581,
      "batch": "n=581-590 (2026-07-22)",
      "repo": "apache/hudi",
      "key": "hudi-7267",
      "introducing_pr": 7267,
      "fixing_pr": 11668,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "v2 still cites FileUtil",
      "defect": "HoodieSnapshotExporter was changed from `SaveMode.Overwrite` to `SaveMode.ErrorIfExists` while improving exporter listing/copy perf. On Spark task failure/retry, the partial target path from the failed task already exists, so retried tasks ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 582,
      "batch": "n=581-590 (2026-07-22)",
      "repo": "apache/accumulo",
      "key": "accumulo-5621",
      "introducing_pr": 5621,
      "fixing_pr": 5631,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "#5621 made `ColumnFamilySkippingIterator.seek` call `range.bound(minCF, maxCF)` to narrow seeks. When the seek range and selected column families are disjoint, public `Range.bound()` throws `IllegalArgumentException`, so server-side iterato",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 583,
      "batch": "n=581-590 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-150027",
      "introducing_pr": 150027,
      "fixing_pr": 154280,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Only flags skipper intoBitSet missing iterDoc>=upTo early return vs no",
      "defect": "Incomplete fix of TSDB doc-values range `intoBitSet`: #150027 fixed position-contract issues on some intoBitSet paths but left the no-skipper range TwoPhaseIterator uncapped. Bulk scoring windows with `upTo > maxDoc` read past encoded block",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 584,
      "batch": "n=581-590 (2026-07-22)",
      "repo": "apache/hudi",
      "key": "hudi-6266",
      "introducing_pr": 6266,
      "fixing_pr": 18887,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "When `MARKERS.type` is absent, `MarkerBasedRollbackUtils.getAllMarkerPaths()` tries DIRECT markers and catches `IOException | IllegalArgumentException` to fall back to TIMELINE_SERVER_BASED. Transient HDFS IOException (e.g. server busy) is ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 585,
      "batch": "n=581-590 (2026-07-22)",
      "repo": "apache/ozone",
      "key": "ozone-8926",
      "introducing_pr": 8926,
      "fixing_pr": 9262,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "HDDS-13520 (#8926) reworked SCM block-deletion retry (always retry; drop max-retry skip). In `DeletedBlockLogImpl.getTransactions`, it hoisted `containerManager.getContainer(id)` **outside** the `try` that catches `ContainerNotFoundExceptio",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 586,
      "batch": "n=581-590 (2026-07-22)",
      "repo": "apache/pulsar",
      "key": "pulsar-24833",
      "introducing_pr": 24833,
      "fixing_pr": 25066,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "PIP-442 (#24833) adds AsyncSemaphoreImpl with update(permit, newPermits) that can race: if a permit is released before the updated permit is acquired, available permits inflate over time and memory limits for topic-list ops become ineffecti",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 587,
      "batch": "n=581-590 (2026-07-22)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-18523",
      "introducing_pr": 18523,
      "fixing_pr": 19766,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "Explicit index resolution API regressed empty index expressions from IndexNotFoundException to StringIndexOutOfBoundsException after #18523.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 588,
      "batch": "n=581-590 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-147038",
      "introducing_pr": 147038,
      "fixing_pr": 154325,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Only a design note that selective reading is blocked / RowRanges parti",
      "defect": "PageColumnReader (page-level Parquet batch reader) skip path: when a page is fully excluded, `loadNextPage` can jump the physical cursor past the `skipRows` target; surplus was discarded so subsequent skips over-advanced into survivor pages",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 589,
      "batch": "n=581-590 (2026-07-22)",
      "repo": "apache/lucene",
      "key": "lucene-14135",
      "introducing_pr": 14135,
      "fixing_pr": 16252,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#14135 implements `intoBitSet` on `RoaringDocIdSet` / `IntArrayDocIdSet`. Once iteration reaches `NO_MORE_DOCS`, the multi-block iterator clears the underlying sub-iterator; the new `intoBitSet` still entered the sub-block loop without a `d",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 590,
      "batch": "n=581-590 (2026-07-22)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-41547",
      "introducing_pr": 41547,
      "fixing_pr": 42400,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Flags singleResultOptional, count() cast, RuntimeException rewrite, ge",
      "defect": "#41547 migrates Panache to `SelectionQuery`/`MutationQuery`. The entityClass overload of `executeUpdate` builds the update via `createMutationQuery` but opens the session with `getSession(DEFAULT_PERSISTENCE_UNIT_NAME)` instead of `getSessi",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 591,
      "batch": "n=591-600 (2026-07-22)",
      "repo": "apache/rocketmq",
      "key": "rocketmq-4809",
      "introducing_pr": 4809,
      "fixing_pr": 10579,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#4809 introduces `DefaultElectPolicy` with comparator `(int) (y.getMaxOffset() - x.getMaxOffset())` (later also priority branch keeps the same cast). When two brokers share epoch and `maxOffset` deltas exceed `Integer.MAX_VALUE`, the cast o",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 592,
      "batch": "n=591-600 (2026-07-22)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-17447",
      "introducing_pr": 17447,
      "fixing_pr": 22390,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Flags finalizePreviousRange with counter==0 / compare() advancing acti",
      "defect": "#17447 adds filter-rewrite sub-aggregation support (`SubAggRangeCollector` + `PointTreeTraversal.multiRangesTraverse`). After BKD traversal, `multiRangesTraverse` **always** called `collector.finalizePreviousRange()` even when traversal end",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 593,
      "batch": "n=591-600 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-21795",
      "introducing_pr": 21795,
      "fixing_pr": 22491,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#21795 (KAFKA-17411 offset-management fixes) **adds** `AbstractSegments.committedOffset(TopicPartition)` iterating `segments.values()` in ascending TreeMap order and returning the first non-null offset. Inactive older segments hold stale SS",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 594,
      "batch": "n=591-600 (2026-07-22)",
      "repo": "apache/commons-lang",
      "key": "commons-lang-6941f81c",
      "introducing_pr": "6941f81cd321",
      "fixing_pr": 1697,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Builder nullIsLess/ignoreCase miswire and equals(String) NPE only",
      "defect": "Direct commit \"Add Strings and refactor StringUtils\" (2024-09-21, no PR) adds `org.apache.commons.lang3.Strings` and implements case-insensitive `replace` by **pre-lowercasing** `searchString` (`if (ignoreCase) searchString = searchString.t",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 595,
      "batch": "n=591-600 (2026-07-22)",
      "repo": "hazelcast/hazelcast",
      "key": "hazelcast-22942",
      "introducing_pr": 22942,
      "fixing_pr": 25114,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#22942 moves pre-join/event registration into `OnJoinOp` carried on `JoinRequest` and makes `EventServiceImpl#getPostJoinOperation` return null permanently. Under sequential join this works; when multiple members join within `WAIT_SECONDS_B",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 596,
      "batch": "n=591-600 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-137367",
      "introducing_pr": 137367,
      "fixing_pr": 152293,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Group-by-all plan rewrite, _timeseries encoding, Values(tsAgg) shape, ",
      "defect": "#137367 ships ESQL `GROUP BY ALL` / bare time-series aggs. `TranslateTimeSeriesAggregate` still throws `IllegalStateException: unexpected inline filter in time-series aggregation` when an `_over_time` agg carries a filter but there is no ou",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 597,
      "batch": "n=591-600 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-18996",
      "introducing_pr": 18996,
      "fixing_pr": 19017,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Pending buffer alias, weight validation, Accumulator dual surface (asB",
      "defect": "#18996 optimizes TDigest aggregation with `PercentileTDigestAccumulator` (capacity-preserving serialize for oversized compact digests). It wires capacity-preserving `serialize()` on the accumulator\u2019s own path, but **misses** generic `TDIGES",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 598,
      "batch": "n=591-600 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-142493",
      "introducing_pr": 142493,
      "fixing_pr": 150319,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Notes removal of postInitializeCompetitiveIterator early-empty prune a",
      "defect": "#142493 implements `setScorer()` on the skipper competitive-iterator builder and removes `PointsCompetitiveDISIBuilder.postInitializeCompetitiveIterator()`. The shared `updateCompetitiveIterator()` still early-returns when `hitsThresholdRea",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 599,
      "batch": "n=591-600 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-12437",
      "introducing_pr": 12437,
      "fixing_pr": 18892,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "limit+negative index semantics and argument-order footguns only",
      "defect": "#12437 adds the 4-arg `splitPart(input, delimiter, limit, index)` scalar used on high-QPS transform/query paths; implementation materializes a full `String[]` via `StringUtils.splitByWholeSeparator(\u2026, limit)` on every call even when only on",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 600,
      "batch": "n=591-600 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-89047",
      "introducing_pr": 89047,
      "fixing_pr": 94159,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#89047 removes ES\u2019s internal `shortcutTotalHitCount` optimization, relying on Lucene `Weight#count` / `TotalHitCountCollector`. For size>0 searches whose query *can* short-circuit total hits (term, match_all, field_exists), Lucene\u2019s top-sco",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 601,
      "batch": "n=601-610 (2026-07-22)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-15579",
      "introducing_pr": 15579,
      "fixing_pr": 21350,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.9 slice",
      "defect": "#15579 extracts `RemoteFsTimestampAwareTranslog` and implements remote-purge cleanup with `metadataFilesNotToBeDeleted.removeAll(metadataFilesToBeDeleted)` (and sibling `removeAll` sites) where both sides are `ArrayList`. `ArrayList.removeA",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 602,
      "batch": "n=601-610 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-97972",
      "introducing_pr": 97972,
      "fixing_pr": 151815,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Correctness notes nested FlatteningXContentParser wrappers for prefix ",
      "defect": "#97972 implements `subobjects:false` flattening via `FlatteningXContentParser` and `DocumentParserContext.createFlattenContext`, allocating a flattening wrapper (and related parser switch) **per intermediate JSON object** on the ingest path",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 603,
      "batch": "n=601-610 (2026-07-22)",
      "repo": "apache/druid",
      "key": "druid-19357",
      "introducing_pr": 19357,
      "fixing_pr": 19439,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#19357 batches small SpillingGrouper spill runs by **always** writing each spill to a temp file, then checking size and reading small ones back into memory (to avoid thousands of tiny files for HLL/groupBy). On high-cardinality groupBy with",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 604,
      "batch": "n=601-610 (2026-07-22)",
      "repo": "apache/iceberg",
      "key": "iceberg-10755",
      "introducing_pr": 10755,
      "fixing_pr": 16691,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#10755 adds `cleanExpiredMetadata` / remove-unused-specs on expire-snapshots by scanning **every retained snapshot\u2019s** `snapshot.allManifests(io)` to collect reachable partitionSpecIds. For tables with many retained snapshots this is always",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 605,
      "batch": "n=601-610 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-17149",
      "introducing_pr": 17149,
      "fixing_pr": 22572,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#17149 introduces `PersisterStateBatchCombiner` with a TreeSet-based iterative overlap merge (`combineStateBatches`). Worst-case cost grows beyond a single sort/sweep because of repeated TreeSet mutations and rescans \u2014 O(n\u00b2) in input batch ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 606,
      "batch": "n=601-610 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-107567",
      "introducing_pr": 107567,
      "fixing_pr": 108179,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.9 slice",
      "defect": "#107567 adds synthetic-source ignored-value tracking (`IgnoredSourceFieldMapper`) and `ObjectMapper.SyntheticFieldLoader.setIgnoredValues`, which walks every field loader on every doc while always allocating a non-null `objectsWithIgnoredFi",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 607,
      "batch": "n=601-610 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-138159",
      "introducing_pr": 138159,
      "fixing_pr": 139203,
      "lane": "performance",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "#138159 unifies last-value downsampling producers onto `FormattedDocValues` for all field kinds (metrics, labels, dimensions) via a shared `LastValueFieldProducer`. Numeric last-value fields lose the specialised numeric doc-values path and ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 608,
      "batch": "n=601-610 (2026-07-22)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-47073",
      "introducing_pr": 47073,
      "fixing_pr": 50847,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "PR #47073 enforces SCIM admin roles/permissions and implements `getAll` as `getModels(...).map(m -> get(m.getId()))` with per-resource `VIEW` inside `get()`. A client with only `query-users`/`query-groups` passes the entry `canQuery()` chec",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 609,
      "batch": "n=601-610 (2026-07-22)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-22075",
      "introducing_pr": 22075,
      "fixing_pr": 22118,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty findings",
      "defect": "#22075 changes `analytics.delegation.<backend>.blocked_predicates` defaults from empty to non-empty for lucene (`IS_NULL`, `IS_NOT_NULL`, `LIKE`) so sensitive predicates stay off secondary backends. Seeding still uses `AffixSetting.getAsMap",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 610,
      "batch": "n=601-610 (2026-07-22)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-45285",
      "introducing_pr": 45285,
      "fixing_pr": 49886,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Findings cover CIMD executor soft-fail when feature off, scheme/SSRF/r",
      "defect": "PR #45285 adds Persistent CIMD (Client ID Metadata Document) client creation. Public clients created through CIMD do not run client-policy REGISTER/REGISTERED executors the same way as Admin Console create/save, so configured enforcers (`se",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 611,
      "batch": "n=611-620 (2026-07-22)",
      "repo": "AsyncHttpClient/async-http-client",
      "key": "ahc-6b2fbb7f",
      "introducing_pr": "6b2fbb7f",
      "fixing_pr": 2224,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Findings discuss default strip on cross-domain redirects, same-origin ",
      "defect": "Commit `6b2fbb7f` \"Strip credentials on cross-domain redirects and HTTPS-to-HTTP downgrades\" clears request realm / Authorization on cross-origin redirect and sets `future.setRealm(null)`, but the 401 re-auth path (`exitAfterIntercept`) sti",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 612,
      "batch": "n=611-620 (2026-07-22)",
      "repo": "apache/cxf",
      "key": "cxf-2b160783",
      "introducing_pr": "2b160783",
      "fixing_pr": 3240,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "Commit `2b160783` (CXF-6909, closes #137) adds JCache OAuth data providers with `isExpired` implemented as `System.currentTimeMillis() < (issuedAt + expiresIn)` \u2014 that is the **not-expired** condition. Expired access tokens and authorizatio",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 613,
      "batch": "n=611-620 (2026-07-22)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-48091",
      "introducing_pr": 48091,
      "fixing_pr": 50801,
      "lane": "security",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings cover null clientId on create, temp-client policy probes, and",
      "defect": "PR #48091 removes the legacy Client API v2 service and lands create/update on `DefaultClientService` without calling `LoginProtocolFactory.setupClientDefaults`. OIDC clients created via Admin API v2 therefore miss `backchannelLogoutSessionR",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 614,
      "batch": "n=611-620 (2026-07-22)",
      "repo": "netty/netty",
      "key": "netty-14300",
      "introducing_pr": 14300,
      "fixing_pr": 14495,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Findings flag Magazine",
      "defect": "#14300 adds AdaptivePoolingAllocator.free() (via finalize) that sets freed=true and drains magazines. Concurrent offerToQueue checks freed once, then centralQueue.offer; if free() runs in the window after the check and before offer complete",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 615,
      "batch": "n=611-620 (2026-07-22)",
      "repo": "apache/ozone",
      "key": "ozone-10378",
      "introducing_pr": 10378,
      "fixing_pr": 10388,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Findings discuss post-desync shutdown vs concurrent start interleaving",
      "defect": "Incomplete deadlock fix residual. HDDS-14645 (#10378) removed synchronized from BackgroundService.shutdown and moved awaitTermination outside the monitor so PeriodicalTask can enter the critical section \u2014 fixing one PeriodicalTask\u2194shutdown ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 616,
      "batch": "n=611-620 (2026-07-22)",
      "repo": "apache/camel",
      "key": "camel-21538",
      "introducing_pr": 21538,
      "fixing_pr": 22492,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Only finding is instanceof SynchronousExecutorService brittleness for ",
      "defect": "CAMEL-23030 (#21538) avoided StackOverflowError on aggregate completion with SynchronousExecutorService by switching non-transacted path from reactiveExecutor.scheduleSync(task) to schedule(task). Aggregated exchanges lose the transacted fl",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 617,
      "batch": "n=611-620 (2026-07-22)",
      "repo": "apache/iceberg",
      "key": "iceberg-10691",
      "introducing_pr": 10691,
      "fixing_pr": 11781,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Findings cover close()/cancel Closeable leaks, ConcurrentLinkedQueue",
      "defect": "#10691 bounded ParallelIterable.queue to cap memory: when the queue is full, a Task yields and is removed from the executor while still holding external resources (e.g. S3 connections via ManifestReader). Under multi-ParallelIterable load t",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 618,
      "batch": "n=611-620 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-12274",
      "introducing_pr": 12274,
      "fixing_pr": 13360,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "ScalingThreadPoolExecutor (new in #12274) autoscales by rejecting when busy then re-queueing. Idle detection used ThreadPoolExecutor.getPoolSize()/getActiveCount(), which lag true idle state under rapid submit \u2014 tasks can sit queued without",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 619,
      "batch": "n=611-620 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-15189",
      "introducing_pr": 15189,
      "fixing_pr": 15724,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#15189 added gauge observability for MSE query server threads as a plain int _currentQueryServerThreads with +=/-= in tryAcquire/release. Those methods run on concurrent broker query-handler threads; non-atomic int racy updates lose counts ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 620,
      "batch": "n=611-620 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-7720",
      "introducing_pr": 7720,
      "fixing_pr": 13916,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#7720 memoizes LiteralTransformFunction (and array/generate literals) in QueryContext so one instance is shared across segments/threads (\"sold as\" buffer reduction). Result arrays (_intResult, _stringArrayResult, \u2026) stayed non-volatile with",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 621,
      "batch": "n=621-630 (2026-07-22)",
      "repo": "apache/ozone",
      "key": "ozone-8157",
      "introducing_pr": 8157,
      "fixing_pr": 8381,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "HDDS-12596 (#8157) enforced ozone.om.fs.snapshot.max.limit via OmSnapshotManager.snapshotLimitCheck using AtomicInteger inFlightSnapshotCount but reading global snapshot chain size *outside* updateAndGet (check-then-act). Concurrent creates",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 622,
      "batch": "n=621-630 (2026-07-22)",
      "repo": "alibaba/nacos",
      "key": "nacos-13604",
      "introducing_pr": 13604,
      "fixing_pr": 15067,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#13604 adds MemoryMcpCacheIndex with ReentrantReadWriteLock guarding updateIndex and clear via writeLock, but both removeIndex overloads mutate nameKeyToId / idToEntry / the LRU doubly-linked list with NO lock. Concurrent removeIndex vs upd",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 623,
      "batch": "n=621-630 (2026-07-22)",
      "repo": "apache/pulsar",
      "key": "pulsar-18390",
      "introducing_pr": 18390,
      "fixing_pr": 25644,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ConcurrentLongHashMap.Section publishes keys/values/capacity as three separate volatile fields. #18390 attempted to fix optimistic-lock AIOOBE by snapshotting keys/ values into locals, but rehash still publishes the triple non-atomically \u2014 ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 624,
      "batch": "n=621-630 (2026-07-22)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-4066",
      "introducing_pr": 4066,
      "fixing_pr": 4771,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Same ConcurrentLongHashMap/Section torn-triple publish race as pulsar-25644. #4066 ported pulsar's incomplete local-snapshot optimistic-lock fix into bookkeeper's ConcurrentLong* collections; residual rehash can still AIOOBE under concurren",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 625,
      "batch": "n=621-630 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-10960",
      "introducing_pr": 10960,
      "fixing_pr": 19972,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings only note split public getters re-reading the volatile Timest",
      "defect": "#10960 refactors LogSegment maxTimestampSoFar + offsetOfMaxTimestampSoFar into a single volatile TimestampOffset maxTimestampAndOffsetSoFar to avoid torn timestamp/offset reads. Lazy init in readMaxTimestampAndOffsetSoFar still does check-t",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 626,
      "batch": "n=621-630 (2026-07-22)",
      "repo": "apache/helix",
      "key": "helix-2814",
      "introducing_pr": 2814,
      "fixing_pr": 3058,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings discuss concurrent leave while iterating _participantInfos an",
      "defect": "#2814 fixed participant ephemeral recreate on any CONNECTED (not only EXPIRED\u2192CONNECTED) and touchLeaderNode, but on expire/reconnect it does not re-register user-registered leadership listeners before recreating the leader node. Race: clie",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 627,
      "batch": "n=621-630 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-9801",
      "introducing_pr": 9801,
      "fixing_pr": 13104,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings name timeout finally vs late receiveDataTable double accounti",
      "defect": "Single AdaptiveServerSelection in-flight counter race. #9801 wired ServerRoutingStatsManager into AsyncQueryResponse so timeout/non-responding servers also decrement numInFlightRequests (bugfix for sticky overload avoidance). Jetty completi",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 628,
      "batch": "n=621-630 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-21692",
      "introducing_pr": 21692,
      "fixing_pr": 21809,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "api-ops notes OffsetCommit overwrites client topicId from metadata cac",
      "defect": "#21692 (KIP-1251 assignment epochs) adds topicId resolving for OffsetCommit in KafkaApis#handleOffsetCommitRequest: always metadataCache.getTopicId(topic.name) then topic.setTopicId(...). Concurrent metadata updates can race between resolve",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 629,
      "batch": "n=621-630 (2026-07-22)",
      "repo": "apache/pulsar",
      "key": "pulsar-5604",
      "introducing_pr": 5604,
      "fixing_pr": 21333,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Findings cover asyncOpen signature break, cursorLedgerStat refresh rac",
      "defect": "#5604 introduces Supplier<Boolean> mlOwnershipChecker and calls ledger.mlOwnershipChecker.get() synchronously inside ManagedCursorImpl.persistPositionMetaStore on the BookKeeper ordered worker thread. When the supplier later blocks (ownersh",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 630,
      "batch": "n=621-630 (2026-07-22)",
      "repo": "alibaba/nacos",
      "key": "nacos-11856",
      "introducing_pr": 11856,
      "fixing_pr": 14927,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "ClientWorker.ConfigRpcTransportClient.multiTaskExecutor is a plain HashMap with non-atomic containsKey+put in ensureSyncExecutor. Concurrent callers for the same taskId each create a ThreadPoolExecutor; only the last put is retained \u2192 perma",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 631,
      "batch": "n=631-640 (2026-07-22)",
      "repo": "apache/iceberg",
      "key": "iceberg-12496",
      "introducing_pr": 12496,
      "fixing_pr": 16880,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Parquet variant metrics upper-bound truncation for BINARY used `BinaryUtil.truncateBinaryMin` instead of `truncateBinaryMax` inside `ParquetVariantUtil.truncateUpperBound`. Truncating the max bound downward can store an upper bound smaller ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 632,
      "batch": "n=631-640 (2026-07-22)",
      "repo": "apache/iceberg",
      "key": "iceberg-13301",
      "introducing_pr": 13301,
      "fixing_pr": 14438,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Adjacent rebind issues filed; case-insensitive bind not named",
      "defect": "Time-travel scan rebound partition specs with `PartitionSpec.toUnbound().bind(snapshotSchema)` (case-sensitive default). When a later schema adds columns used in partition filters, rebinding against the older snapshot schema fails/finds the",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 633,
      "batch": "n=631-640 (2026-07-22)",
      "repo": "apache/iceberg",
      "key": "iceberg-16818",
      "introducing_pr": 16818,
      "fixing_pr": 17002,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "FIXED_LEN decimal shredding not filed",
      "defect": "`VariantShreddingAnalyzer.createDecimalTypedValue` hard-coded `FIXED_LEN_BYTE_ARRAY` length 16 for precision > 18. Writer uses `TypeUtil.decimalRequiredBytes` (e.g. 9 bytes for precision 20), so shredded variant writes fail with length mism",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 634,
      "batch": "n=631-640 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-17593",
      "introducing_pr": 17593,
      "fixing_pr": 18840,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Performance cache of Protobuf field descriptors keyed invalidation on `descriptor.getFullName()`. After Schema Registry schema evolution the new `Descriptor` instance keeps the same full name, so stale `FieldDescriptor`s are reused \u2192 `Illeg",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 635,
      "batch": "n=631-640 (2026-07-22)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-3783",
      "introducing_pr": 3783,
      "fixing_pr": 3919,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "writeBytes readerIndex not filed; recovery flags adjacent",
      "defect": "Single-buffer packaging for small add requests used `buf.writeBytes(unwrapped)`, which advances the source ByteBuf's `readerIndex`. Callers (e.g. Pulsar) reusing the buffer then saw corrupted reader positions. Fix uses index-preserving `wri",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 636,
      "batch": "n=631-640 (2026-07-22)",
      "repo": "debezium/debezium",
      "key": "debezium-1090",
      "introducing_pr": 1090,
      "fixing_pr": 6498,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Empty; treated as fix",
      "defect": "Snapshot path restored `SET TRANSACTION ISOLATION LEVEL REPEATABLE READ` after `FLUSH TABLES` but never issued `START TRANSACTION WITH CONSISTENT SNAPSHOT` under the global lock. InnoDB therefore lacked a fixed MVCC view before unlock, so c",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 637,
      "batch": "n=631-640 (2026-07-22)",
      "repo": "trinodb/trino",
      "key": "trino-29362",
      "introducing_pr": 29362,
      "fixing_pr": 30342,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Empty; treated as fix",
      "defect": "Failed-write cleanup for Delta Lake deletion vectors: #29362 filtered out entire `DataFileInfo` entries with a DV to avoid deleting active source Parquet files, but that also skipped deleting newly written DV sidecars, leaving orphans after",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 638,
      "batch": "n=631-640 (2026-07-22)",
      "repo": "hibernate/hibernate-orm",
      "key": "hibernate-8057",
      "introducing_pr": 8057,
      "fixing_pr": 13038,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "unique/not-null property column drop not filed",
      "defect": "`HbmXmlTransformer` property transform path (completed in HHH-17429) drops **unique** and **not-null** when a `<property>` has no explicit `<column>` child \u2014 constraints on the property element itself never transfer to the generated column,",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 639,
      "batch": "n=631-640 (2026-07-22)",
      "repo": "apache/hudi",
      "key": "hudi-18224",
      "introducing_pr": 18224,
      "fixing_pr": 18689,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "string sequence compare not filed",
      "defect": "New JsonKinesisSource treated Kinesis sequence numbers as decimal strings compared with `String.compareTo`. Variable-length 128-bit sequence strings mis-order (e.g. `\"9\"` > `\"10\"` lexicographically), breaking closed-shard fully-consumed che",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 640,
      "batch": "n=631-640 (2026-07-22)",
      "repo": "apache/ozone",
      "key": "ozone-9472",
      "introducing_pr": 9472,
      "fixing_pr": 10260,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "SCM container health reporting after HDDS-14119: `RatisUnhealthyReplicationCheckHandler` incremented under/over-replicated-unhealthy stats but never counted containers that are UNHEALTHY yet sufficiently replicated. Replica-health reports u",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 641,
      "batch": "n=641-650 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-18171",
      "introducing_pr": 18171,
      "fixing_pr": 19036,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "INT\u00d7INT\u2192DOUBLE not filed",
      "defect": "In `BaseBinaryArithmeticScalarFunction.functionInfoForTypes`, PR #18171 inserted an equal-argument-types fast-path *before* the \u201cboth whole numbers \u2192 LONG\u201d rule. `Plus`/`Minus`/`Mult` register only LONG and DOUBLE overloads. For `(INT, INT)",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 642,
      "batch": "n=641-650 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-22479",
      "introducing_pr": 22479,
      "fixing_pr": 22849,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "hiResClockMs not filed",
      "defect": "Share-group DLQ produce path (KAFKA-20613) stamps every DLQ `SimpleRecord` with `time.hiResClockMs()` (`System.nanoTime()` ms, non-epoch origin). Log retention compares record timestamps to wall-clock `milliseconds()`; near-epoch stamps alw",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 643,
      "batch": "n=641-650 (2026-07-22)",
      "repo": "apache/lucene",
      "key": "lucene-16050",
      "introducing_pr": 16050,
      "fixing_pr": 16105,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "doc < upTo off-by-one not filed; density bulk-set adjacent",
      "defect": "`BatchDocValuesRangeIterator#intoBitSet` (added by SIMD/bulk range PR #16050) advances past a YES block with `if (doc < upTo)` after setting `doc = blockEnd`. When `upTo` equals the block boundary (`maxDoc` / block end), the iterator fails ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 644,
      "batch": "n=641-650 (2026-07-22)",
      "repo": "apache/lucene",
      "key": "lucene-16069",
      "introducing_pr": 16069,
      "fixing_pr": 16199,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Empty",
      "defect": "#16069 loads dense filters via `intoBitSet` inside `MaxScoreBulkScorer` windows. When a dense filter has a gap and iterators advance past the outer window `max`, the next inner window computes a **negative** `innerWindowSize` and passes it ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 645,
      "batch": "n=641-650 (2026-07-22)",
      "repo": "FasterXML/jackson-databind",
      "key": "jackson-5988",
      "introducing_pr": 5988,
      "fixing_pr": 5990,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "PTV EnumSet rejection not filed",
      "defect": "CVE-oriented #5988 validated **generic type parameters** via `PolymorphicTypeValidator`. Enum element types are JVM singletons resolved by name (not gadget construction), but were still validated. A name-prefix PTV that allow-lists `java.ut",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 646,
      "batch": "n=641-650 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-13943",
      "introducing_pr": 13943,
      "fixing_pr": 19003,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "withNewTableOptions option-drop not filed; double-get/matches adjacent",
      "defect": "`PinotImplicitTableHintRule.withNewTableOptions` (introduced in #13943 colocated-without-hints) rebuilds the `tableOptions` hint with **only** partition_* keys, discarding any other explicit options. When inference rewrites a scan that also",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 647,
      "batch": "n=641-650 (2026-07-22)",
      "repo": "apache/druid",
      "key": "druid-19460",
      "introducing_pr": 19460,
      "fixing_pr": 19702,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "stale row-id supplier not filed",
      "defect": "Clustered-segment factories from #19460 implemented `getRowIdSupplier()` / vector inspectors by returning the **current** delegate\u2019s supplier directly. After a cluster-group transition (`setDelegate`), callers holding the old supplier see s",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 648,
      "batch": "n=641-650 (2026-07-22)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-48445",
      "introducing_pr": 48445,
      "fixing_pr": 54864,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Dev Services model refactor (#48445) introduced `DevServicesResultBuildItem.discovered()`, which needs a `RunningContainer` to expose env/ports. `ComposeLocator` was updated; `ContainerLocator` still built `ContainerAddress(id, host, port)`",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 649,
      "batch": "n=641-650 (2026-07-22)",
      "repo": "apache/calcite",
      "key": "calcite-4068",
      "introducing_pr": 4068,
      "fixing_pr": 5034,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Empty",
      "defect": "CALCITE-6709 rewrote `TRIM` parsing so that the branch with BOTH/LEADING/ TRAILING requires `<FROM>` then an expression. Legal SQL `TRIM(BOTH ' a ')` (implicit FROM) became a parse failure \u2014 regression vs pre-1.39.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 650,
      "batch": "n=641-650 (2026-07-22)",
      "repo": "spring-projects/spring-kafka",
      "key": "spring-kafka-4360",
      "introducing_pr": 4360,
      "fixing_pr": 4431,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "LOW",
      "defect": "New Streams recovering handlers (`RecoveringProcessingExceptionHandler` / production sibling) build the `ConsumerRecord` passed to `KafkaStreamsDeadLetterDestinationResolver` from **source raw** key/value/headers (`context.sourceRawKey()` /",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 651,
      "batch": "n=651-660 (2026-07-22)",
      "repo": "spring-projects/spring-kafka",
      "key": "spring-kafka-4469",
      "introducing_pr": 4469,
      "fixing_pr": 4505,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Empty",
      "defect": "`KafkaMessageListenerContainer.handleAsyncFailure` (after #4469) no longer re-queues `FailedRecordTuple` on `RecordInRetryException`, relying solely on seek-induced re-delivery. With **two** always-failing async/suspend records on the same ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 652,
      "batch": "n=651-660 (2026-07-22)",
      "repo": "redisson/redisson",
      "key": "redisson-874588fa",
      "introducing_pr": "874588fa394c",
      "fixing_pr": 7035,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "`MasterSlaveConnectionManager.detectCluster()` switched single-node cluster detection from `MGET` to a Lua `EVAL` script, but the script called `redis.call('get', KEYS[i], ARGV[i])` \u2014 **GET arity is 1**, so Redis rejects the script and clus",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 653,
      "batch": "n=651-660 (2026-07-22)",
      "repo": "apache/logging-log4j2",
      "key": "log4j2-a1b952bd",
      "introducing_pr": "a1b952bd472d",
      "fixing_pr": 4125,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "retry break-then-error not filed; retryCount dual-path adjacent",
      "defect": "`KafkaAppender.append` app-level retry loop does `tryAppend` then `break` on success, but control still falls through to `error(...)` after the while \u2014 so a **successful retry still reports an error** to the ErrorHandler (and can mislead op",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 654,
      "batch": "n=651-660 (2026-07-22)",
      "repo": "redis/jedis",
      "key": "jedis-4226",
      "introducing_pr": 4226,
      "fixing_pr": 4547,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "`TrackingConnectionPool` / Connection builder path initializes a pooled `Connection` twice (Builder.build initializes; factory `makeObject` initializes again) \u2192 extra HELLO/CLIENT round-trips and double-registered default PUBSUB_CONSUMER on",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 655,
      "batch": "n=651-660 (2026-07-22)",
      "repo": "apache/paimon",
      "key": "paimon-1535",
      "introducing_pr": 1535,
      "fixing_pr": 7333,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "removeIf O(n\u00b7m) not filed; dual full scan adjacent",
      "defect": "#1535 adds incremental tag-read planning in `SnapshotReaderImpl` and deduplicates before/after manifest entry lists with `before.removeIf(data::remove)` (later renamed `beforeEntries.removeIf(dataEntries::remove)`). Both sides are `ArrayLis",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 656,
      "batch": "n=651-660 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-18033",
      "introducing_pr": 18033,
      "fixing_pr": 18067,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no-dict decompress cost not filed",
      "defect": "#18033 extends `PinotSegmentSorter.getSortedDocIds` to no-dictionary columns via new `PinotSegmentColumnReader.compare(docId1, docId2)` that reads typed values from the forward index on every comparison. Quicksort\u2019s random access thrashing ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 657,
      "batch": "n=651-660 (2026-07-22)",
      "repo": "apache/druid",
      "key": "druid-12600",
      "introducing_pr": 12600,
      "fixing_pr": 12679,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "LOW",
      "defect": "#12600 widens `SqlSegmentsMetadataQuery` OVERLAPS SQL with extra OR bounds (`minmatch`/`maxmatch`) so extreme-year segment intervals match. Those predicates also pull large numbers of non-overlapping segments (lexicographic year jumble), so",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 658,
      "batch": "n=651-660 (2026-07-22)",
      "repo": "apache/pulsar",
      "key": "pulsar-18987",
      "introducing_pr": 18987,
      "fixing_pr": 18997,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#18987 makes `ServerCnx.handleAck` copy `CommandAck` before async work (`new CommandAck().copyFrom(ack)`) so the recycled `BaseCommand` is not shared across threads. Because the broker always installed a non-null `BrokerInterceptorDisabled`",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 659,
      "batch": "n=651-660 (2026-07-22)",
      "repo": "apache/ozone",
      "key": "ozone-668",
      "introducing_pr": 668,
      "fixing_pr": 9633,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#668 (HDDS-3139) changes `PipelinePlacementPolicy` to sort healthy datanodes by pipeline load via `Stream.sorted(Comparator.comparingInt(...))` on every placement, turning the prior linear filter into O(n log n) over the full DN list. Fix #",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 660,
      "batch": "n=651-660 (2026-07-22)",
      "repo": "apache/hudi",
      "key": "hudi-4480",
      "introducing_pr": 4480,
      "fixing_pr": 10130,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#4480\u2019s bucket-index abstraction for simple/consistent hashing tags records with an eager Spark action `records.map(HoodieRecord::getPartitionPath).distinct().collectAsList()` plus mapper materialization, inserting two unnecessary stages on",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 661,
      "batch": "n=661-670 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-133446",
      "introducing_pr": 133446,
      "fixing_pr": 134481,
      "lane": "performance",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "Empty",
      "defect": "#133446 stops sharing Lucene `Weight` across ES|QL Drivers to fix a serverless NPE (`bulkScorer` null when concurrent drivers race a shared Weight). That forces per-driver weight/scorer construction and regressed some query shapes. Fix #134",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 662,
      "batch": "n=661-670 (2026-07-22)",
      "repo": "apache/camel",
      "key": "camel-16105",
      "introducing_pr": 16105,
      "fixing_pr": 24736,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "PR #16105 adds camel-amqp SSL (`useSsl` + store options) and, when `useSsl=true`, always appends all six `transport.*` store query params onto the Qpid JMS URI. When store locations are null/unset (common trust-JVM-defaults / server-only TL",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 663,
      "batch": "n=661-670 (2026-07-22)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-7679",
      "introducing_pr": 7679,
      "fixing_pr": 49791,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "brute-force lockout skip not filed; other CIBA issues adjacent",
      "defect": "PR #7679 lands Client-Initiated Backchannel Authentication including `BackchannelAuthenticationEndpoint.resolveUser`, which only checks `user == null || !user.isEnabled()` and never consults `BruteForceProtector`. A temporarily locked accou",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 664,
      "batch": "n=661-670 (2026-07-22)",
      "repo": "AsyncHttpClient/async-http-client",
      "key": "ahc-67f1cd6696",
      "introducing_pr": "67f1cd669630",
      "fixing_pr": 2234,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Empty",
      "defect": "`NettyRequestFactory.newNettyRequest` always calls `addAuthorizationHeader(... perRequestAuthorizationHeader ...)` even when building the CONNECT used to open an HTTPS tunnel. That CONNECT is sent to the proxy in the clear, so preemptive Ba",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 665,
      "batch": "n=661-670 (2026-07-22)",
      "repo": "apache/cxf",
      "key": "cxf-52bdff0740",
      "introducing_pr": "52bdff074019",
      "fixing_pr": 3317,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Commit `52bdff0740` makes JWT Authorization Request (JAR) claims overwrite outer form parameters indiscriminately (`Store previous params in the new map, allow them to be overwritten by request params`). That includes `code_challenge`, `cod",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 666,
      "batch": "n=661-670 (2026-07-22)",
      "repo": "apache/pulsar",
      "key": "pulsar-9275",
      "introducing_pr": 9275,
      "fixing_pr": 26046,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "volatile exclusiveLeaderProducer not filed; other leadership races adjacent",
      "defect": "FunctionMetaDataManager.exclusiveLeaderProducer is the sole leadership signal (non-null \u21d2 leader). #9275 reworks exclusive-producer leadership so acquireLeadership(Producer) writes exclusiveLeaderProducer without holding the instance monito",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 667,
      "batch": "n=661-670 (2026-07-22)",
      "repo": "apache/flink",
      "key": "flink-13366",
      "introducing_pr": 13366,
      "fixing_pr": 28463,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "FutureCompletingBlockingQueue (FLIP-27 split-fetcher \u2192 source-reader handover) #13366 rewrote the queue with per-putter Condition objects tracked in notFull. waitOnPut does notFull.add(cond); cond.await() and never removes the condition whe",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 668,
      "batch": "n=661-670 (2026-07-22)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-78",
      "introducing_pr": 78,
      "fixing_pr": 4701,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "HandleFactoryImpl.getHandle is the sole map that must return the *same* LedgerDescriptor instance so fencing and addEntry share synchronized(handle). BOOKKEEPER-852 (#78) migrates ledgers to ConcurrentLongHashMap and rewrites getHandle to c",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 669,
      "batch": "n=661-670 (2026-07-22)",
      "repo": "apache/helix",
      "key": "helix-2844",
      "introducing_pr": 2844,
      "fixing_pr": 2934,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "HelixGatewayServiceGrpcService (#2844 GatewayServiceManager work) stores per-instance StreamObserver in a plain HashMap and calls observer.onNext from sendStateChangeRequests without synchronization. gRPC StreamObserver onNext/ onError/onCo",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 670,
      "batch": "n=661-670 (2026-07-22)",
      "repo": "apache/ozone",
      "key": "ozone-1780",
      "introducing_pr": 1780,
      "fixing_pr": 10613,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "DeletedBlockLogStateManagerImpl (#1780 HDDS-3205 DeleteBlock via Ratis) introduces deletingTxIDs = ConcurrentHashMap.newKeySet() filtered by the read-only iterator and cleared in onFlush() on the SCM state-machine thread. Iterator holds a l",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 671,
      "batch": "n=671-679 (2026-07-22)",
      "repo": "apache/kafka",
      "key": "kafka-14406",
      "introducing_pr": 14406,
      "fixing_pr": 21476,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "AsyncKafkaConsumer fetch path races the application poll thread against a background thread that observes CompletedFetch.isConsumed. isConsumed was non- volatile and drain() set isConsumed=true before the subscription position was advanced.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 672,
      "batch": "n=671-679 (2026-07-22)",
      "repo": "micronaut-projects/micronaut-core",
      "key": "micronaut-53f75c9788",
      "introducing_pr": "53f75c97884a",
      "fixing_pr": 12773,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Commit `53f75c9788` (\"Support SSL configuration per manual http service\") adds `ServiceSslClientConfiguration` without `setEnabled(true)`. Declaring any `micronaut.http.services.<name>.ssl.*` property binds a disabled SSL config \u2192 HTTPS cli",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 673,
      "batch": "n=671-679 (2026-07-22)",
      "repo": "SAP/cloud-security-services-integration-library",
      "key": "sap-c9061a3d",
      "introducing_pr": "c9061a3d70a0",
      "fixing_pr": 1979,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "Empty",
      "defect": "Commit `c9061a3d` \"Fix FIPS compatibility by using default KeyManagerFactory algorithm\" drops SunX509 preference and passes null TrustManagers into SSLContext.init \u2192 `No X509TrustManager implementation available` mTLS handshake failures on ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 674,
      "batch": "n=671-679 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-45272",
      "introducing_pr": 45272,
      "fixing_pr": 56090,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#45272 adds `xpack.notification.email.ssl.*` and always installs SSLService socket factory when an SSLConfiguration exists, ignoring legacy Account `smtp.ssl.trust` hostname list.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 675,
      "batch": "n=671-679 (2026-07-22)",
      "repo": "AsyncHttpClient/async-http-client",
      "key": "ahc-2227",
      "introducing_pr": 2227,
      "fixing_pr": 2251,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#2227 replaces Thread.sleep busy-poll with an event-driven `http2ConnectionWaiters` registry in `ChannelManager`. Residual races: (1) a waiter throwing from `accept` aborts the notify loop so later waiters never fire and permits leak; (2) r",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 676,
      "batch": "n=671-679 (2026-07-22)",
      "repo": "trinodb/trino",
      "key": "trino-1ef442738f",
      "introducing_pr": "1ef442738fc5",
      "fixing_pr": 22039,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "LOW",
      "defect": "Commit `1ef442738f` (\"Decide number of clients basing on average request size of client\") reworks `DirectExchangeClient.scheduleRequestIfNecessary` and keeps `queuedClients` as a `LinkedList`/`Deque` that is scanned with contains/filter-sty",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 677,
      "batch": "n=671-679 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-14179",
      "introducing_pr": 14179,
      "fixing_pr": 19028,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "tryLock gates first-time snapshots not filed",
      "defect": "#14179 adds non-blocking `segmentLock.tryLock()` around upsert validDocIds snapshot writes (to avoid deadlock with Helix replace holding segmentLock then snapshot RLock). The two-loop `doTakeSnapshot` used tryLock failure in the *first* loo",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 678,
      "batch": "n=671-679 (2026-07-22)",
      "repo": "elastic/elasticsearch",
      "key": "es-150160",
      "introducing_pr": 150160,
      "fixing_pr": 152293,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "false ISE group-by-all not filed",
      "defect": "After #150160 moved `TranslateTimeSeriesAggregate` to the Analyzer, the rule still threw `IllegalStateException: unexpected inline filter in time-series aggregation` whenever an `_over_time` agg had a filter but the outer aggregate had none",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 679,
      "batch": "n=671-679 (2026-07-22)",
      "repo": "apache/pinot",
      "key": "pinot-17315",
      "introducing_pr": 17315,
      "fixing_pr": 17675,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#17315 adds renewable TlsUtils SSL context to HttpsSegmentFetcher, but SegmentFetcherFactory still maps default HTTPS protocol to HttpSegmentFetcher \u2014 renewable SSL options never apply on the default HTTPS path until #17675 registers HTTPS_",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 680,
      "batch": "n=680-689 (2026-07-23)",
      "repo": "alibaba/nacos",
      "key": "nacos-14751",
      "introducing_pr": 14751,
      "fixing_pr": 15182,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Residual incomplete ConcurrentHashMap check-then-act. #14751 rewrote several naming-module containsKey+get sites to single get+null-check, but left three readers on the old pattern: ClientServiceIndexesManager#getAllClientsRegisteredService",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 681,
      "batch": "n=680-689 (2026-07-23)",
      "repo": "alibaba/nacos",
      "key": "nacos-3654",
      "introducing_pr": 3654,
      "fixing_pr": 14779,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "CRITICAL",
      "defect": "Incomplete ConcurrentHashMap. #3654 (HTTPS client support) newly adds TlsFileWatcher with watchFilesMap as ConcurrentHashMap but fileMd5Map as a plain HashMap. fileMd5Map is written from addFileChangeListener on the caller thread and read/w",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 682,
      "batch": "n=680-689 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-146780",
      "introducing_pr": 146780,
      "fixing_pr": 147796,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Incomplete ConcurrentHashMap / unsafe lazy map. #146780 (Hadoop-free Parquet path) introduces PlainCompressionCodecFactory with two plain HashMaps + computeIfAbsent for compressors/decompressors. Once the factory is shared across query driv",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 683,
      "batch": "n=680-689 (2026-07-23)",
      "repo": "apache/pinot",
      "key": "pinot-9311",
      "introducing_pr": 9311,
      "fixing_pr": 13104,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "TOCTOU / dual-path stats on one map of per-server counters. #9311 Adaptive Server Selection records numInFlightRequests from both the Netty response path (recordStatsUponResponseArrival) and the Jetty timeout/completion path (getFinalRespon",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 684,
      "batch": "n=680-689 (2026-07-23)",
      "repo": "apache/dubbo",
      "key": "dubbo-9420",
      "introducing_pr": 9420,
      "fixing_pr": 9588,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Residual incomplete race fix (R2 exception). MetadataInfo.ServiceInfo#getMethodParameter lazy-inits methodParams / consumerMethodParams under a non-atomic null check. #9420 \"Fix #9086 NPE\" only null-guarded map.get after partial publication",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 685,
      "batch": "n=680-689 (2026-07-23)",
      "repo": "apache/camel",
      "key": "camel-21703",
      "introducing_pr": 21703,
      "fixing_pr": 22381,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / cleared / empty",
      "defect": "Single lock-order deadlock. CAMEL-20199 (#21703) replaced synchronized with ReentrantLock for virtual-thread un-pinning. In QueueReplyManager this collapsed two independent monitors (BaseService private lock vs QueueReplyManager.this) into ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 686,
      "batch": "n=680-689 (2026-07-23)",
      "repo": "apache/flink",
      "key": "flink-22380",
      "introducing_pr": 22380,
      "fixing_pr": 22769,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "Single lock-order deadlock. FLINK-31773 (#22380) reworked DefaultLeaderElectionService lifecycle (driver start separated from contender registration) and moved driver close under the service lock monitor while removing the running field. Rp",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 687,
      "batch": "n=680-689 (2026-07-23)",
      "repo": "apache/hudi",
      "key": "hudi-17773",
      "introducing_pr": 17773,
      "fixing_pr": 19202,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / cleared / empty",
      "defect": "Cross-thread close race on one iterator. #17773 adds Flink Source V2 stack (HoodieSourceSplitReader, BatchRecords, \u2026). BatchRecords holds a live ClosableIterator drained on the Flink task thread while split-fetcher teardown closes the same ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 688,
      "batch": "n=680-689 (2026-07-23)",
      "repo": "apache/druid",
      "key": "druid-8950",
      "introducing_pr": 8950,
      "fixing_pr": 19497,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / cleared / empty",
      "defect": "Concurrent init race on shared FileSystem. #8950 (native ORC batch ingestion) adds OrcInputFormat.createReader that calls initialize() \u2014 swapping Thread.currentThread().setContextClassLoader and FileSystem.get(conf) \u2014 on every createReader.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 689,
      "batch": "n=680-689 (2026-07-23)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-4609",
      "introducing_pr": 4609,
      "fixing_pr": 4737,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Get-then-async-then-remove race made fatal by recycle-null. #4609 (shared Netty recycler for bookie-client completions) extracts AddCompletion etc. with release() that nulls fields before returning to the pool. readV3Response still did non-",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 690,
      "batch": "n=690-699 (2026-07-23)",
      "repo": "lettuce-io/lettuce-core",
      "key": "lettuce-3486",
      "introducing_pr": 3486,
      "fixing_pr": 3801,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "LOW",
      "defect": "#3486 (XREADGROUP CLAIM support) rewrote `StreamReadOutput.complete` to emit a `StreamMessage` when `depth == 2` (was `depth == 3`) so CLAIM extra integers fit the nesting. Under RESP2 the outer array shifts nesting: stream-key completion a",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 691,
      "batch": "n=690-699 (2026-07-23)",
      "repo": "apache/commons-vfs",
      "key": "commons-vfs-438",
      "introducing_pr": 438,
      "fixing_pr": 773,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "LOW",
      "defect": "#438 (VFS-524 IPv6 URI parsing) taught `UriParser.decode` to set `ipv6Host=true` on any `[` and skip percent-decoding until `]`. That is correct inside the authority (`http://[fe80::1]/\u2026`) but also matches brackets in path segments (`file:/",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 692,
      "batch": "n=690-699 (2026-07-23)",
      "repo": "swagger-api/swagger-core",
      "key": "swagger-5004",
      "introducing_pr": 5004,
      "fixing_pr": 5205,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#5004 adds `resolveArraySchemaWithCycleGuard` that calls `AnnotationsUtils.getArraySchema(..., processSchemaImplementation=false)` when the annotated type is already on the resolve stack (recursive models). With `processSchemaImplementation",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 693,
      "batch": "n=690-699 (2026-07-23)",
      "repo": "apache/druid",
      "key": "druid-15842",
      "introducing_pr": 15842,
      "fixing_pr": 19592,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#15842 (Delta Kernel 3.1.0) rewrote `DeltaInputSourceIterator.hasNext` for multi-file scans: it took `filteredColumnarBatchIterators.next()` into a **local** `filteredBatchIterator`, scanned only until the first non-empty batch, then return",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 694,
      "batch": "n=690-699 (2026-07-23)",
      "repo": "apache/pinot",
      "key": "pinot-14823",
      "introducing_pr": 14823,
      "fixing_pr": 15200,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#14823 (MSQE cancellation + clientQueryId) makes engine `getRunningQueries()` return `Collections.unmodifiableMap(_queriesById)` and rewrites `BrokerRequestHandlerDelegate.getRunningQueries` to `queries = single.getRunningQueries(); queries",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 695,
      "batch": "n=690-699 (2026-07-23)",
      "repo": "eclipse-store/store",
      "key": "store-755",
      "introducing_pr": 755,
      "fixing_pr": 767,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#755 (multi-channel GC pending-load gate) gives `StorageTaskBroker.Default` a **strong** `StorageSystem` field so enqueue can signal the mark monitor. Channel threads (non-daemon) \u2192 broker \u2192 StorageSystem keeps the system strongly reachable",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 696,
      "batch": "n=690-699 (2026-07-23)",
      "repo": "apache/camel",
      "key": "camel-94847d8c4a84",
      "introducing_pr": "94847d8c4a84",
      "fixing_pr": 24802,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Commit CAMEL-17049 (no PR; 2021-10-12) replaced `nestedParameters.putAll(this.parameters)` with a nested loop: for each endpoint param, for each operation param, `if (!clash) nestedParameters.put(...)`. Quantifier is inverted \u2014 put runs whe",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 697,
      "batch": "n=690-699 (2026-07-23)",
      "repo": "apache/pulsar",
      "key": "pulsar-20607",
      "introducing_pr": 20607,
      "fixing_pr": 22685,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#20607 adds `userCreatedProducerCount` and decrements it in `AbstractTopic.removeProducer`. `NonPersistentTopic` already overrode `removeProducer` without the new decrement, so closes never lower the counter; with `maxProducersPerTopic` set",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 698,
      "batch": "n=690-699 (2026-07-23)",
      "repo": "apache/pinot",
      "key": "pinot-18237",
      "introducing_pr": 18237,
      "fixing_pr": 18941,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#18237 adds `PlanNodeRoutingQueryBuilder` for MSE broker pruning. It folds every Filter/Project in the leaf chain and **silently skips** other node types, continuing upward. With partitioned group-by (DIRECT aggregate, no exchange), a HAVIN",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 699,
      "batch": "n=690-699 (2026-07-23)",
      "repo": "apache/camel",
      "key": "camel-17092",
      "introducing_pr": 17092,
      "fixing_pr": 24746,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / cleared / empty",
      "defect": "#17092 (CAMEL-21733 Poll EIP DynamicAware) paths leave `GenericFileOnCompletion` re-evaluating the idempotent key expression at completion against the routed exchange\u2019s **mutated** headers. If the route changes `CamelFileName` (or other key",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 700,
      "batch": "n=700-709 (2026-07-23)",
      "repo": "apache/hudi",
      "key": "hudi-4307",
      "introducing_pr": 4307,
      "fixing_pr": 8079,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "LOW",
      "defect": "`#4307` implemented `HoodieMetadataFileSystemView#reset`/`#sync` for metadata-table-backed FS views, but the sync is not atomic with the timeline the timeline-server RequestHandler uses. With both metadata table and timeline server enabled,",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 701,
      "batch": "n=700-709 (2026-07-23)",
      "repo": "apache/hudi",
      "key": "hudi-9723",
      "introducing_pr": 9723,
      "fixing_pr": 19075,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "LOW",
      "defect": "Partition TTL management `#9723` computes `ttlInMilis = writeConfig.getPartitionTTLStrategyDaysRetain() * 1000 * 3600 * 24` with `int` arithmetic in `KeepByTimeStrategy`. For `daysRetain > 24` the product overflows `Integer.MAX_VALUE` (goes",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 702,
      "batch": "n=700-709 (2026-07-23)",
      "repo": "linkedin/venice",
      "key": "venice-2468",
      "introducing_pr": 2468,
      "fixing_pr": 2622,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "findings lack GT keywords ['broker', 'fabric', 'global', 'source']",
      "defect": "Spark KIF repush enablement `#2468` sets source-broker address via `setInputConf()` into **both** DataFrameReader options and `SparkSession` runtime config under `PUBSUB_BROKER_ADDRESS`. Executors later broadcast `SparkSession.conf().getAll",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 703,
      "batch": "n=700-709 (2026-07-23)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-19793",
      "introducing_pr": 19793,
      "fixing_pr": 22193,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "`#19793` removes legacy Elasticsearch version support so `Version.fromId()` throws `UnsupportedVersionException` for unmasked legacy ES version IDs. `SnapshotInfo` deserialization still calls `Version.fromId()` unconditionally on stored `ve",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 704,
      "batch": "n=700-709 (2026-07-23)",
      "repo": "apache/accumulo",
      "key": "accumulo-6077",
      "introducing_pr": 6077,
      "fixing_pr": 6166,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "LOW",
      "defect": "`#6077` added `ServiceLock.deleteLock(..., path, ...)` that `zoo.recursiveDelete(path)` on the **entire** lock path (including the top-level `gc/lock/` node) when zapping GC locks. That removes the parent ZK path itself, breaking subsequent",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 705,
      "batch": "n=700-709 (2026-07-23)",
      "repo": "trinodb/trino",
      "key": "trino-18332",
      "introducing_pr": 18332,
      "fixing_pr": 18789,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "LOW",
      "defect": "Delta Lake metadata-only DELETE pushdown `#18332` adds `executeDelete` for enforceable partition/full-table filters but **omits** `checkWriteAllowed` / `checkWriteSupported` that other mutating paths call. The new durable DELETE path can ru",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 706,
      "batch": "n=700-709 (2026-07-23)",
      "repo": "brettwooldridge/HikariCP",
      "key": "hikaricp-60c4aa0fb1c1",
      "introducing_pr": "60c4aa0fb1c1",
      "fixing_pr": 2346,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Commit `60c4aa0` (\"fixes #2323 \u2026 get/setSchema behavior\") rewrote `ProxyConnection.setSchema` so `DIRTY_BIT_SCHEMA` is set only when `delegate.getSchema()` is non-null and differs from the pool's configured schema. After a borrower sets a s",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 707,
      "batch": "n=700-709 (2026-07-23)",
      "repo": "apache/struts",
      "key": "struts-1625",
      "introducing_pr": 1625,
      "fixing_pr": 1775,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#1625 (WW-5618) adds `StrutsJSONReader` with DoS limits (`maxDepth`/`maxElements`/\u2026) and injects **one** reader into `JSONInterceptor`. Parse cursor, token buffer, and nesting depth live as **instance fields**. Concurrent `read()` calls on ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 708,
      "batch": "n=700-709 (2026-07-23)",
      "repo": "open-telemetry/opentelemetry-java",
      "key": "otel-6924",
      "introducing_pr": 6924,
      "fixing_pr": 8504,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#6924 adds default getters on `ReadWriteLogRecord` for binary compatibility. `getObservedTimestampEpochNanos()` default returns `toLogRecordData().getTimestampEpochNanos()` instead of `getObservedTimestampEpochNanos()` \u2014 observed-time calle",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 709,
      "batch": "n=700-709 (2026-07-23)",
      "repo": "open-telemetry/opentelemetry-java",
      "key": "otel-6429",
      "introducing_pr": 6429,
      "fixing_pr": 8493,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#6429 \"Low allocation OTLP logs marshaler\" adds `LogStatelessMarshaler`, which passes the `TraceFlags` **byte** into int-taking `serializeFixed32` / `sizeFixed32` without masking. High bit set (`0x80`) sign-extends to `80 FF FF FF` little-e",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 710,
      "batch": "n=710-719 (2026-07-23)",
      "repo": "apache/httpcomponents-core",
      "key": "httpcore-513",
      "introducing_pr": 513,
      "fixing_pr": 674,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#513 (HTTPCORE-775) \"fixed\" `SSLIOSession::write` BUFFER_OVERFLOW by expanding the encrypted output buffer as far as needed for the full `src` payload. That disables real TLS write backpressure and blows heap/latency under load (buffers gro",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 711,
      "batch": "n=710-719 (2026-07-23)",
      "repo": "resilience4j/resilience4j",
      "key": "resilience4j-1557",
      "introducing_pr": 1557,
      "fixing_pr": 2478,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#1557 adds `HedgeConfig` + `Builder(HedgeConfig baseConfig)` used by `HedgeConfig.from(...)`. Copy ctor copies most fields but **omits `durationSupplierType`**, which defaults to `PRECONFIGURED`. Copying an `AVERAGE_PLUS` config silently do",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 712,
      "batch": "n=710-719 (2026-07-23)",
      "repo": "deephaven/deephaven-csv",
      "key": "deephaven-309",
      "introducing_pr": 309,
      "fixing_pr": 310,
      "lane": "performance",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / cleared / empty",
      "defect": "#309 adds opt-in CSV escape-character support in `DelimitedCellGrabber` quoted/unquoted scan loops. The new control flow forces extra branches/calls per character on the hot parse path \u2192 5\u201310% throughput regression on benchmarks even when e",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 713,
      "batch": "n=710-719 (2026-07-23)",
      "repo": "open-telemetry/opentelemetry-java",
      "key": "otel-5246",
      "introducing_pr": 5246,
      "fixing_pr": 8565,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "With only client mTLS configured (`setClientTls` / autoconfig key material, no custom trust store), `TlsConfigHelper` builds an `SSLContext` with the client `KeyManager` but may leave `trustManager` null. OkHttp sender installed the custom ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 714,
      "batch": "n=710-719 (2026-07-23)",
      "repo": "fabric8io/kubernetes-client",
      "key": "k8s-client-3857",
      "introducing_pr": 3857,
      "fixing_pr": 7953,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "JDK HTTP client backend only calls `HttpRequest.Builder.method(...)` inside the `body != null` branch. Bodyless requests (DELETE/GET with caller-selected verb via `Client.raw` / `OperationSupport.handleRaw`) keep the default method (GET) \u2014 ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 715,
      "batch": "n=710-719 (2026-07-23)",
      "repo": "zxing/zxing",
      "key": "zxing-2179c52ee3",
      "introducing_pr": "2179c52ee3",
      "fixing_pr": 2110,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "`URIResultParser.isPossiblyMaliciousURI` uses `USER_IN_HOST.find()` where `:` is inside the userinfo class `[^/@]`. Crafted input `\"http://\" + thousands of ':'` is **quadratic** regex backtracking on the full decoded text (~600ms vs ~1ms) \u2014",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 716,
      "batch": "n=710-719 (2026-07-23)",
      "repo": "camunda/camunda",
      "key": "camunda-43503",
      "introducing_pr": 43503,
      "fixing_pr": 58326,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#43503 replaces top_hits aggregation with scroll in `ElasticsearchProcessStore.getProcessesGrouped` / OpenSearch counterpart so all process versions are returned. The new scroll request omits an explicit page `size`, so ES/OS default to **1",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 717,
      "batch": "n=710-719 (2026-07-23)",
      "repo": "hiero-ledger/hiero-mirror-node",
      "key": "hiero-12943",
      "introducing_pr": 12943,
      "fixing_pr": 13162,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "LOW",
      "defect": "#12943 rewires web3 exchange-rate loading (`SystemFileLoader`, singletons, `ExchangeRateManager`) so the latest DB rate is used. The rewrite drops / misplaces **hour-floor normalization** of consensus timestamps used as cache keys, so each ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 718,
      "batch": "n=710-719 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-147176",
      "introducing_pr": 147176,
      "fixing_pr": 152938,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#147176 adds `ImplicitPrivilegesProvider` SPI. Providers receive stored `ApplicationPrivilegeDescriptor`s and rebuild a `StringMatcher` over every action on **each role build**. With realistic Kibana roles (thousands of `\"all\"` actions, col",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 719,
      "batch": "n=710-719 (2026-07-23)",
      "repo": "eclipse-openj9/openj9",
      "key": "openj9-20111",
      "introducing_pr": 20111,
      "fixing_pr": 24042,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / cleared / empty",
      "defect": "#20111 adds off-heap / dual-header awareness in DDR (`J9IndexableObjectHelper` et al.). `isIndexableDataAddrPresent()` (and callers like `rawSize`) re-resolve `J9RASHelper.getVM` / `javaVM.isIndexableDataAddrPresent()` on **every call** wit",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 720,
      "batch": "n=720-728 (2026-07-23)",
      "repo": "apache/druid",
      "key": "druid-16511",
      "introducing_pr": 16511,
      "fixing_pr": 16740,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "LOW",
      "defect": "#16511 deserializes group-by dimensions over the wire into their **typed** complex forms via per-dimension Jackson (`objectMapper.readValue` style) so complex group-by works. On large result sets the per-value Jackson overhead dominates bro",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 721,
      "batch": "n=720-728 (2026-07-23)",
      "repo": "apache/knox",
      "key": "knox-1258",
      "introducing_pr": 1258,
      "fixing_pr": 1300,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "PR #1258 adds `RolesLookupBypassControl` so internal Knox LDAP searches can skip the roles-rewrite interceptor and return raw group DNs. `KnoxLDAPServerManager.getUserGroups` never attaches the control. With `LDAPRolesLookupInterceptor` act",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 722,
      "batch": "n=720-728 (2026-07-23)",
      "repo": "AsyncHttpClient/async-http-client",
      "key": "ahc-7136391a05",
      "introducing_pr": "7136391a05",
      "fixing_pr": 2245,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "`perConnectionAuthorizationHeader` for origin KERBEROS/SPNEGO picks `proxyServer.getHost()` whenever a proxy is configured, minting a service ticket for the proxy SPN instead of the origin. Origin Negotiate auth fails / credentials are usab",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 723,
      "batch": "n=720-728 (2026-07-23)",
      "repo": "AsyncHttpClient/async-http-client",
      "key": "ahc-63d4ba7702",
      "introducing_pr": "63d4ba7702",
      "fixing_pr": 2239,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / cleared / empty",
      "defect": "`Uri` constructor sets `secured = HTTPS.equals(scheme) || WSS.equals(scheme)` (case-sensitive) while `validateSupportedScheme` accepts any case and `webSocket` already used `WSS.equalsIgnoreCase`. A Uri built as `\"HTTPS\"` validates but `isS",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 724,
      "batch": "n=720-728 (2026-07-23)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-22073",
      "introducing_pr": 22073,
      "fixing_pr": 22245,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "#22073 installs process-wide `ObjectInputFilter` reject-all in `Bootstrap.setup()` only. Nodes started via `new PluginAwareNode(settings).start()` never run Bootstrap.setup, so the serial filter never arms \u2014 plugins cannot verify deser opt-",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 725,
      "batch": "n=720-728 (2026-07-23)",
      "repo": "apache/struts",
      "key": "struts-1657",
      "introducing_pr": 1657,
      "fixing_pr": 1773,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "After WW-5624, JSON body population authorized `@StrutsParameter` but still skipped the shared ExcludedPatternsChecker / AcceptedPatternsChecker that ParametersInterceptor applies to form params. JSON keys that fail name allowlists still bi",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 726,
      "batch": "n=720-728 (2026-07-23)",
      "repo": "apache/cxf",
      "key": "cxf-3157",
      "introducing_pr": 3157,
      "fixing_pr": 3256,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "LOW",
      "defect": "#3157 sets `ACCESS_EXTERNAL_SCHEMA=\"\"` so schema resolution routes through SchemaLSResourceResolver \u2192 URIResolver.tryFileSystem under SecurityManager. That path calls `SecurityActions.fileExists()` with `sm.checkPermission()` **outside** do",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 727,
      "batch": "n=720-728 (2026-07-23)",
      "repo": "eclipse-vertx/vertx-grpc",
      "key": "vertx-grpc-126",
      "introducing_pr": 126,
      "fixing_pr": 285,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "MEDIUM",
      "defect": "gRPC frame reassembly compact-every-frame super-linear cost",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 728,
      "batch": "n=720-728 (2026-07-23)",
      "repo": "apache/iceberg",
      "key": "iceberg-11656",
      "introducing_pr": 11656,
      "fixing_pr": 12305,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / cleared / empty",
      "defect": "Parquet 1.15 no-arg builder loads full Hadoop Configuration on every reader init",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 729,
      "batch": "n=729-730 (2026-07-23)",
      "repo": "apache/pulsar",
      "key": "pulsar-17371",
      "introducing_pr": 17371,
      "fixing_pr": 25732,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent shadow lifecycle; retain leak not filed",
      "defect": "ShadowReplicator.replicateEntries retains headersAndPayload ByteBuf before sendAsync; with empty-payload shadow path producer does not own/release that buffer \u2192 Netty LEAK (extra refCnt after Entry release). Fix #25732 removes the retain.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 730,
      "batch": "n=729-730 (2026-07-23)",
      "repo": "eclipse-openj9/openj9",
      "key": "openj9-23890",
      "introducing_pr": 23890,
      "fixing_pr": 24049,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "postCompilationTasks tracks unstored AOT bytes with ineligibleForRelocatableCompile == RELOCATABLE_COMPILE_OK, but TR_NoStoreAOT overwrites to AOT_INELIGIBLE_NO_STORE_AOT so unstored count stays 0. Fix also accepts NO_STORE_AOT. Introduced ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 731,
      "batch": "n=731-740 (2026-07-23)",
      "repo": "apache/druid",
      "key": "druid-14435",
      "introducing_pr": 14435,
      "fixing_pr": 14643,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "KubernetesTaskRunner #14435 removed synchronized(tasks) around ConcurrentHashMap computeIfAbsent/get/remove, selling the CHM as sufficient. Under concurrent doTask completion vs map mutation a workItem can disappear mid-run (ISE 'Task disap",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 732,
      "batch": "n=731-740 (2026-07-23)",
      "repo": "alibaba/nacos",
      "key": "nacos-9914",
      "introducing_pr": 9914,
      "fixing_pr": 14916,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#9914 adds CachedJwtTokenManager (token performance cache) with ConcurrentHashMap userMap/tokenMap and non-atomic containsKey()+get() plus a scheduled cleanExpiredToken remover. Cleanup can evict between containsKey and get \u2192 NPE on token m",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 733,
      "batch": "n=731-740 (2026-07-23)",
      "repo": "apache/pinot",
      "key": "pinot-14237",
      "introducing_pr": 14237,
      "fixing_pr": 18559,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#14237 reworked IdealStateGroupCommit failure handling (Entry._exception, re-queue processed entries) but left a residual race: when a batch fails, the leader's own pending Entry can remain in _pending and be applied by a later leader after",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 734,
      "batch": "n=731-740 (2026-07-23)",
      "repo": "apache/camel",
      "key": "camel-11275",
      "introducing_pr": 11275,
      "fixing_pr": 24872,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#11275 (\"make aws streaming thread safe\") partially synchronized uploadAggregate batching but left processWithoutTimestampGrouping reading/mutating uploadAggregate outside the lock while StreamingUploadTimeoutTask nulls it under the lock \u2192 ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 735,
      "batch": "n=731-740 (2026-07-23)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-20359",
      "introducing_pr": 20359,
      "fixing_pr": 22358,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#20359 stream-transport refactor reworks FlightTransportResponse and adds openAndPrefetchAsync: prefetch can publish flightStream after close() observed null, or close races the finally path \u2192 double-close / stranded stream. #22358 uses Ato",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 736,
      "batch": "n=731-740 (2026-07-23)",
      "repo": "apache/camel",
      "key": "camel-14823",
      "introducing_pr": 14823,
      "fixing_pr": 24727,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#14823 fixes getInOnlyTemplate to check inOnlyTemplate (was wrongly checking inOutTemplate) but leaves plain unsynchronized check-then-act lazy init. Concurrent first messages each create a RabbitTemplate; only the last assignment is retain",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 737,
      "batch": "n=731-740 (2026-07-23)",
      "repo": "apache/hudi",
      "key": "hudi-17717",
      "introducing_pr": 17717,
      "fixing_pr": 18834,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#17717 made RocksDBDAO serializers ConcurrentHashMap to allow multi-threaded Timeline Service access (fixing CME) but left close() racing concurrent puts: handles nulled while other threads still write \u2192 NPE in RocksDBDAO.put. #18834 takes ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 738,
      "batch": "n=731-740 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-114719",
      "introducing_pr": 114719,
      "fixing_pr": 153213,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "InferenceWaitForAllocation.WaitingRequest derived deploymentId() from request.getId() (may be model_id/alias). assignmentForDeploymentId is deployment-id-only, so scale-from-zero waiters looked up the wrong key, saw null, and failed pending",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 739,
      "batch": "n=731-740 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-146576",
      "introducing_pr": 146576,
      "fixing_pr": 148503,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "With routing as sorted doc values, LuceneChangesSnapshot filled ParallelArray.routingOrdinals only on advanceExact hits. Docs without _routing left reused slots holding a prior batch ordinal; later lookupOrd used the stale ord on the curren",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 740,
      "batch": "n=731-740 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-142170",
      "introducing_pr": 142170,
      "fixing_pr": 148754,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "CanMatchPreFilterSearchPhase empty-shards short-circuit returned Collections.emptyMap() for skippedByClusterAlias; callers Map#merge into that immutable map and throw UnsupportedOperationException when remotes report skip counts.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 741,
      "batch": "n=741-750 (2026-07-23)",
      "repo": "apache/maven-resolver",
      "key": "maven-resolver-1785",
      "introducing_pr": 1785,
      "fixing_pr": 1948,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "JettyTransporter set connectTimeout from getHttpRequestTimeout (same as requestTimeout), so connect used the request-timeout config instead of CONNECT_TIMEOUT.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 742,
      "batch": "n=741-750 (2026-07-23)",
      "repo": "trinodb/trino",
      "key": "trino-22102",
      "introducing_pr": 22102,
      "fixing_pr": 30355,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Delta Lake deletion-vector writer double-counted the 4-byte bitmap key in sizeInBytes (serializedSizeInBytes already includes it) and skipped runOptimize; sidecars oversized with trailing zeros broke foreign readers.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 743,
      "batch": "n=741-750 (2026-07-23)",
      "repo": "apache/pinot",
      "key": "pinot-14229",
      "introducing_pr": 14229,
      "fixing_pr": 18959,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "JsonIndexConfig added _indexPaths (later _maxBytesSize) without equals/hashCode updates; configs differing only in those fields compared equal, breaking Map/Set and reload change detection.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 744,
      "batch": "n=741-750 (2026-07-23)",
      "repo": "apache/iceberg",
      "key": "iceberg-11415",
      "introducing_pr": 11415,
      "fixing_pr": 15087,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "ShreddedObject.SerializationState constructor param shreddedFields shadowed the instance field; partial variant shredding lost unshredded fields in durable binary value (permanent data loss).",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 745,
      "batch": "n=741-750 (2026-07-23)",
      "repo": "apache/iceberg",
      "key": "iceberg-11415-fix17066",
      "introducing_pr": 11415,
      "fixing_pr": 17066,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "ShreddedObject.put left prior remove marker in removedFields; remove-then-put made get/fieldNames disagree with writeTo durable bytes.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 746,
      "batch": "n=741-750 (2026-07-23)",
      "repo": "apache/iceberg",
      "key": "iceberg-11144",
      "introducing_pr": 11144,
      "fixing_pr": 17210,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "TableMaintenance.Builder defaulted uidSuffix to UUID.randomUUID(); Flink savepoint restore of table-maintenance state fails across job resubmits.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 747,
      "batch": "n=741-750 (2026-07-23)",
      "repo": "apache/hive",
      "key": "hive-5973",
      "introducing_pr": 5973,
      "fixing_pr": 6423,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "CREATE TABLE moved to DDLSemanticAnalyzerFactory but SemanticAnalyzer.materializeCTE still new SemanticAnalyzer(); NPE after merge of CreateTableAnalyzer extraction.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 748,
      "batch": "n=741-750 (2026-07-23)",
      "repo": "camunda/camunda",
      "key": "camunda-41694",
      "introducing_pr": 41694,
      "fixing_pr": 44866,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Intent.fromProtocolValue linear enum scan after #41694 simplify; fix #44866 O(1) Int2ObjectHashMap.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 749,
      "batch": "n=741-750 (2026-07-23)",
      "repo": "apache/iceberg",
      "key": "iceberg-5505",
      "introducing_pr": 5505,
      "fixing_pr": 8297,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "DefaultCounter Math.addExact(counter.longValue(), amount) multi-thread hot path; fix removes addExact.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 750,
      "batch": "n=741-750 (2026-07-23)",
      "repo": "trinodb/trino",
      "key": "trino-7875",
      "introducing_pr": 7875,
      "fixing_pr": 8559,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "JdbcPageSink auto-commit simplify causes multi-commit write regression on MySQL/SQL Server.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 751,
      "batch": "n=751-760 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-147562",
      "introducing_pr": 147562,
      "fixing_pr": 151102,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "DatasetRewriter FROM <dataset> rewrote with always-open auth predicate before security filter; any ES|QL user could read any dataset via parent datasource credentials.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 752,
      "batch": "n=751-760 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-142325",
      "introducing_pr": 142325,
      "fixing_pr": 148263,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "ResumeBulkByScrollRequest lacked CompositeIndicesRequest and reindex/resume was missing from RBAC name-only composite list, so resume reindex was not authorized like original reindex.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 753,
      "batch": "n=751-760 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-147562-fix149963",
      "introducing_pr": 147562,
      "fixing_pr": 149963,
      "lane": "security",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "DatasetRewriter.mergeSettings flattened datasource secrets into plan/EXPLAIN-facing config so credentials could leak in EXPLAIN output.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 754,
      "batch": "n=751-760 (2026-07-23)",
      "repo": "micrometer-metrics/micrometer",
      "key": "micrometer-4506",
      "introducing_pr": 4506,
      "fixing_pr": 4985,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#4506 switched AnnotationHandler from Class.getMethod to getDeclaredMethod so @MeterTag works on package-private methods. getDeclaredMethod only sees methods declared on the target class itself, so tags declared on a superclass method are s",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 755,
      "batch": "n=751-760 (2026-07-23)",
      "repo": "apache/pekko",
      "key": "pekko-3164",
      "introducing_pr": 3164,
      "fixing_pr": 3201,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#3164 (hostname verification for classic remoting) was based on a branch that predated #3165's fail-fast SSL init, so it reintroduced `private lazy val sslContext` in ConfigSSLEngineProvider. Keystore/truststore misconfiguration is only dis",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 756,
      "batch": "n=751-760 (2026-07-23)",
      "repo": "ebean-orm/ebean",
      "key": "ebean-3794",
      "introducing_pr": 3794,
      "fixing_pr": 3819,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#3794 (DbJson support for DTO queries) rewrote createJsonObjectMapperType to take DeployProperty and added: if DeployBeanProperty, type = getField().getDeclaringClass(). For a generic superclass B<T>, declaring class is the erased B, so Jac",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 757,
      "batch": "n=751-760 (2026-07-23)",
      "repo": "apache/logging-log4j2",
      "key": "log4j2-3508",
      "introducing_pr": 3508,
      "fixing_pr": 3773,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#3508 fixed shutdownHook=disable by restructuring LoggerContext.start(Configuration): it only reconfigures when isInitialized()/isStopped() and removed the unconditional setConfiguration(config) that always ran afterward. When the context i",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 758,
      "batch": "n=751-760 (2026-07-23)",
      "repo": "spring-projects/spring-boot",
      "key": "spring-boot-ad79c373f8",
      "introducing_pr": "ad79c373f827",
      "fixing_pr": 50301,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Commit ad79c373 (\"Add SNI support to web server SSL auto-configuration\") adds SslServerCustomizer SNI mapping that does serverNameSslProviders.get(domainName) and setSuccess(provider) with no fallback. When client-auth/truststore is configu",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 759,
      "batch": "n=751-760 (2026-07-23)",
      "repo": "apache/curator",
      "key": "curator-520",
      "introducing_pr": 520,
      "fixing_pr": 1293,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#520 (CURATOR-729 PersistentWatcher dead-loop fix) registers a CuratorListenable listener in PersistentWatcher.start() so Closed events can be delivered, but never removes it in close(). Each create/start/close cycle leaves an orphan listen",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 760,
      "batch": "n=751-760 (2026-07-23)",
      "repo": "apache/james-project",
      "key": "james-3065",
      "introducing_pr": 3065,
      "fixing_pr": 3069,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#3065 improved mailbox rename by preloading the mailbox and children then renaming via renameSubMailboxes. That helper updated mailbox name and user but not namespace, so id-based renames across namespaces keep the old namespace in storage ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 761,
      "batch": "n=761-770 (2026-07-23)",
      "repo": "ebean-orm/ebean",
      "key": "ebean-3779",
      "introducing_pr": 3779,
