Every day, developers have the daunting task of tracing vulnerabilities back in a morass of commits. In this article, we report the experience of the industrial open source tool, Prospector, to support developers in this task.
Known Vulnerabilities of Open Source Projects: Where Are the Fixes? / Sabetta, A., Elisa Ponta, S., Cabrera Lozoya, R., Bezzi, M., Sacchetti, T., Greco, M., Balogh, G., Hegedus, P., Ferenc, R., Paramitha, R., Pashchenko, I., Papotti, A., Milankovic, A., Massacci, F.. - In: IEEE SECURITY & PRIVACY. - ISSN 1540-7993. - 22:2(2024), pp. 49-59. [10.1109/MSEC.2023.3343836]
Known Vulnerabilities of Open Source Projects: Where Are the Fixes?
Ranindya Paramitha;Ivan Pashchenko;Aurora Papotti;Fabio Massacci
2024-01-01
Abstract
Every day, developers have the daunting task of tracing vulnerabilities back in a morass of commits. In this article, we report the experience of the industrial open source tool, Prospector, to support developers in this task.File in questo prodotto:
| File | Dimensione | Formato | |
|---|---|---|---|
|
Known_Vulnerabilities_of_Open_Source_Projects_Where_Are_the_Fixes.pdf
accesso aperto
Descrizione: Versione Finale
Tipologia:
Versione editoriale (Publisher’s layout)
Licenza:
Creative commons
Dimensione
1.59 MB
Formato
Adobe PDF
|
1.59 MB | Adobe PDF | Visualizza/Apri |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione



