Known Vulnerabilities of Open Source Projects: Where Are the Fixes?

Sabetta, Antonino; Ponta, Serena Elisa; Cabrera Lozoya, Rocio; Bezz, Michele; Sacchetti, Tommaso; Greco, Matteo; Balogh, Gergo; Hegedus, Péter; Ferenc, Rudolf; Paramitha, Ranindya; Pashchenko, Ivan; Papotti, Aurora; Milánkovich, Ákos; Massacci, Fabio
IEEE Security & Privacy, 5 January 2024

Every day, developers have the daunting task of tracing vulnerabilities back in a morass of commits. In this article, we report the experience of the industrial open source tool, Prospector, to support developers in this task.
 

DOI
Type:
Journal
Date:
2024-01-05
Department:
Sécurité numérique
Eurecom Ref:
7561
Copyright:
© 2024 IEEE. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE.
See also:

PERMALINK : https://www.eurecom.fr/publication/7561