      "fixing_pr": 3790,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#3779 redesigned query metric/plan labels for secondary loads. Inline SQL comment labels that previously looked like `/* Customer.hiLabel */` dropped the bean type prefix (`/* hiLabel */`), breaking label-based metrics/plan correlation that",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 762,
      "batch": "n=761-770 (2026-07-23)",
      "repo": "fabric8io/kubernetes-client",
      "key": "k8s-client-7898",
      "introducing_pr": 7898,
      "fixing_pr": 7920,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#7898 adds WatchRequestState.startedAtNs as a plain long, written in startWatch() *after* the volatile publication of latestRequestState. The happens-before of that volatile store does not cover the later plain write, so the WebSocket recei",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 763,
      "batch": "n=761-770 (2026-07-23)",
      "repo": "apache/kafka",
      "key": "kafka-17021",
      "introducing_pr": 17021,
      "fixing_pr": 21989,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "KIP-1076 (#17021) adds StreamsThreadMetricsDelegatingReporter on stream-thread create but never removes it on thread shutdown/replace. With StreamsUncaughtExceptionHandler replacing crashed threads, reporters accumulate \u2192 unbounded metrics ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 764,
      "batch": "n=761-770 (2026-07-23)",
      "repo": "trinodb/trino",
      "key": "trino-18719",
      "introducing_pr": 18719,
      "fixing_pr": 30359,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "Alluxio cache (#18719) AlluxioInputHelper always allocates a per-input page-sized readBuffer for sequential amortization. Positioned reads (AlluxioInput / AbstractParquetDataSource) never use it \u2192 idle page-sized alloc per open input (heap ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 765,
      "batch": "n=761-770 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-152515",
      "introducing_pr": 152515,
      "fixing_pr": 154280,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#152515 rewrites TSDB numeric range as TwoPhaseIterator.intoBitSet but the no-skipper path does not cap upTo at maxDoc. ConstantScoreBulkScorer windows can pass upTo>maxDoc \u2192 EOFException past encoded blocks or phantom matches at docs \u2265 max",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 766,
      "batch": "n=761-770 (2026-07-23)",
      "repo": "open-telemetry/opentelemetry-java",
      "key": "otel-7291",
      "introducing_pr": 7291,
      "fixing_pr": 8497,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#7291 refactored Prometheus label conversion and JSON-encoded array point attributes, but left scope/resource convertAttributes on Object.toString() so array values render as [a, b] (no quotes/escaping) instead of JSON [\"a\",\"b\"]. #8497 rout",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 767,
      "batch": "n=761-770 (2026-07-23)",
      "repo": "micronaut-projects/micronaut-core",
      "key": "micronaut-12678",
      "introducing_pr": 12678,
      "fixing_pr": 12788,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#12678 adds ApplicationContextConfigurationDelegate for CDI/bootstrap wrapping but does not forward getConfigurationLoadingStrategy(). Bootstrap then uses interface default FAIL_ON_DUPLICATE even when caller configured MERGE_ALL \u2192 startup f",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 768,
      "batch": "n=761-770 (2026-07-23)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-54245",
      "introducing_pr": 54245,
      "fixing_pr": 54832,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#54245 migrates K8s/OpenShift volume generation to Fabric8 builders; secret/ConfigMap volume items without explicit mode get mode:-1 from property defaults, which the API rejects. #54832 omits mode when unset so defaultMode applies.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 769,
      "batch": "n=761-770 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-127661",
      "introducing_pr": 127661,
      "fixing_pr": 154644,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "MATCH_PHRASE (#127661) pushdown treats potentially unmapped fields as Lucene match_phrase, silently dropping rows from indices where the field is unmapped. Fix routes such fields to runtime evaluation (mirrors match fix #153800).",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 770,
      "batch": "n=761-770 (2026-07-23)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-50315",
      "introducing_pr": 50315,
      "fixing_pr": 50415,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#50315 widens client-secret-rotation timestamps int\u2192long (Y2K38) but breaks config/default paths that still assume int and reject or mishandle long values. #50415 restores config/defaults to honor long values (reverts breaking surface for p",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 771,
      "batch": "n=771-780 (2026-07-23)",
      "repo": "linkedin/venice",
      "key": "venice-2809",
      "introducing_pr": 2809,
      "fixing_pr": 2927,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#2809 fixed one EOP leader-to-local latestProcessedVtPosition corruption but left a residual race: updateOffsetsFromConsumerRecord still branches on live shouldProduceToVersionTopic(pcs)/consumeRemotely while in-flight leader-produced recor",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 772,
      "batch": "n=771-780 (2026-07-23)",
      "repo": "apache/ozone",
      "key": "ozone-2733",
      "introducing_pr": 2733,
      "fixing_pr": 10324,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "#2733 adopts Hadoop EC CoderUtil with a static emptyChunk buffer. Concurrent ECKeyOutputStreams with different encode lengths race resize/clear of the shared cache \u2192 ArrayIndexOutOfBoundsException during parity encoding (Java raw encoder pa",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 773,
      "batch": "n=771-780 (2026-07-23)",
      "repo": "alibaba/nacos",
      "key": "nacos-9461",
      "introducing_pr": 9461,
      "fixing_pr": 15226,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "Maintainer-cited residual of #9461 null-guard pattern: ConfigRpcTransportClient.checkListenCache uses unsafe cacheMap.get().get(changeKey).isInitializing() pre-dereference. Concurrent removeListener can clear the key \u2192 NPE when server retur",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 775,
      "batch": "n=771-780 (2026-07-23)",
      "repo": "apache/pulsar",
      "key": "pulsar-14648",
      "introducing_pr": 14648,
      "fixing_pr": 18818,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#14648 reworked LinuxBrokerHostUsageImpl NIC-speed handling; overrideBrokerNicSpeedGbps stopped being multiplied by NIC count, wrong bandwidth for multi-NIC brokers (unreleased 2.11). #18818 multiplies by NIC number.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 776,
      "batch": "n=771-780 (2026-07-23)",
      "repo": "apache/iceberg",
      "key": "iceberg-13191",
      "introducing_pr": 13191,
      "fixing_pr": 13386,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#13191 context-aware REST response parsing added an abstract method on BaseHTTPClient, breaking external subclasses. #13386 restores binary compatibility by UOE default when the new parameter is set (historical BaseHTTPClient pattern).",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 777,
      "batch": "n=771-780 (2026-07-23)",
      "repo": "apache/pinot",
      "key": "pinot-16035",
      "introducing_pr": 16035,
      "fixing_pr": 17181,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "PinotJoinPushTransitivePredicatesRule added default-on in #16035. On complex multi-predicate joins it fires recursive Calcite RelMdPredicates/predicateConstants work (RexUtil.isConstant/gatherConstraints) and burns planner CPU. #17181 disab",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 778,
      "batch": "n=771-780 (2026-07-23)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-47414",
      "introducing_pr": 47414,
      "fixing_pr": 55353,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIGH",
      "defect": "DevMCP (#47414) exposes DevUI capabilities as an MCP server in dev mode but was not wired through the same localhost Host + CORS filters applied to other DevUI endpoints \u2192 broader network exposure than sibling dev endpoints.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 779,
      "batch": "n=771-780 (2026-07-23)",
      "repo": "spring-projects/spring-kafka",
      "key": "spring-kafka-3996",
      "introducing_pr": 3996,
      "fixing_pr": 4460,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "Jackson 3 type-mapper (#3996) reverse lookup keyed on Class<?> identity misses when producer classloader \u2260 mapper classloader (DevTools restart). Fallback writes FQCN header instead of configured alias, breaking consumers expecting the alia",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 780,
      "batch": "n=771-780 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-128531",
      "introducing_pr": 128531,
      "fixing_pr": 129107,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#128531 made Limit combine small pages into larger ones to cut exchange overhead, but combined pages drop per-block attributes (e.g. ordinal-based BytesRef). Downstream Enrich ordinal fast-path no longer applies \u2192 large measured slowdown. #",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 781,
      "batch": "n=781-790 (2026-07-23)",
      "repo": "debezium/debezium",
      "key": "debezium-7471",
      "introducing_pr": 7471,
      "fixing_pr": 7488,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (data)",
      "defect": "#7471 switched USE db in getEstimatedTableSize to execute() which commits and ends the snapshot transaction \u2192 inconsistent snapshot. Fix restore executeWithoutCommitting.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 782,
      "batch": "n=781-790 (2026-07-23)",
      "repo": "hazelcast/hazelcast",
      "key": "hazelcast-11660",
      "introducing_pr": 11660,
      "fixing_pr": 12545,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (performance)",
      "defect": "Cleanup of ConcurrencyUtil.getOrPutSynchronized(..., ContextMutexFactory, ...) always called contextMutexFactory.mutexFor(key) (and closed the mutex) even on map hits. Prior code took the factory mutex only on the miss path after a null map",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 783,
      "batch": "n=781-790 (2026-07-23)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-49975",
      "introducing_pr": 49975,
      "fixing_pr": 50223,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#49975 hardens SCIM ScimRealmResourceFactory bearer auth (500\u2192401 when unauthenticated) but still accepts any authenticated client. Public clients can call SCIM. Fix #50223 rejects client.isPublicClient() with 403.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 784,
      "batch": "n=781-790 (2026-07-23)",
      "repo": "apache/struts",
      "key": "struts-1653",
      "introducing_pr": 1653,
      "fixing_pr": 1737,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "Sibling XSS encoding: #1653 HTML-encodes PostbackResult form action. ServletRedirectResult.sendRedirect still writes finalLocation raw into the response body for non-302 statuses (Content-Type text/html) enabling reflected XSS via OGNL-driv",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 785,
      "batch": "n=781-790 (2026-07-23)",
      "repo": "spring-projects/spring-kafka",
      "key": "spring-kafka-4382",
      "introducing_pr": 4382,
      "fixing_pr": 4435,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#4382 makes getStreamsConfiguration return this.properties.clone(); null properties \u2192 NPE. Fix #4435 null-checks before clone.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 786,
      "batch": "n=781-790 (2026-07-23)",
      "repo": "linkedin/venice",
      "key": "venice-2840",
      "introducing_pr": 2840,
      "fixing_pr": 2927,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (concurrency)",
      "defect": "#2840 reverts the prior offset-corruption fix, re-landing leader VT offset updates that branch on live shouldProduceToVersionTopic/consumeRemotely. After consumeRemotely flips false, leader-produced records still advance local VT from the c",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 787,
      "batch": "n=781-790 (2026-07-23)",
      "repo": "hazelcast/hazelcast",
      "key": "hazelcast-21517",
      "introducing_pr": 21517,
      "fixing_pr": 24844,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (concurrency)",
      "defect": "#21517 adds PartitionContainer.cleanUpOnMigration that filters maps via getRecordStore(mapName), which recreates a RecordStore for maps already removed during migration cleanup. Fix filters via MapContainer backup counts without materializi",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 788,
      "batch": "n=781-790 (2026-07-23)",
      "repo": "trinodb/trino",
      "key": "trino-29763",
      "introducing_pr": 29763,
      "fixing_pr": 29877,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (data)",
      "defect": "#29763 fixed nested-field equality-delete key collisions but left FlatEqualityDeleteFilter building channels that mishandle metadata-column projections \u2014 equality deletes mis-filter Iceberg metadata-column queries. Fix dedupes by base colum",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 789,
      "batch": "n=781-790 (2026-07-23)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-46019",
      "introducing_pr": 46019,
      "fixing_pr": 46622,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (performance)",
      "defect": "RealmCacheSession.prepareCachedRealm gained a master-admin-role up-to-date check that, for every non-admin realm, loads the admin role and runs getCompositesStream().noneMatch(...). Expanding composites on the cache-miss/JPA path is N+1, so",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 790,
      "batch": "n=781-790 (2026-07-23)",
      "repo": "swagger-api/swagger-core",
      "key": "swagger-4975",
      "introducing_pr": 4975,
      "fixing_pr": 5005,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#4975 rewrites AnnotatedType.equals/hashCode dropping schemaProperty \u2192 property vs subtype cache collision \u2192 incomplete polymorphic schemas. Fix #5005 includes schemaProperty/isSubtype in equality.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 791,
      "batch": "n=791-800 (2026-07-23)",
      "repo": "FasterXML/jackson-databind",
      "key": "jackson-5772",
      "introducing_pr": 5772,
      "fixing_pr": 5853,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#5772 always type-wraps object-id references; for As.PROPERTY inclusion breaks MINIMAL_CLASS+@JsonIdentityInfo output. Fix #5853 wraps only WRAPPER_ARRAY/WRAPPER_OBJECT.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 792,
      "batch": "n=791-800 (2026-07-23)",
      "repo": "hibernate/hibernate-orm",
      "key": "hibernate-3498",
      "introducing_pr": 3498,
      "fixing_pr": 3694,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.12 slice (campaign stays MISS)",
      "defect": "PR #3498 added temp-table column annotations via column.getSqlTypeCode(metadata) without null-guard. For PersistentTableBulkIdStrategy's hib_sess_id column, getSqlTypeCode(metadata) NPEs. Fix null-checks sqlTypeCode and sets Types.VARCHAR o",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 793,
      "batch": "n=791-800 (2026-07-23)",
      "repo": "apache/accumulo",
      "key": "accumulo-1008",
      "introducing_pr": 1008,
      "fixing_pr": 1012,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#1008 adds Property.resolve() using isPropertySet and switches tablet WAL max via table config that did not implement isPropSet \u2014 resolve fails / wrong property selection.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 794,
      "batch": "n=791-800 (2026-07-23)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-4462",
      "introducing_pr": 4462,
      "fixing_pr": 4701,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (concurrency)",
      "defect": "HandleFactoryImpl.getHandle: putIfAbsent without using winner; concurrent create returns wrong LedgerDescriptor \u2192 entry loss / residual write-after-delete race",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 795,
      "batch": "n=791-800 (2026-07-23)",
      "repo": "apache/ozone",
      "key": "ozone-9150",
      "introducing_pr": 9150,
      "fixing_pr": 9810,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "isSnapshotPurged() returned true when snapshot chain tableKey was null, so orphan-version cleanup deleted active snapshot YAML metadata (NPE / unloadable snapshot). Intro #9150 landed the null\u2192true branch; fix requires purge-flushed transac",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 796,
      "batch": "n=791-800 (2026-07-23)",
      "repo": "apache/pinot",
      "key": "pinot-16615",
      "introducing_pr": 16615,
      "fixing_pr": 17723,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.12 slice (campaign stays MISS)",
      "defect": "#16615 adds disableSummary so rebalance can skip summary (summaryResult=null). Later summaryResult.getSegmentInfo() runs unguarded \u2192 NPE when summary disabled. Fix #17723 null-guards the read.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 797,
      "batch": "n=791-800 (2026-07-23)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-49962",
      "introducing_pr": 49962,
      "fixing_pr": 50275,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (security)",
      "defect": "#49962 rewrites SCIM discovery permissions and updates SchemaResourceTypeProvider.getAll() to hasDiscoveryEndpointPermission (query-users/query-groups), but leaves get(String id) on REALMS_RESOURCE_TYPE + VIEW. Schema-by-id remains inconsis",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 798,
      "batch": "n=791-800 (2026-07-23)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-1289",
      "introducing_pr": 1289,
      "fixing_pr": 4305,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "SingleDirectoryDbLedgerStorage.swapWriteCache clears hasFlushBeenTriggered before isFlushOngoing=true \u2192 concurrent double flush",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 799,
      "batch": "n=791-800 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-112026",
      "introducing_pr": 112026,
      "fixing_pr": 150789,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "StreamingHttpResultPublisher.ApacheClientBackpressure: pauseProducer vs shutdownProducer TOCTOU under ioLock leaves Apache producer suspended forever",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 800,
      "batch": "n=791-800 (2026-07-23)",
      "repo": "ebean-orm/ebean",
      "key": "ebean-3301",
      "introducing_pr": 3301,
      "fixing_pr": 3382,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "Bulk update clear of PersistenceContext (#3301/#3295) removes parent before OneToMany lazy load when batch overflows \u2192 empty collections. Fix putIfAbsent parents on many lazy load.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 801,
      "batch": "n=801-810 (2026-07-23)",
      "repo": "ebean-orm/ebean",
      "key": "ebean-3824",
      "introducing_pr": 3824,
      "fixing_pr": 3849,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "query.exists() emits select exists(...) invalid as scalar on SQL Server/Oracle; wrap with case-when (+ from dual).",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 802,
      "batch": "n=801-810 (2026-07-23)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-33326",
      "introducing_pr": 33326,
      "fixing_pr": 50098,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "After #33326 migrates FolderTheme.getResourceAsStream through ResourceLoader.getFileAsStream (normalize + startsWith jail), sibling getTemplate(String name) remains new File(themeDir, name) with no path-containment. ../ template names escap",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 803,
      "batch": "n=801-810 (2026-07-23)",
      "repo": "apache/cloudstack",
      "key": "cloudstack-12014",
      "introducing_pr": 12014,
      "fixing_pr": 13452,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#12014 always builds DataCenterDeployment with srcHost.clusterId for migration listing; previously storage-motion path used null clusterId to include other clusters. Fix #13452 restores null cluster when storage migration supported.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 804,
      "batch": "n=801-810 (2026-07-23)",
      "repo": "apache/pinot",
      "key": "pinot-17892",
      "introducing_pr": 17892,
      "fixing_pr": 18139,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#17892 ServerGrpcChannelBackoffResetHandler else-branch always treats non-INIT as CALLBACK and substring(pathChanged); FINALIZE has null pathChanged \u2192 NPE. Fix #18139 only handles Type.CALLBACK.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 805,
      "batch": "n=801-810 (2026-07-23)",
      "repo": "ebean-orm/ebean",
      "key": "ebean-3324",
      "introducing_pr": 3324,
      "fixing_pr": 3818,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "ON_CONFLICT_NOTHING parent insert can return 0 rows while cascade still inserts children \u2192 FK violation. Fix skips cascade when insert conflict-skipped.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 806,
      "batch": "n=801-810 (2026-07-23)",
      "repo": "apache/doris",
      "key": "doris-46879",
      "introducing_pr": 46879,
      "fixing_pr": 47409,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#46879 doDistribute early-returns when FE computes result in cloud mode without setting distributedPlans \u2192 NPE on getDistributedPlans for select 1. Fix #47409 uses notNeedBackend dummy backend path.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 807,
      "batch": "n=801-810 (2026-07-23)",
      "repo": "camunda/camunda",
      "key": "camunda-56690",
      "introducing_pr": 56690,
      "fixing_pr": 58110,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (security)",
      "defect": "#56690 migrates Group processors to PermissionsBehavior.isAuthorized. Siblings GroupUpdateProcessor/GroupRemoveEntityProcessor pass groupId; GroupAddEntityProcessor calls isAuthorized(command, GROUP, UPDATE) without record.getGroupId(), so ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 808,
      "batch": "n=801-810 (2026-07-23)",
      "repo": "apache/rocketmq",
      "key": "rocketmq-7500",
      "introducing_pr": 7500,
      "fixing_pr": 10517,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (performance)",
      "defect": "#7500 adds TransactionMetricsFlushService whose run loop only calls waitForRunning inside the interval-elapsed branch \u2014 busy-spins while waiting for flush interval. Fix always waitForRunning then persist if elapsed.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 809,
      "batch": "n=801-810 (2026-07-23)",
      "repo": "apache/pinot",
      "key": "pinot-11092",
      "introducing_pr": 11092,
      "fixing_pr": 18089,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.12 slice (campaign stays MISS)",
      "defect": "#11092 multi-strategy FUNNEL_COUNT extractors dereference null DictIdsWrapper when WHERE empties segment \u2192 server NPE. Fix #18089 returns empty bitmaps/sets for null wrapper.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 811,
      "batch": "n=811-820 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-154186",
      "introducing_pr": 154186,
      "fixing_pr": 154476,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#154186 wraps SearchExecutionContext in EsqlSearchExecutionContext without registering releaseQueryConstructionMemory \u2192 request breaker leak. Fix #154476 addReleasable at wrap site.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 812,
      "batch": "n=811-820 (2026-07-23)",
      "repo": "apache/tika",
      "key": "tika-2882",
      "introducing_pr": 2882,
      "fixing_pr": 2888,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "Interaction #2878 utf8Tolerated + #2882 mojibuster default \u2192 UTF-8 false positive on short Latin-1 probes. Fix #2888 STRUCTURAL only for LIKELY_UTF8.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 813,
      "batch": "n=811-820 (2026-07-23)",
      "repo": "apache/cxf",
      "key": "cxf-646",
      "introducing_pr": 646,
      "fixing_pr": 3297,
      "lane": "security",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "Dynamic Client Registration accepted client-requested OAuth scopes without allowlist validation (fromClientRegistrationToClient \u2192 setRegisteredScopes). #646 wires real update path through that unvalidated conversion. Fix #3297 adds validate",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 814,
      "batch": "n=811-820 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-145628",
      "introducing_pr": 145628,
      "fixing_pr": 154447,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#145628 stores primaryTerm in failedShardsCache but resolves term at cache-update time from current cluster state; term bump can stale-suppress recovery. Fix #154447 resolves term at failure time.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 815,
      "batch": "n=811-820 (2026-07-23)",
      "repo": "apache/hudi",
      "key": "hudi-17694",
      "introducing_pr": 17694,
      "fixing_pr": 19126,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#17694 enabled MAP/ARRAY nested col-stats on schema/Parquet paths; MOR log-append AvroRecordContext still RECORD-only and threw on MAP leaves during V2 stats collection.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 816,
      "batch": "n=811-820 (2026-07-23)",
      "repo": "camunda/camunda",
      "key": "camunda-53724",
      "introducing_pr": 53724,
      "fixing_pr": 57829,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#53724 priority job CF changes insert path; pre-8.10 job event appliers replay via new path \u2192 state divergence. Fix #57829 versions appliers for insert-path events.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 817,
      "batch": "n=811-820 (2026-07-23)",
      "repo": "camunda/camunda",
      "key": "camunda-56526",
      "introducing_pr": 56526,
      "fixing_pr": 58415,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#56526 routes post-importer-queue writes by partitionId; archiver treated any processedCount != expectedCount as hard failure. Legitimate overcounts after the routing change throw and break archiving. Fix only fails on undercount.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 818,
      "batch": "n=811-820 (2026-07-23)",
      "repo": "apache/kafka",
      "key": "kafka-13267",
      "introducing_pr": 13267,
      "fixing_pr": 22204,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "RPCProducerIdManager: race between maybeRequestNextBlock and response-handler backoff clear \u2192 premature AllocateProducerIds retry",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 819,
      "batch": "n=811-820 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-79279",
      "introducing_pr": 79279,
      "fixing_pr": 148179,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (security)",
      "defect": "#79279 lands ModifyDataStreams admin API (add/remove backing indices). Authorization treated it as a generic index action and did not validate both data-stream and backing-index privileges. Fix #148179 adds authorizeModifyDataStreams dual p",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 820,
      "batch": "n=811-820 (2026-07-23)",
      "repo": "linkedin/venice",
      "key": "venice-2821",
      "introducing_pr": 2821,
      "fixing_pr": 2838,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#2821 adds VPJ external-storage dual-write with a single global storageMode broadcast to all executors \u2014 per-region DUAL_WRITE vs INTERNAL cannot be expressed.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 821,
      "batch": "n=821-830 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-120302",
      "introducing_pr": 120302,
      "fixing_pr": 128687,
      "lane": "performance",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "DATE_TRUNC arbitrary-interval support threaded a multiplier into every DateTimeUnit.roundFloor path, including units that always use multiplier==1 on the date-histogram critical path. Fix specializes fixed-unit floor paths to remove general",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 822,
      "batch": "n=821-830 (2026-07-23)",
      "repo": "apache/activemq-artemis",
      "key": "artemis-4724",
      "introducing_pr": 4724,
      "fixing_pr": 6480,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (concurrency)",
      "defect": "MQTTStateManager.getSessionState ConcurrentHashMap containsKey+get/put during link-steal \u2192 NPE",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 823,
      "batch": "n=821-830 (2026-07-23)",
      "repo": "apache/pekko",
      "key": "pekko-1990",
      "introducing_pr": 1990,
      "fixing_pr": 3007,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (concurrency)",
      "defect": "#1990 migrates AbstractNodeQueue to VarHandle but uses plain VarHandle.get for tail/next reads \u2014 no acquire ordering, pollNode can spin forever on JDK 25. Fix uses getAcquire/getVolatile.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 824,
      "batch": "n=821-830 (2026-07-23)",
      "repo": "apache/struts",
      "key": "struts-1765",
      "introducing_pr": 1765,
      "fixing_pr": 1777,
      "lane": "security",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#1765 adds WebJars static serving through DefaultStaticContentLoader/DefaultWebJarUrlProvider without canonicalisePath (and still double-decodes servlet paths). Fix #1777 adds Validator.canonicalisePath (reject .. escape), drops redundant U",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 825,
      "batch": "n=821-830 (2026-07-23)",
      "repo": "apache/pulsar",
      "key": "pulsar-9973",
      "introducing_pr": 9973,
      "fixing_pr": 24639,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (concurrency)",
      "defect": "MetadataStoreCacheLoader concurrent ChildrenChanged updates race availableBrokers list",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 826,
      "batch": "n=821-830 (2026-07-23)",
      "repo": "netty/netty",
      "key": "netty-10331",
      "introducing_pr": 10331,
      "fixing_pr": 10528,
      "lane": "performance",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "Native SSLEngine session-cache support (#10331) landed client/server external session-cache wiring. Maintainers fully reverted it after measuring a large TLS performance regression.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 827,
      "batch": "n=821-830 (2026-07-23)",
      "repo": "micronaut-projects/micronaut-core",
      "key": "micronaut-12636",
      "introducing_pr": 12636,
      "fixing_pr": 12729,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#12636 Introspected.Property + @JsonProperty mapping treats Groovy property fields as field accessors when not accessible. Fix #12729 requires accessibility; fixes Groovy package-private visibility.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 828,
      "batch": "n=821-830 (2026-07-23)",
      "repo": "alibaba/nacos",
      "key": "nacos-3809",
      "introducing_pr": 3809,
      "fixing_pr": 14928,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "ClientServiceIndexesManager.removeSubscriberIndexes: non-atomic remove+isEmpty+map.remove loses concurrent subscriber adds",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 829,
      "batch": "n=821-830 (2026-07-23)",
      "repo": "apache/pinot",
      "key": "pinot-10322",
      "introducing_pr": 10322,
      "fixing_pr": 10432,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "GrpcSendingMailbox: cancel races first onNext on unstarted gRPC stream after mailbox leak/cancel rework",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 830,
      "batch": "n=821-830 (2026-07-23)",
      "repo": "FasterXML/jackson-databind",
      "key": "jackson-4988",
      "introducing_pr": 4988,
      "fixing_pr": 5844,
      "lane": "correctness",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#4988 changes _constructStdTypeResolverBuilder signature; xml format module override breaks. Fix #5844 restores deprecated overload.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 831,
      "batch": "n=831-840 (2026-07-23)",
      "repo": "apache/hudi",
      "key": "hudi-11084",
      "introducing_pr": 11084,
      "fixing_pr": 12325,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (performance)",
      "defect": "#11084 (HUDI-7660) rewrites RowDataKeyGen to cut excess StringBuilder/deleteCharAt work but introduces String.format(HIVE_PARTITION_TEMPLATE, partField, partValue) for hive-style partition segments. On the Flink write hot path that is ~8.7\u00d7",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 832,
      "batch": "n=831-840 (2026-07-23)",
      "repo": "crate/crate",
      "key": "crate-17946",
      "introducing_pr": 17946,
      "fixing_pr": 19449,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#17946 parallelized stale-index deletion and only schedules next cleanup on successful delete; a failed delete leaves GroupedActionListener unfinished \u2192 DROP/CREATE SNAPSHOT hang. Fix continues deletions on failure.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 833,
      "batch": "n=831-840 (2026-07-23)",
      "repo": "ebean-orm/ebean",
      "key": "ebean-2646",
      "introducing_pr": 2646,
      "fixing_pr": 2666,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#2646 made DeployInheritInfo.compareTo sort by discriminatorStringValue for deterministic DDL. Children with null discriminator (common for abstract/root types) hit NPE / TreeSet breakage in addChild. Fix sorts by type name instead.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 834,
      "batch": "n=831-840 (2026-07-23)",
      "repo": "apache/rocketmq",
      "key": "rocketmq-3619",
      "introducing_pr": 3619,
      "fixing_pr": 3632,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.12 slice (campaign stays MISS)",
      "defect": "#3619 rewrote buildStatsKey to pre-size StringBuilder with topic.length()+group.length(). When topic or group is null (msg-back path), length() NPEs. Fix null-guards before sizing.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 835,
      "batch": "n=831-840 (2026-07-23)",
      "repo": "apache/pulsar",
      "key": "pulsar-13023",
      "introducing_pr": 13023,
      "fixing_pr": 15162,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#13023 forces triggerListener onto internalPinnedExecutor (and makes messageReceived call tryTriggerListener on the internal path) to fix message-order races with listeners. Per-message path becomes external \u2192 internal \u2192 external executor h",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 836,
      "batch": "n=831-840 (2026-07-23)",
      "repo": "apache/logging-log4j2",
      "key": "log4j2-315",
      "introducing_pr": 315,
      "fixing_pr": 4125,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#315 added KafkaAppender retryCount. On successful retry the loop break's out of the while but still falls through to error(), so every recovered transient Kafka failure is reported as an error. Fix #4125 replaces break with return.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 837,
      "batch": "n=831-840 (2026-07-23)",
      "repo": "apache/struts",
      "key": "struts-1773",
      "introducing_pr": 1773,
      "fixing_pr": 1784,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#1773 adds accepted-name/ParameterNameAware filtering to JSONInterceptor but evaluates allowlist checks at every JSON tree node before recurse. Leaf-targeted patterns fail on intermediate nodes and drop whole subtrees; array elements judged",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 838,
      "batch": "n=831-840 (2026-07-23)",
      "repo": "micro-manager/micro-manager",
      "key": "micro-manager-2377",
      "introducing_pr": 2377,
      "fixing_pr": 2378,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#2377 replaced JComboBox ActionListeners with PopupMenuListener snapshot logic to stop spurious commits, but the snapshot approach fails when selecting the first item while current value is not in the allowed list (snapshot null \u2192 change ne",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 839,
      "batch": "n=831-840 (2026-07-23)",
      "repo": "apache/helix",
      "key": "helix-2604",
      "introducing_pr": 2604,
      "fixing_pr": 2669,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (concurrency)",
      "defect": "filterOutEvacuatingInstances does instanceConfigMap.get(instance).getInstanceOperation() without null-guard; concurrent instance add/remove can map instance\u2192null config while ZNode remains \u2192 NPE",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 840,
      "batch": "n=831-840 (2026-07-23)",
      "repo": "ebean-orm/ebean",
      "key": "ebean-3759",
      "introducing_pr": 3759,
      "fixing_pr": 3847,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#3759 made DatabaseFactory.create() with register(true) return the already-registered Database under the same name. Two independently created configs (different DataSource URLs, same logical name) silently shared state. Fix #3847 throws Ill",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 841,
      "batch": "n=841-850 (2026-07-23)",
      "repo": "powsybl/powsybl-open-loadflow",
      "key": "powsybl-olf-1394",
      "introducing_pr": 1394,
      "fixing_pr": 1461,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#1394 changed equation derivative term sort from variable.getRow() to variable.hashCode(). Hash order differs across runs \u2192 non-reproducible sparse-matrix AC load-flow drift. Fix sorts by stable variable comparator.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 842,
      "batch": "n=841-850 (2026-07-23)",
      "repo": "Jikoo/OpenInv",
      "key": "openinv-311",
      "introducing_pr": 311,
      "fixing_pr": 414,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#311 extracted per-inventory match into SearchHelper.findMatch but left break in the outer player loop of SearchInvCommand. First matching player ends the entire scan.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 843,
      "batch": "n=841-850 (2026-07-23)",
      "repo": "apache/pekko",
      "key": "pekko-3030",
      "introducing_pr": 3030,
      "fixing_pr": 3373,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (performance)",
      "defect": "#3030's releaseStage() nulls connection refs during finalization and sets a pendingFinalization flag that makes afterStageHasRun scan all initializedStages on every dispatch \u2014 O(n) per event (O(n\u00b2) at scale). Fix replaces Boolean flag with ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 844,
      "batch": "n=841-850 (2026-07-23)",
      "repo": "micronaut-projects/micronaut-core",
      "key": "micronaut-12632",
      "introducing_pr": 12632,
      "fixing_pr": 12740,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#12632 made RequestBeanAnnotationBinder skip instantiation whenever no request values bound (if (!bindingFound) return empty). Non-null @RequestBean parameters with only-nullable fields stayed unbound instead of receiving an empty bean. Fix",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 845,
      "batch": "n=841-850 (2026-07-23)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-4041",
      "introducing_pr": 4041,
      "fixing_pr": 22376,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#4041 made ReplicationCheckpoint Comparable with return isAheadOf(other) ? -1 : 1 \u2014 equal checkpoints never return 0, breaking Comparator contract. Large PSA TimSort throws IllegalArgumentException. Fix returns 0 when neither is ahead.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 846,
      "batch": "n=841-850 (2026-07-23)",
      "repo": "apache/helix",
      "key": "helix-2180",
      "introducing_pr": 2180,
      "fixing_pr": 2776,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#2180 reused the builder-supplied ZkClient in BestPossibleExternalViewVerifier. Callers often configure ZNRecordSerializer; assignment metadata store requires ByteArraySerializer \u2192 verifier cannot read best-possible state and silently retur",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 847,
      "batch": "n=841-850 (2026-07-23)",
      "repo": "apache/paimon",
      "key": "paimon-6354",
      "introducing_pr": 6354,
      "fixing_pr": 8305,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#6354 adds parent_id to Iceberg snapshots but hardcodes null in createMetadataWithoutBase; after metadata expiry non-first snapshots get null parent_id and break lineage.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 848,
      "batch": "n=841-850 (2026-07-23)",
      "repo": "apache/pinot",
      "key": "pinot-16812",
      "introducing_pr": 16812,
      "fixing_pr": 18850,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "getValidDocIdsType overrides user SNAPSHOT to SNAPSHOT_WITH_DELETE when delete enabled; compaction drops tombstones before deletedKeysTTL, allowing resurrection of deleted keys on metadata rebuild.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 849,
      "batch": "n=841-850 (2026-07-23)",
      "repo": "apache/pulsar",
      "key": "pulsar-23236",
      "introducing_pr": 23236,
      "fixing_pr": 25732,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#23236 deserializes ShadowReplicator source entries with empty payload while still retain()ing headersAndPayload before send. Empty-payload path does not own the buffer \u2192 Netty LEAK after Entry release. Fix removes retain.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 850,
      "batch": "n=841-850 (2026-07-23)",
      "repo": "crate/crate",
      "key": "crate-17943",
      "introducing_pr": 17943,
      "fixing_pr": 19326,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (performance)",
      "defect": "#17943 re-implemented bulk BackoffPolicy on streams and changed aggressiveness of retries for multi-shard INSERT INTO VALUES. Bulk inserts hitting many shards became less aggressive than 5.10 \u2192 longer wall time. Fix restores 5.10 backoff be",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 851,
      "batch": "n=851-860 (2026-07-23)",
      "repo": "grpc/grpc-java",
      "key": "grpc-java-7696",
      "introducing_pr": 7696,
      "fixing_pr": 7778,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#7696 xDS CDS parsing for EDS clusters only added edsServiceName to edsResources when non-empty. When service_name is empty, EDS resource name defaults to cluster name but was never tracked \u2192 deleting/updating CDS left orphan EDS watches. F",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 852,
      "batch": "n=851-860 (2026-07-23)",
      "repo": "ebean-orm/ebean",
      "key": "ebean-2309",
      "introducing_pr": 2309,
      "fixing_pr": 2316,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "shipped v0.38.12 slice (campaign stays MISS)",
      "defect": "#2309's ScalarTypeJsonList/Set.formatValue called value.isEmpty() without null check. Setting a JSON List/Set property to null then persisting NPEs. Fix removes the isEmpty short-circuit and lets EJson.write handle null/empty.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 853,
      "batch": "n=851-860 (2026-07-23)",
      "repo": "apache/beam",
      "key": "beam-31128",
      "introducing_pr": 31128,
      "fixing_pr": 31685,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#31128 added queryTempProject to BigQueryIO TypedRead config translation and always read configRow.getString(\"query_temp_project\") on upgrade. Upgrading transforms from Beam <2.57 lack the field \u2192 NPE/bad upgrade. Fix gates the field read o",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 854,
      "batch": "n=851-860 (2026-07-23)",
      "repo": "apache/pinot",
      "key": "pinot-10000",
      "introducing_pr": 10000,
      "fixing_pr": 10356,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (design)",
      "defect": "#10000 adds AggregationFunctionUtils.buildFilteredAggTransformPairs for filtered aggs + GROUP BY. The loop treats a pair as filtered when inputPair.getLeft() != null (AggregationFunction) instead of when getRight() (FilterContext) is non-nu",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 855,
      "batch": "n=851-860 (2026-07-23)",
      "repo": "apache/logging-log4j2",
      "key": "log4j2-3199",
      "introducing_pr": 3199,
      "fixing_pr": 3418,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#3199 introduces InternalLoggerRegistry.computeIfAbsent that takes the write lock and then calls loggerSupplier.apply(...) (full Logger construction, property lookups, user code) while holding the lock \u2014 serializing logger creation and risk",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 856,
      "batch": "n=851-860 (2026-07-23)",
      "repo": "resilience4j/resilience4j",
      "key": "resilience4j-672",
      "introducing_pr": 672,
      "fixing_pr": 824,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#672 added weighted permits to AtomicRateLimiter; nanosToWaitForPermission used truncating integer division for fullCyclesToWait, under-waiting when remaining permits don't divide evenly \u2192 acquire times out or returns early. Fix uses divCei",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 857,
      "batch": "n=851-860 (2026-07-23)",
      "repo": "ebean-orm/ebean",
      "key": "ebean-2617",
      "introducing_pr": 2617,
      "fixing_pr": 2763,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#2617 added JsonContext.toJson(bean, targetBean) but property jsonRead paths still used setValue instead of setValueIntercept when a target bean is supplied, so interceptors/dirty tracking miss updates into the provided instance.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 858,
      "batch": "n=851-860 (2026-07-23)",
      "repo": "apache/beam",
      "key": "beam-36631",
      "introducing_pr": 36631,
      "fixing_pr": 38894,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#36631 abort-on-close path throws ReadLoopAbortedException (extends InterruptedException) then re-sets the thread interrupt flag after close. Workers treat the sticky interrupt as a real thread death and fail the read loop permanently. Fix ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 859,
      "batch": "n=851-860 (2026-07-23)",
      "repo": "powsybl/powsybl-core",
      "key": "powsybl-core-2648",
      "introducing_pr": 2648,
      "fixing_pr": 2733,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#2648 made 3-winding transformer ratedS optional in CGMES import but InterpretedWinding.ratedS stayed primitive double, so missing ratedS became 0.0 and broke optional semantics. Fix uses Double boxed type.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 860,
