Known Vulnerabilities of Open Source Projects: Where Are the Fixes?

Antonino Sabetta,Serena Elisa Ponta,Rocio Cabrera Lozoya,Michele Bezzi,Tommaso Sacchetti,Matteo Greco,Gergő Balogh,Péter Hegedűs,Rudolf Ferenc,Ranindya Paramitha,Ivan Pashchenko,Aurora Papotti,Ákos Milánkovich,Fabio Massacci
DOI: https://doi.org/10.1109/msec.2023.3343836
IF: 3.105
2024-01-01
IEEE Security & Privacy
Abstract:Every day, developers have the daunting task of tracing vulnerabilities back in a morass of commits. In this article, we report the experience of the industrial open source tool, Prospector, to support developers in this task.
computer science, information systems, software engineering
What problem does this paper attempt to address?