Empirical Analysis of Vulnerabilities Life Cycle in Golang Ecosystem

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Hu, Jinchang, Zhang, Lyuye, Liu, Chengwei, Yang, Sen, Huang, Song, Liu, Yang
Formato: Preprint
Publicado: 2023
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866916093963010048
author Hu, Jinchang
Zhang, Lyuye
Liu, Chengwei
Yang, Sen
Huang, Song
Liu, Yang
author_facet Hu, Jinchang
Zhang, Lyuye
Liu, Chengwei
Yang, Sen
Huang, Song
Liu, Yang
contents Open-source software (OSS) greatly facilitates program development for developers. However, the high number of vulnerabilities in open-source software is a major concern, including in Golang, a relatively new programming language. In contrast to other commonly used OSS package managers, Golang presents a distinctive feature whereby commits are prevalently used as dependency versions prior to their integration into official releases. This attribute can prove advantageous to users, as patch commits can be implemented in a timely manner before the releases. However, Golang employs a decentralized mechanism for managing dependencies, whereby dependencies are upheld and distributed in separate repositories. This approach can result in delays in the dissemination of patches and unresolved vulnerabilities. To tackle the aforementioned concern, a comprehensive investigation was undertaken to examine the life cycle of vulnerability in Golang, commencing from its introduction and culminating with its rectification. To this end, a framework was established by gathering data from diverse sources and systematically amalgamating them with an algorithm to compute the lags in vulnerability patching. It turned out that 66.10% of modules in the Golang ecosystem were affected by vulnerabilities. Within the vulnerability life cycle, we found two kinds of lag impeding the propagation of vulnerability fixing. By analyzing reasons behind non-lagged and lagged vulnerabilities, timely releasing and indexing patch versions could significantly enhance ecosystem security.
format Preprint
id arxiv_https___arxiv_org_abs_2401_00515
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Empirical Analysis of Vulnerabilities Life Cycle in Golang Ecosystem
Hu, Jinchang
Zhang, Lyuye
Liu, Chengwei
Yang, Sen
Huang, Song
Liu, Yang
Software Engineering
Open-source software (OSS) greatly facilitates program development for developers. However, the high number of vulnerabilities in open-source software is a major concern, including in Golang, a relatively new programming language. In contrast to other commonly used OSS package managers, Golang presents a distinctive feature whereby commits are prevalently used as dependency versions prior to their integration into official releases. This attribute can prove advantageous to users, as patch commits can be implemented in a timely manner before the releases. However, Golang employs a decentralized mechanism for managing dependencies, whereby dependencies are upheld and distributed in separate repositories. This approach can result in delays in the dissemination of patches and unresolved vulnerabilities. To tackle the aforementioned concern, a comprehensive investigation was undertaken to examine the life cycle of vulnerability in Golang, commencing from its introduction and culminating with its rectification. To this end, a framework was established by gathering data from diverse sources and systematically amalgamating them with an algorithm to compute the lags in vulnerability patching. It turned out that 66.10% of modules in the Golang ecosystem were affected by vulnerabilities. Within the vulnerability life cycle, we found two kinds of lag impeding the propagation of vulnerability fixing. By analyzing reasons behind non-lagged and lagged vulnerabilities, timely releasing and indexing patch versions could significantly enhance ecosystem security.
title Empirical Analysis of Vulnerabilities Life Cycle in Golang Ecosystem
topic Software Engineering
url https://arxiv.org/abs/2401.00515