Every day, developers have the daunting task of tracing vulnerabilities back in a morass of commits. In this article, we report the experience of the industrial open source tool, Prospector, to support developers in this task.
Known Vulnerabilities of Open Source Projects: Where Are the Fixes? / Sabetta, A.; Ponta, S. E.; Cabrera Lozoya, R.; Bezzi, M.; Sacchetti, T.; Greco, M.; Balogh, G.; Hegedus, P.; Ferenc, R.; Paramitha, R.; Pashchenko, I.; Papotti, A.; Milankovich, A.; Massacci, F.. - In: IEEE SECURITY & PRIVACY. - ISSN 1540-7993. - 22:2(2024), pp. 49-59. [10.1109/MSEC.2023.3343836]
Known Vulnerabilities of Open Source Projects: Where Are the Fixes?
Paramitha R.;Pashchenko I.;Papotti A.;Massacci F.
Ultimo
2024-01-01
Abstract
Every day, developers have the daunting task of tracing vulnerabilities back in a morass of commits. In this article, we report the experience of the industrial open source tool, Prospector, to support developers in this task.File in questo prodotto:
Non ci sono file associati a questo prodotto.
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione



