Known Vulnerabilities of Open Source Projects: Where Are the Fixes?

Antonino Sabetta, Serena Elisa Ponta, Rocio Cabrera Lozoya, Michele Bezzi, Tommaso Sacchetti, Matteo Greco, Gergo Balogh, Peter Hegedus, Rudolf Ferenc, Ranindya Paramitha, Ivan Pashchenko, Aurora Papotti, Akos Milankovich, Fabio Massacci

Research output: Contribution to JournalArticleAcademicpeer-review

Abstract

Every day, developers have the daunting task of tracing vulnerabilities back in a morass of commits. In this article, we report the experience of the industrial open source tool, Prospector, to support developers in this task.

Original languageEnglish
Pages (from-to)49-59
Number of pages11
JournalIEEE Security and Privacy
Volume22
Issue number2
Early online date5 Jan 2024
DOIs
Publication statusPublished - Apr 2024

Bibliographical note

Publisher Copyright:
© 2003-2012 IEEE.

Funding

This work was partially supported by EU-funded projects Sec4AI4Sec (Grant 101120393) and AssureMoss (Grant 952647) and NWO-funded project Theseus (Grant NWA.121518006). Antonino Sabetta would like to thank Henrik Plate, Bonaventura Coppola, Daan Hommersom, Damian A. Tamburri, and Dario Di Nucci for insightful discussions.

FundersFunder number
European Commission101120393
AssureMoss952647
NWO-fundedNWA.121518006

    Fingerprint

    Dive into the research topics of 'Known Vulnerabilities of Open Source Projects: Where Are the Fixes?'. Together they form a unique fingerprint.

    Cite this