Vision: Identifying affected library versions for open source software vulnerabilities
Vulnerability reports play a crucial role in mitigating open-source software risks. Typically,
the vulnerability report contains affected versions of a software. However, despite the …
the vulnerability report contains affected versions of a software. However, despite the …
VFCFinder: Pairing Security Advisories and Patches
Security advisories are the primary channel of communication for discovered vulnerabilities
in open-source software, but they often lack crucial information. Specifically, 63% of …
in open-source software, but they often lack crucial information. Specifically, 63% of …
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
Developers usually use third-party libraries (TPLs) to facilitate the development of their
projects to avoid reinventing the wheels, however, the vulnerable TPLs indeed cause severe …
projects to avoid reinventing the wheels, however, the vulnerable TPLs indeed cause severe …
Vul4Java: A Java OSS vulnerability identification method based on a two-stage analysis
Open source software (OSS) has been widely used to accelerate software development,
inevitably exposing downstr omissions and false positives; omissions put applications and …
inevitably exposing downstr omissions and false positives; omissions put applications and …