      "batch": "n=851-860 (2026-07-23)",
      "repo": "linkedin/venice",
      "key": "venice-2704",
      "introducing_pr": 2704,
      "fixing_pr": 2788,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#2704's createStoreMetadataFetcher hard-wires D2TransportClient(clientConfig.getD2Client(), d2ServiceName). HTTP/HTTPS thin-client configs without D2 NPE or cannot reach /stores. Fix constructs RouterBasedStoreMetadataFetcher from ClientCon",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 861,
      "batch": "n=861-870 (2026-07-23)",
      "repo": "debezium/debezium",
      "key": "debezium-6222",
      "introducing_pr": 6222,
      "fixing_pr": 6313,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (performance)",
      "defect": "#6222 centralized sensitive-data logging through Loggings helpers used on hot enqueue/convert paths. The wrapper overhead regressed pipeline throughput. Fix inlines maybeRedactSensitiveData static import and lighter trace formatting on hot ",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 862,
      "batch": "n=861-870 (2026-07-23)",
      "repo": "fabric8io/kubernetes-client",
      "key": "k8s-client-4365",
      "introducing_pr": 4365,
      "fixing_pr": 4643,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#4365 added Watcher exception-handler support and reworked WatchConnectionManager/WatcherWebSocketListener readiness. websocketFuture was set in a timing window that could miss the initial watch event (race between ready flag and first mess",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 863,
      "batch": "n=861-870 (2026-07-23)",
      "repo": "alibaba/nacos",
      "key": "nacos-9820",
      "introducing_pr": 9820,
      "fixing_pr": 14988,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (concurrency)",
      "defect": "ConfigChangeConfigs.configPluginProperties: non-volatile Map reassigned on ServerConfigChangeEvent + containsKey/get TOCTOU so request threads can miss the new map or get null mid-refresh",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 864,
      "batch": "n=861-870 (2026-07-23)",
      "repo": "apache/paimon",
      "key": "paimon-3739",
      "introducing_pr": 3739,
      "fixing_pr": 8788,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "createWithDeleteManifestFileMetas keeps entry.snapshotId() on DELETED entries (add snapshot) instead of deleting snapshot; Iceberg incremental scans drop deletes.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 865,
      "batch": "n=861-870 (2026-07-23)",
      "repo": "ebean-orm/ebean",
      "key": "ebean-2411",
      "introducing_pr": 2411,
      "fixing_pr": 2437,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (data)",
      "defect": "#2411 introduced weak-reference BeanRef persistence context for streaming queries. When a key is put again, the old BeanRef is replaced in the map but still lives on the ReferenceQueue; expunge then removes the new mapping for that key \u2192 su",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 866,
      "batch": "n=861-870 (2026-07-23)",
      "repo": "apache/druid",
      "key": "druid-19571",
      "introducing_pr": 19571,
      "fixing_pr": 19615,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#19571 adds DimensionValueSetShardSpec for streaming segments; upgrade path in IndexerSQLMetadataStorageCoordinator stamps pending NumberedShardSpec and drops the value-set shard spec, making upgraded segments unprunable.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 867,
      "batch": "n=861-870 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-149063",
      "introducing_pr": 149063,
      "fixing_pr": 154675,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#149063 (No subobjects for columnar modes) made strict columnar modes throw MapperParsingException on any explicit subobjects value. Fleet packages with subobjects:false (same as forced-flat default) broke. Fix accepts subobjects:false as n",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 868,
      "batch": "n=861-870 (2026-07-23)",
      "repo": "linkedin/venice",
      "key": "venice-2444",
      "introducing_pr": 2444,
      "fixing_pr": 2800,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#2444 adds blobDbEnabled getters/setters but omits cloneVersion copy; every RMW via ZK clone wipes version-level BlobDB flag to NOT_SPECIFIED.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 869,
      "batch": "n=861-870 (2026-07-23)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-30966",
      "introducing_pr": 30966,
      "fixing_pr": 50182,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (security)",
      "defect": "#30966 SD-JWT verification: validateViaRecursiveDisclosing inserts each Disclosure with currentObjectNode.set(claimName, value) without checking the name is free, so a Disclosure can silently overwrite a plaintext claim or collide with anot",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 870,
      "batch": "n=861-870 (2026-07-23)",
      "repo": "micronaut-projects/micronaut-core",
      "key": "micronaut-10402",
      "introducing_pr": 10402,
      "fixing_pr": 12753,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (security)",
      "defect": "#10402 lands pure-Java DefaultServerCookieEncoder/DefaultClientCookieEncoder that concatenate cookie name/value/path/domain with no character validation. Values containing ';' inject extra Set-Cookie attributes; CR/LF split headers (CWE-113",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 871,
      "batch": "n=871-880 (2026-07-23)",
      "repo": "ClickHouse/clickhouse-java",
      "key": "clickhouse-2579",
      "introducing_pr": 2579,
      "fixing_pr": 2629,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#2579's JDBC-v2 parser work added DriverProperties.SQL_PARSER allowed values via List.of(...). List.of is Java 9+; on Java 8 the enum <clinit> throws NoSuchMethodError. Fix switches to Arrays.asList.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 872,
      "batch": "n=871-880 (2026-07-23)",
      "repo": "apache/paimon",
      "key": "paimon-3731",
      "introducing_pr": 3731,
      "fixing_pr": 5209,
      "lane": "data",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "IcebergCommitCallback not wired into DropPartition's AbstractFileStore#newCommit(commitUser) empty-callback path; dropPartition does not sync durable Iceberg metadata.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 873,
      "batch": "n=871-880 (2026-07-23)",
      "repo": "apache/doris",
      "key": "doris-56423",
      "introducing_pr": 56423,
      "fixing_pr": 64412,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "#56423 adds baseViewsOneLevel on MTMVRelation without null-safe getter. Pre-feature MTMVs load null \u2192 getBaseViewsOneLevel().stream() NPE on information_schema.view_dependency. Fix null-guards getter.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 874,
      "batch": "n=871-880 (2026-07-23)",
      "repo": "alibaba/nacos",
      "key": "nacos-13001",
      "introducing_pr": 13001,
      "fixing_pr": 15002,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (concurrency)",
      "defect": "NacosServerAuthConfig.authPluginProperties: non-volatile map reassignment from refresh + containsKey/get TOCTOU on auth hot path (same dual bug as ConfigChangeConfigs)",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 875,
      "batch": "n=871-880 (2026-07-23)",
      "repo": "OpenIdentityPlatform/OpenDJ",
      "key": "opendj-7e3a759031",
      "introducing_pr": "7e3a75903159",
      "fixing_pr": 651,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "CVE-2026-46495 hardening commit set both jmx.remote.rmi.server.credential.types and jmx.remote.rmi.server.credentials.filter.pattern on the JMX env map. JDK forbids both; RMIJRMPServerImpl constructor fails and JMX RMI connector never start",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 876,
      "batch": "n=871-880 (2026-07-23)",
      "repo": "apache/cxf",
      "key": "cxf-3126",
      "introducing_pr": 3126,
      "fixing_pr": 3294,
      "lane": "security",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#3126 hardens JwtAccessTokenValidator with issuer + JwtUtils.validateTokenClaims (expiry/nbf/audience) but still accepts non-access-token JWTs when typ/token_use are present and wrong. Fix #3294 adds validateTokenType requiring typ=at+jwt a",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 877,
      "batch": "n=871-880 (2026-07-23)",
      "repo": "opensearch-project/OpenSearch",
      "key": "os-22021",
      "introducing_pr": 22021,
      "fixing_pr": 22148,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "Refresh flushQueue: if writer.flush() throws, writer is not closed \u2192 NativeFSLockFactory LOCK_HELD leak / LockObtainFailedException. #22021 fixed CompositeWriter constructor/close but missed this path.",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 878,
      "batch": "n=871-880 (2026-07-23)",
      "repo": "apache/pekko",
      "key": "pekko-3035",
      "introducing_pr": 3035,
      "fixing_pr": 3116,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "no target match / adjacent / empty",
      "defect": "#3035 moved LazyDispatch scheduling state to a VarHandle-backed field but instance access modes were not consistently getVolatile/setVolatile, risking lost lazy-dispatch state updates across threads. Fix uses explicit getVolatile/setVolatil",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 879,
      "batch": "n=871-880 (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-115667",
      "introducing_pr": 115667,
      "fixing_pr": 120617,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (security)",
      "defect": "#115667 adds index-mode LOOKUP loading via AbstractLookupService: index privilege check then threadContext.stashWithOrigin(ClientHelper.ENRICH_ORIGIN) for the shard request. Index-level authz covered; document-level security not applied und",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 880,
      "batch": "n=871-880 (2026-07-23)",
      "repo": "vert-x3/vertx-ignite",
      "key": "vertx-ignite-158",
      "introducing_pr": 158,
      "fixing_pr": 165,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (concurrency)",
      "defect": "#158 switched subscription-map updates to Ignite map.invoke for linear-time search, but registration values were not Binarylizable under the invoke path. Binary serialization then blocked an internal Ignite thread (cluster hang / event star",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 881,
      "batch": "n=881-890 post-restructure Grok smoke (2026-07-23)",
      "repo": "ebean-orm/ebean",
      "key": "ebean-2996",
      "introducing_pr": 2996,
      "fixing_pr": 3006,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "RawSql + default select: after #2996, DefaultServer still setDefaultSelectClause for LAZY *ToOne so RawSql rewrote SELECT to camelCase property names not DB columns \u2192 SQLException",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 882,
      "batch": "n=881-890 post-restructure Grok smoke (2026-07-23)",
      "repo": "ebean-orm/ebean",
      "key": "ebean-2978",
      "introducing_pr": 2978,
      "fixing_pr": 3014,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "CallStack(List<StackFrame>) hashes StackFrame.hashCode() which is identity-based \u2192 unstable AutoTune origin keys",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 883,
      "batch": "n=881-890 post-restructure Grok smoke (2026-07-23)",
      "repo": "testcontainers/testcontainers-java",
      "key": "testcontainers-7714",
      "introducing_pr": 7714,
      "fixing_pr": 7820,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "GenericContainer.setImage only updates ContainerDef; this.image stale so create still uses old image",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 884,
      "batch": "n=881-890 post-restructure Grok smoke (2026-07-23)",
      "repo": "apache/kafka",
      "key": "kafka-22493",
      "introducing_pr": 22493,
      "fixing_pr": 22529,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent AllBrokers retry; close race empty",
      "defect": "Stale-leader recovery re-enqueues via runnable during AdminClient.close grace \u2192 rejected instead of staying pending until deadline",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 885,
      "batch": "n=881-890 post-restructure Grok smoke (2026-07-23)",
      "repo": "apache/amoro",
      "key": "amoro-4182",
      "introducing_pr": 4182,
      "fixing_pr": 4185,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "empty trio \u2014 treated as Iceberg 1.7 fix",
      "defect": "ops.current\u2192refresh made createTable post-create commit race background tableExplorerScheduler \u2192 dual CommitFailedException",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 886,
      "batch": "n=881-890 post-restructure Grok smoke (2026-07-23)",
      "repo": "FasterXML/jackson-databind",
      "key": "jackson-3724",
      "introducing_pr": 3724,
      "fixing_pr": 5974,
      "lane": "security",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent dual-path ignore; not naming-strategy CVE",
      "defect": "Record @JsonIgnore recorded under pre-rename name; PropertyNamingStrategy rename leaves ignore set stale so renamed key binds (CVE-2026-59888)",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 887,
      "batch": "n=881-890 post-restructure Grok smoke (2026-07-23)",
      "repo": "apache/paimon",
      "key": "paimon-5751",
      "introducing_pr": 5751,
      "fixing_pr": 8783,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (data)",
      "defect": "FileRewriteCompactTask never attaches CompactDeletionFile after DV rewrite \u2014 orphan DV index metadata",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 888,
      "batch": "n=881-890 post-restructure Grok smoke (2026-07-23)",
      "repo": "ebean-orm/ebean",
      "key": "ebean-3155",
      "introducing_pr": 3155,
      "fixing_pr": 3223,
      "lane": "data",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent IdBinder residual; not Formula match",
      "defect": "IdClass name-match treated @Formula properties as imported matches \u2192 INSERT with formula placeholders e.g. ${}meta_key",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 889,
      "batch": "n=881-890 post-restructure Grok smoke (2026-07-23)",
      "repo": "elastic/elasticsearch",
      "key": "es-94564",
      "introducing_pr": 94564,
      "fixing_pr": 120133,
      "lane": "performance",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "adjacent unconditional scoring; not two-phase advance",
      "defect": "MatchedQueriesPhase Scorer.iterator().advance walks expensive two-phase second phase (e.g. geo) \u2192 multi-hour hang; fix advances approximation + twoPhase.matches()",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 890,
      "batch": "n=881-890 post-restructure Grok smoke (2026-07-23)",
      "repo": "apache/pulsar",
      "key": "pulsar-21081",
      "introducing_pr": 21081,
      "fixing_pr": 21647,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (performance)",
      "defect": "phaseTwoLoop skip arm for messageId<=lastCompacted never m.close() \u2192 RawMessage/ByteBuf leak on reconnect",
      "finder_model": "Grok 4.5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 891,
      "batch": "n=891-900 Opus 5 rate decade (2026-07-25)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-30620",
      "introducing_pr": 30620,
      "fixing_pr": 30709,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "BuildTimeConfigurationReader.ReadResult.run() drops the `continue` after each pattern-map match but reuses a single `Container matched` local, reassigning it per map. The terminal `if (matched == null) unknownBuildProperties.add(propertyNam",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 892,
      "batch": "n=891-900 Opus 5 rate decade (2026-07-25)",
      "repo": "apache/kafka",
      "key": "kafka-12366",
      "introducing_pr": 12366,
      "fixing_pr": 13723,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "MirrorConnectorConfig.sourceConsumerConfig(Map) was rewritten from originalsWithPrefix(SOURCE_CLUSTER_PREFIX) to Utils.entriesWithPrefix(props, SOURCE_PREFIX). SOURCE_PREFIX is \"source.\" but source-cluster client settings live under SOURCE_",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 893,
      "batch": "n=891-900 Opus 5 rate decade (2026-07-25)",
      "repo": "apache/iceberg",
      "key": "iceberg-10433",
      "introducing_pr": 10433,
      "fixing_pr": 11335,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "S3InputStream's new Failsafe RetryPolicy hooks the stream re-open on .onFailure(failure -> openStream(true)). Failsafe's onFailure fires only after the whole policy has exhausted every attempt, so the stream is never reopened BETWEEN retrie",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 894,
      "batch": "n=891-900 Opus 5 rate decade (2026-07-25)",
      "repo": "apache/flink",
      "key": "flink-25130",
      "introducing_pr": 25130,
      "fixing_pr": 25569,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "SplitFetcherManager.close(long) gained a drain task whose loop body is elementsQueue.getAvailabilityFuture().thenRun(...). thenRun registers a callback and returns immediately, so nothing in the loop blocks: it spins at full speed for the w",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 895,
      "batch": "n=891-900 Opus 5 rate decade (2026-07-25)",
      "repo": "apache/solr",
      "key": "solr-1827",
      "introducing_pr": 1827,
      "fixing_pr": 2045,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "RequestUtil.processParams' JSON \"query\" branch unconditionally does newMap.put(QueryParsing.DEFTYPE, {\"lucene\"}), forcing defType=lucene for every JSON query value. That is only correct when the value is a JSON structure; when query is a pl",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 896,
      "batch": "n=891-900 Opus 5 rate decade (2026-07-25)",
      "repo": "apache/ozone",
      "key": "ozone-8557",
      "introducing_pr": 8557,
      "fixing_pr": 10850,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "S3LifecycleConfiguration.convertFromOzoneExpiration does `if (ozoneExpiration.getDays() > 0)` on a boxed Integer that is null for date-based expiration rules (a rule has either Date or Days), so a plain GET of a date-based bucket lifecycle ",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 897,
      "batch": "n=891-900 Opus 5 rate decade (2026-07-25)",
      "repo": "camunda/camunda",
      "key": "camunda-35742",
      "introducing_pr": 35742,
      "fixing_pr": 58075,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (data)",
      "defect": "The ES 8.16.6 Java client migration replaced the exact JsonData.of(long) range bound in AbstractZeebeRecordFetcherES.buildPositionQuery/buildSequenceQuery with .gt(page.getPosition().doubleValue()). Zeebe sequences are partitionId << 51 | c",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 898,
      "batch": "n=891-900 Opus 5 rate decade (2026-07-25)",
      "repo": "trinodb/trino",
      "key": "trino-13757",
      "introducing_pr": 13757,
      "fixing_pr": 14094,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (performance)",
      "defect": "ParquetReader's `private final long[] maxBytesPerCell` became a Map<Integer,Long> initialised empty, and the array store `maxBytesPerCell[fieldId] = bytesPerCell;` became `maxBytesPerCell.replace(fieldId, bytesPerCell);`. Map.replace is a n",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 899,
      "batch": "n=891-900 Opus 5 rate decade (2026-07-25)",
      "repo": "trinodb/trino",
      "key": "trino-12968",
      "introducing_pr": 12968,
      "fixing_pr": 21445,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (performance)",
      "defect": "EventListenerManager.queryCompleted(QueryCompletedEvent) became queryCompleted(Function<Boolean, QueryCompletedEvent>) and applies the provider INSIDE the per-listener loop, so a QueryCompletedEvent that was constructed once per query \u2014 ser",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 900,
      "batch": "n=891-900 Opus 5 rate decade (2026-07-25)",
      "repo": "trinodb/trino",
      "key": "trino-15374",
      "introducing_pr": 15374,
      "fixing_pr": 15552,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (performance)",
      "defect": "PR #15374 added lib/trino-parquet/.../reader/ChunkedInputStream.java, whose whole purpose is reading a Parquet column chunk lazily in small steps; its constructor ends with an unconditional readNextChunk(). Constructing the stream therefore",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 901,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-33984",
      "introducing_pr": 33984,
      "fixing_pr": 41049,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "QuteProcessor#validateExpressions' new 'register all param declarations as targets of implicit value resolvers' block runs inside the per-template loop and does implicitClassToMembersUsed.put(type.name(), new HashSet<>()) unconditionally. T",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 902,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-43308",
      "introducing_pr": 43308,
      "fixing_pr": 44817,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (correctness)",
      "defect": "MethodsCandidate.isShared(EvalContext) loops over context.getParams() and does `if (param.isLiteral()) return false;`, which is inverted \u2014 the comment on the very next line of the same added hunk says \"Single method; all params are literals",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 903,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "spring-projects/spring-boot",
      "key": "springboot-b02f7ddea3",
      "introducing_pr": "b02f7ddea361",
      "fixing_pr": null,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed; validity SKIP-unresolvable (commit-sha fix)",
      "defect": "ServletContextInitializers#configureSessionCookie replaced the `.as(Object::toString)` mapping with `map.from(cookie::getPartitioned).to((partitioned) -> config.setAttribute(\"Partitioned\", \"\"))`. PropertyMapper.from(...).to(...) only filter",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "skipped",
      "attribution_verdict": "SKIP-unresolvable"
    },
    {
      "n": 904,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "spring-projects/spring-framework",
      "key": "springframework-41cd6879bd",
      "introducing_pr": "41cd6879bde4",
      "fixing_pr": null,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed; validity SKIP-unresolvable (commit-sha fix)",
      "defect": "MimeTypeUtils#parseMimeTypeInternal's quoted-pair fix changed `else if (ch == '\"')` to `else if (ch == '\"' && mimeType.charAt(nextIndex - 1) != '\\\\')`. nextIndex is the index of the character currently being scanned and is 0 on the first ch",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "skipped",
      "attribution_verdict": "SKIP-unresolvable"
    },
    {
      "n": 905,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "spring-projects/spring-framework",
      "key": "springframework-e58ba2c665",
      "introducing_pr": "e58ba2c66593",
      "fixing_pr": null,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed; validity SKIP-unresolvable (commit-sha fix)",
      "defect": "DefaultRestClient gained `isStreamingResult(Object result)` returning (result instanceof InputStream || result instanceof InputStreamResource), used to decide close=false on the response. It tests the OUTER returned object only, so retrieve",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "skipped",
      "attribution_verdict": "SKIP-unresolvable"
    },
    {
      "n": 906,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/pulsar",
      "key": "pulsar-11737",
      "introducing_pr": 11737,
      "fixing_pr": 12993,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "HIT quote-backed (concurrency)",
      "defect": "PR #11737 added `this.recycle();` inside OpAddEntry.failed(). OpAddEntry is a Netty Recycler-pooled object and failed() is reachable from two independent threads: the BookKeeper add-callback path and ManagedLedgerImpl.clearPendingAddEntries",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 907,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/bookkeeper",
      "key": "bookkeeper-2794",
      "introducing_pr": 2794,
      "fixing_pr": 3513,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "2-of-3; correctness cleared the blocking close",
      "defect": "PR #2794 added a private closeLedgerHandle() to LedgerOpenOp that calls the BLOCKING lh.close() (its own catch of InterruptedException makes the blocking contract obvious on the diff), and called it from inside three async metadata callback",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 908,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "mybatis/mybatis-3",
      "key": "mybatis-3349",
      "introducing_pr": 3349,
      "fixing_pr": 3375,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "2-of-3; design cleared it on the top-level joiner",
      "defect": "XMLScriptBuilder.parseDynamicTags added `if (data.trim().isEmpty()) { continue; }` before building a TextSqlNode, to cut heap from whitespace-only TEXT nodes. But whitespace-only text nodes are the only separator between adjacent dynamic SQ",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 909,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "mybatis/mybatis-3",
      "key": "mybatis-2804",
      "introducing_pr": 2804,
      "fixing_pr": 2841,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "3/3 on the shared-helper blast radius that forced the revert",
      "defect": "MapperBuilderAssistant.resolveResultJavaType changed constructor-arg type resolution from metaResultType.getSetterType(property) to getGetterType(property) to make @Arg work for records; because the helper is shared by every result mapping,",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 910,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/hudi",
      "key": "hudi-755",
      "introducing_pr": 755,
      "fixing_pr": 927,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "3/3 on copy-on-get losing the avro read schema",
      "defect": "SerializableConfiguration.get() returns `new Configuration(configuration)` \u2014 a fresh defensive copy per call \u2014 so callers that set the Avro write/read schema onto the meta-client Configuration write into a throwaway copy; AvroReadSupport.in",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 911,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/pulsar",
      "key": "pulsar-20337",
      "introducing_pr": 20337,
      "fixing_pr": 20369,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "3/3 sweep on the brokerMeta empty-path leak",
      "defect": "#20337 added brokerMeta = payload.readRetainedSlice(...) to RawBatchConverter.rebatchMessage. The extra reference is only handed off on the path where at least one message survives filtering (the CompositeByteBuf); when nothing is retained ",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 912,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "micronaut-projects/micronaut-core",
      "key": "micronaut-5306",
      "introducing_pr": 5306,
      "fixing_pr": 5467,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "3/3 on the shared static SafeConstructor; 2 under-rated MEDIUM",
      "defect": "The startup-performance refactor hoisted the SnakeYAML SafeConstructor into a `private static final` shared instance passed to every `new Yaml(...)` in YamlPropertySourceLoader. SafeConstructor/BaseConstructor carries per-parse mutable stat",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 913,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/kafka",
      "key": "kafka-16837",
      "introducing_pr": 16837,
      "fixing_pr": 17434,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "2-of-3; api-ops considered the timer and declined it",
      "defect": "KafkaRaftClient.pollFollowerAsVoter gained an else-if arm whose body is the only caller of state.resetUpdateVoterPeriod(currentTimeMs). When the update-voter period expired but the voter node does not need an update, control falls to the fi",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 914,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/iceberg",
      "key": "iceberg-11052",
      "introducing_pr": 11052,
      "fixing_pr": 11274,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "3/3 on the overrideConfiguration Consumer overload clobber",
      "defect": "S3FileIOProperties.applyRetryConfigurations(T builder) calls builder.overrideConfiguration(config -> config.retryPolicy(...)). The AWS SDK consumer form builds a FRESH ClientOverrideConfiguration rather than mutating, so applying retry conf",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 915,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/flink",
      "key": "flink-22928",
      "introducing_pr": 22928,
      "fixing_pr": 22977,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "3/3 on both halves + the compiled-plan serde gap",
      "defect": "DefaultCatalogTable gained a @Nullable Long snapshot field and a 5-arg constructor. Both copy() overloads carry it, but CatalogPropertiesUtil.serialize/deserializeCatalogTable and equals/hashCode were not updated \u2014 ResolvedCatalogTable, con",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 916,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "trinodb/trino",
      "key": "trino-9766",
      "introducing_pr": 9766,
      "fixing_pr": 10954,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "1-of-3; only the owning finder saw the per-request parser rebuild",
      "defect": "#9766 \"Update to latest JWT apis\" rewrote every Jwts.parser() call site to Jwts.parserBuilder().build(), including InternalAuthenticationManager.parseJwt which runs on every internal cluster HTTP request. parserBuilder() resolves its implem",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 917,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "trinodb/trino",
      "key": "trino-13178",
      "introducing_pr": 13178,
      "fixing_pr": 13415,
      "lane": "performance",
      "review_grade": "C",
      "result": "HIT",
      "severity_or_note": "1-of-3; owning finder sized the ~2.5-3x hash-memory regression",
      "defect": "#13178 added specialized hash-table/pages-index classes for the single-bigint-column join key path. The specialized layout retains substantially more memory per build-side row, so large TPC-DS joins blow the task memory limit (peak ~69GB ->",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 918,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/solr",
      "key": "solr-529",
      "introducing_pr": 529,
      "fixing_pr": 3259,
      "lane": "performance",
      "review_grade": "C",
      "result": "MISS",
      "severity_or_note": "correctness cleared the file as a faithful port; WEAK adjudication",
      "defect": "ValueSourceRangeFilter.ValueSourceRangeWeight.scorer \u2014 #529 rewrote the class onto ConstantScoreWeight and built `new ConstantScoreScorer(this, score(), scoreMode, scorer.iterator())`. ValueSourceScorer is a two-phase matcher; taking iterat",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 919,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "datahub-project/datahub",
      "key": "datahub-10932",
      "introducing_pr": 10932,
      "fixing_pr": 11309,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "2-of-3; design cleared the dual path",
      "defect": "escapeForwardSlash() dropped one escaping level in two files but left the consumer constant SearchQueryBuilder.STRUCTURED_QUERY_PREFIX = \"\\\\\\\\/q \" untouched, so structured /q queries stop being recognized and fall through to full-text searc",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "arms-sibling",
      "attribution_verdict": "WEAK-no-shared-file"
    },
    {
      "n": 920,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "quarkusio/quarkus",
      "key": "quarkus-34420",
      "introducing_pr": 34420,
      "fixing_pr": 35555,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "3/3 on both null arms incl. the Gizmo.equals operand order",
      "defect": "ValueResolverGenerator.java \u2014 \"use shared constants for booleans, enums and nulls\" added two return paths dereferencing the invocation result without a null check: boxed Boolean emits Boolean.booleanValue() on invokeRet; enum completeEnum e",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 921,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/kafka",
      "key": "kafka-13424",
      "introducing_pr": 13424,
      "fixing_pr": 13548,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "3/3 on the namespacedUrl typo the split diff hid",
      "defect": "KIP-875 split DistributedHerder's task-config publishing into publishConnectorTaskConfigs(...) and the extracted copy builds the leader forwarding URL with UriBuilder.fromUri(leaderUrl) instead of namespacedUrl(leaderUrl). Forwarded PUT /co",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 922,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/seatunnel",
      "key": "seatunnel-11127",
      "introducing_pr": 11127,
      "fixing_pr": 11165,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "3/3 on the enforcement regression; all 3 missed the URL-validator arm",
      "defect": "PR #11127 made FactoryUtil.createOptionalCatalog() enforce optionRule() during catalog creation. Fix PR #11165 '[Fix][API] Fix backward compatibility issue in CatalogFactory optionRule validation' records TWO resulting regressions for JDBC ",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 923,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "spring-projects/spring-framework",
      "key": "springframework-6e97587",
      "introducing_pr": "6e9758700a49",
      "fixing_pr": null,
      "lane": "correctness",
      "review_grade": "A",
      "result": "MISS",
      "severity_or_note": "api-ops named it in its attestation and triaged it away as LOW/NIT",
      "defect": "ServerSentEvent.java#BuilderImpl \u2014 the SSE hardening adds checkEvent(id)/checkEvent(event) where checkEvent dereferences content unguarded. Builder#id/#event accept @Nullable, so builder.id(null) now NPEs inside a reactive pipeline. gh-3663",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 924,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "mybatis/mybatis-3",
      "key": "mybatis-3247",
      "introducing_pr": 3247,
      "fixing_pr": 3334,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "3/3 on the narrowed java.sql.Date return type",
      "defect": "PR 3247 ('encapsulation code to method level for reuse') refactored DateOnlyTypeHandler, replacing three inlined bodies of getNullableResult(...) that each did `return new Date(sqlDate.getTime())` (a java.util.Date) with a newly extracted h",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 925,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/shardingsphere",
      "key": "shardingsphere-35520",
      "introducing_pr": 35520,
      "fixing_pr": 35527,
      "lane": "data",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "3/3 on the inlined parse binding to the param, not the field",
      "defect": "In ShardingSpherePreparedStatement's private constructor, #35520 replaced the helper call parseSQL(connection) \u2014 which parsed the FIELD this.sql (hint-stripped by SQLHintUtils.removeHint) \u2014 with an inlined ...getSQLParserEngine(databaseType",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 926,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/shardingsphere",
      "key": "shardingsphere-38411",
      "introducing_pr": 38411,
      "fixing_pr": 38455,
      "lane": "data",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "2-of-3; design cleared it as \"a clear improvement\"",
      "defect": "#38411 changed WithSegmentBinder.bind's third argument from an externalTableBinderContexts map to the statement's own tableBinderContexts, and updated the four DML binders to pass tableBinderContexts instead of a fresh LinkedHashMultimap.cr",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 927,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-40272",
      "introducing_pr": 40272,
      "fixing_pr": 40964,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "3/3 on the unguarded feature-dependent flow steps",
      "defect": "DefaultAuthenticationFlows.browserFlow() unconditionally appends two AuthenticationExecutionModel steps to the conditional-OTP subflow \u2014 webauthn-authenticator (priority 30) and auth-recovery-authn-code-form (priority 40) \u2014 with no check th",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 928,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-46062",
      "introducing_pr": 46062,
      "fixing_pr": 48835,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "3/3; WEAK adjudication (fix cites the issue, not the PR)",
      "defect": "The new OrganizationGroupMembershipMapper.resolveFromRequestedScopes(...) does `OrganizationScope scope = OrganizationScope.valueOfScope(session, rawScopes); return scope.resolveOrganizations(...)`. valueOfScope() returns null whenever the ",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 929,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "keycloak/keycloak",
      "key": "keycloak-29967",
      "introducing_pr": 29967,
      "fixing_pr": 33797,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "3/3 on the wrong instanceof receiver in the docker filter",
      "defect": "The DPoP epic added `.filter(mapper -> mapper instanceof DockerAuthV2AttributeMapper)` to DockerAuthV2Protocol.authenticated(...). The stream element is a Map.Entry<ProtocolMapperModel, ProtocolMapper>, not a ProtocolMapper \u2014 the neighbouri",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "skipped",
      "attribution_verdict": "SKIP-api-error"
    },
    {
      "n": 930,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "jenkinsci/jenkins",
      "key": "jenkins-7398",
      "introducing_pr": 7398,
      "fixing_pr": 10065,
      "lane": "security",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "1-of-3; security finder framed the narrowing as a BENEFIT",
      "defect": "PR #7398 rewrote ZipExtractionInstaller.DescriptorImpl.doCheckUrl from the protocol-agnostic ProxyConfiguration.open(new URL(value))/URLConnection path to ProxyConfiguration.newHttpClient() + newHttpRequestBuilder(uri). java.net.http.HttpRe",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 931,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/uniffle",
      "key": "uniffle-2735",
      "introducing_pr": 2735,
      "fixing_pr": 2737,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "2-of-3; correctness framed it as a leak, not the deadlock",
      "defect": "#2735 added an Optional<Semaphore> segmentPermits to DecompressionWorker to cap in-flight decompressed segments; the worker thread calls segmentPermits.get().acquire() before submitting a decompression task. In the same PR's new get(int bat",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-ADJACENT"
    },
    {
      "n": 932,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/gravitino",
      "key": "gravitino-8553",
      "introducing_pr": 8553,
      "fixing_pr": 9086,
      "lane": "concurrency",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "2-of-3; WEAK adjudication (issue names file, not PR)",
      "defect": "#8553 added AuthorizationRequestContext.java with a loadRole(Runnable) method whose body is a non-atomic check-then-act on an AtomicBoolean: if (hasLoadRole.get()) return; runnable.run(); hasLoadRole.set(true);. Two threads entering concurr",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 933,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/pulsar",
      "key": "pulsar-23062",
      "introducing_pr": 23062,
      "fixing_pr": 24401,
      "lane": "concurrency",
      "review_grade": "B",
      "result": "MISS",
      "severity_or_note": "3/3 CLEARED the executor downgrade that arms the deadlock",
      "defect": "#23062 added TableView.java whose readLatest(String topic) drives snapshot replay through a private wait(CompletableFuture<R>, String) helper doing a BLOCKING future.get(clientOperationTimeoutMs, MILLISECONDS). The same PR changed TopicTran",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 934,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/pulsar",
      "key": "pulsar-23901",
      "introducing_pr": 23901,
      "fixing_pr": 23958,
      "lane": "concurrency",
      "review_grade": "C",
      "result": "MISS",
      "severity_or_note": "full weight \u2014 pattern predates #23901 but the async limiter arms it; 3/3 ran the inversion check and cleared it",
      "defect": "#23901 rewrote PendingReadsManager.PendingRead, introducing attach(CompletableFuture<List<EntryImpl>>) which calls the new private synchronized completeAndRemoveFromCache() on the BK completing thread and then dispatches synchronized readEn",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 935,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "FasterXML/jackson-databind",
      "key": "jackson-databind-4467",
      "introducing_pr": 4467,
      "fixing_pr": 4744,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "2-of-3; design cleared the hunk as correct",
      "defect": "PropertyBuilder.buildWriter handles JsonInclude.Include.NON_DEFAULT in two modes the surrounding code already distinguishes via the _useRealPropertyDefaults flag: POJO-level @JsonInclude(NON_DEFAULT), where real property defaults are known ",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 936,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "open-telemetry/opentelemetry-java",
      "key": "otel-4325",
      "introducing_pr": 4325,
      "fixing_pr": 8613,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "3/3; WEAK adjudication stratum (fix never cites the intro PR)",
      "defect": "ArrayBasedTraceStateBuilder.remove(String) \u2014 #4325 replaced physical list removal with a tombstone scheme guarded by a new numEntries counter; put() checks whether the slot's existing value is null before incrementing, but remove() does num",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 937,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "testcontainers/testcontainers-java",
      "key": "testcontainers-2473",
      "introducing_pr": 2473,
      "fixing_pr": 2490,
      "lane": "correctness",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "3/3, each enumerating the same four broken modules",
      "defect": "The refactor moved per-module port exposure out of the start-time configure() hook into constructors, but several no-arg constructors call super(...) rather than this(...), bypassing the constructor that now does addExposedPort \u2014 so a defau",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "skipped",
      "attribution_verdict": "SKIP-unresolvable"
    },
    {
      "n": 938,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/lucene",
      "key": "lucene-1017",
      "introducing_pr": 1017,
      "fixing_pr": 11825,
      "lane": "performance",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "1-of-3; correctness+design both cleared the un-hoisted visitor",
      "defect": "In lucene/core/src/java/org/apache/lucene/document/SpatialQuery.java, #1017's own diff deleted the hoisted `final SpatialVisitor spatialVisitor = getSpatialVisitor();` from createWeight(...) and replaced the use site with a per-leaf call in",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 939,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/druid",
      "key": "druid-6677",
      "introducing_pr": 6677,
      "fixing_pr": 8024,
      "lane": "performance",
      "review_grade": "B",
      "result": "HIT",
      "severity_or_note": "3/3; WEAK adjudication (maintainer issue comment, not the fix body)",
      "defect": "#6677 ('FileUtils: Sync directory entry too on writeAtomically') re-routed CompressionUtils.zip(...) through FileUtils.writeAtomically \u2014 its own diff adds `return FileUtils.writeAtomically(outputZipFile, out -> zip(directory, out));`. write",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "unattributed",
      "attribution_verdict": "NOT-LOCAL"
    },
    {
      "n": 940,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "opensearch-project/security",
      "key": "opensearch-security-1698",
      "introducing_pr": 1698,
      "fixing_pr": 2052,
      "lane": "security",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "3/3; OVERSIZED 62-file intro (R1+R8) + a disclosed fabricated-payload incident",
      "defect": "In src/main/java/org/opensearch/security/tools/SecurityAdmin.java, method execute(String[]), the `legacy` predicate lost its final conjunct. Before #1698 it read `createLegacyMode || (indexExists && getMappings() != null && getMappings().ge",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    },
    {
      "n": 941,
      "batch": "n=901-941 Opus 5 batch-92 wave (2026-07-25)",
      "repo": "apache/seatunnel",
      "key": "seatunnel-3499",
      "introducing_pr": 3499,
      "fixing_pr": 5579,
      "lane": "correctness",
      "review_grade": "A",
      "result": "HIT",
      "severity_or_note": "2-of-3; design cleared the inverted order; WEAK adjudication stratum",
      "defect": "SeaTunnelRowDebeziumDeserializationConverters.convert(): `Object fieldValue = struct.get(fieldName);` sits ABOVE the `if (field == null)` guard, so struct.get(...) throws for an absent field and the guard can never do its job \u2014 it is dead c",
      "finder_model": "Opus 5",
      "scoring": "hard-gate+second-pass",
      "attribution": "in-diff",
      "attribution_verdict": "LOCAL-STRONG"
    }
  ],
  "recent_hard_gate_window": {
    "n_start": 781,
    "n_end": 880,
    "hits": 42,
    "total": 99,
    "label": "batches 80\u201389 Layer B hard-gate",
    "postmortem": "mining/ledgers/batch80-89-miss-postmortem-2026-07-23.md"
  },
  "notes": "review_grade A/B = defect on the introducing diff's surface, C = cross-file, per mining/mined-pairs-candidates.md. 'deeper-than-fix' unadjudicated findings are deliberately NOT in these headline fields. Mis-graded candidates dropped pre-scoring are not counted. finder_model is the model that ran the finders for that banked HIT/MISS \u2014 do not mix models when quoting a single recall rate without disclosing the split. 2026-07-22 audit: four v0.38.9 post-slice re-banks reverted to their mined-time MISS (a slice's motivating pairs stay MISS \u2014 the uplift belongs in the How-it-improves card, not the recall count), and 12 batch-54\u201358 sticky-prior HITs re-banked to their second-pass re-run MISS results for consistency with the batch 59\u201363 replace policy. Recent hard-gate rate window n=781\u2013880 (batches 80\u201389): 42/99 (42%). Miss postmortem: mining/ledgers/batch80-89-miss-postmortem-2026-07-23.md (adjacent-target dominant; empty minority). Soft shortlist R9 multi-sibling/dual-path."
}