학술논문

Known Vulnerabilities of Open Source Projects: Where Are the Fixes?
Document Type
Periodical
Source
IEEE Security & Privacy IEEE Secur. Privacy Security & Privacy, IEEE. 22(2):49-59 Apr, 2024
Subject
Computing and Processing
Aerospace
Bioengineering
Components, Circuits, Devices and Systems
Engineered Materials, Dielectrics and Plasmas
Engineering Profession
Fields, Waves and Electromagnetics
General Topics for Engineers
Nuclear Engineering
Robotics and Control Systems
Signal Processing and Analysis
Transportation
Communication, Networking and Broadcast Technologies
Photonics and Electrooptics
Power, Energy and Industry Applications
Codes
Security
Source coding
Databases
Metadata
Knowledge based systems
Data mining
Open source software
Language
ISSN
1540-7993
1558-4046
Abstract
Every day, developers have the daunting task of tracing vulnerabilities back in a morass of commits. In this article, we report the experience of the industrial open source tool, Prospector, to support developers in this task.