Notes from the
mlab engineering team
How the platform is built, measured and broken. Internal studies, benchmarks against other tools, and the details we usually keep in our own docs. Written for people who read the methodology before the conclusion.
Method before result
Corpus, versions, hardware and configuration come first. If a number cannot be traced back to how it was produced, it does not ship.
We show where we lose
Every comparison names the cases where mlab does worse. A benchmark that wins everywhere is a benchmark nobody should trust.
Raw numbers, open data
Precision, recall, timings and memory as measured, no composite score. Datasets and scripts are published whenever their licence allows it.
All notes
Newest firstReplaying supply-chain attacks against postmortem
Eleven public npm, PyPI and crates.io incidents replayed against postmortem, then five large real projects read by hand: which signals fire before an advisory exists, why a 48-hour cooldown is the cheapest control, and the six bugs the test found in our own tool.
No note matches .