Trusting code in the wild: Exploring contributor reputation measures to review dependencies in the Rust ecosystem
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Hamer, Sivana, Imtiaz, Nasif, Tamanna, Mahzabin, Shabrina, Preya, Williams, Laurie |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2024
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
Just another copy and paste? Comparing the security vulnerabilities of ChatGPT generated code and StackOverflow answers
von: Hamer, Sivana, et al.
Veröffentlicht: (2024)
von: Hamer, Sivana, et al.
Veröffentlicht: (2024)
Your ATs to Ts: MITRE ATT&CK Attack Technique to P-SSCRM Task Mapping
von: Hamer, Sivana, et al.
Veröffentlicht: (2025)
von: Hamer, Sivana, et al.
Veröffentlicht: (2025)
Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ Utils
von: Hamer, Sivana, et al.
Veröffentlicht: (2025)
von: Hamer, Sivana, et al.
Veröffentlicht: (2025)
Analyzing Challenges in Deployment of the SLSA Framework for Software Supply Chain Security
von: Tamanna, Mahzabin, et al.
Veröffentlicht: (2024)
von: Tamanna, Mahzabin, et al.
Veröffentlicht: (2024)
SandCell: Sandboxing Rust Beyond Unsafe Code
von: Zhang, Jialun, et al.
Veröffentlicht: (2025)
von: Zhang, Jialun, et al.
Veröffentlicht: (2025)
RiskHarvester: A Risk-based Tool to Prioritize Secret Removal Efforts in Software Artifacts
von: Basak, Setu Kumar, et al.
Veröffentlicht: (2025)
von: Basak, Setu Kumar, et al.
Veröffentlicht: (2025)
SafeTrans: LLM-assisted Transpilation from C to Rust
von: Farrukh, Muhammad, et al.
Veröffentlicht: (2025)
von: Farrukh, Muhammad, et al.
Veröffentlicht: (2025)
An Empirical Security Evaluation of LLM-Generated Cryptographic Rust Code
von: Elsayed, Mohamed, et al.
Veröffentlicht: (2026)
von: Elsayed, Mohamed, et al.
Veröffentlicht: (2026)
KVerus: Scalable and Resilient Formal Verification Proof Generation for Rust Code
von: Liu, Yuwei, et al.
Veröffentlicht: (2026)
von: Liu, Yuwei, et al.
Veröffentlicht: (2026)
HALURust: Exploiting Hallucinations of Large Language Models to Detect Vulnerabilities in Rust
von: Luo, Yu, et al.
Veröffentlicht: (2025)
von: Luo, Yu, et al.
Veröffentlicht: (2025)
Comparing Effectiveness and Efficiency of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) Tools in a Large Java-based System
von: Seth, Aishwarya, et al.
Veröffentlicht: (2023)
von: Seth, Aishwarya, et al.
Veröffentlicht: (2023)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
von: Rahman, Imranur, et al.
Veröffentlicht: (2024)
von: Rahman, Imranur, et al.
Veröffentlicht: (2024)
Rust for Embedded Systems: Current State, Challenges and Open Problems (Extended Report)
von: Sharma, Ayushi, et al.
Veröffentlicht: (2023)
von: Sharma, Ayushi, et al.
Veröffentlicht: (2023)
AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts
von: Basak, Setu Kumar, et al.
Veröffentlicht: (2024)
von: Basak, Setu Kumar, et al.
Veröffentlicht: (2024)
Static Deadlock Detection for Rust Programs
von: Zhang, Yu, et al.
Veröffentlicht: (2024)
von: Zhang, Yu, et al.
Veröffentlicht: (2024)
What You Trust Is Insecure: Demystifying How Developers (Mis)Use Trusted Execution Environments in Practice
von: Niu, Yuqing, et al.
Veröffentlicht: (2025)
von: Niu, Yuqing, et al.
Veröffentlicht: (2025)
Intent-Aware Authorization for Zero Trust CI/CD
von: Avirneni, Surya Teja
Veröffentlicht: (2025)
von: Avirneni, Surya Teja
Veröffentlicht: (2025)
Towards Trust Proof for Secure Confidential Virtual Machines
von: Mao, Jingkai, et al.
Veröffentlicht: (2024)
von: Mao, Jingkai, et al.
Veröffentlicht: (2024)
Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure
von: Avirneni, Surya Teja
Veröffentlicht: (2025)
von: Avirneni, Surya Teja
Veröffentlicht: (2025)
Characterizing Trust Boundary Vulnerabilities in TEE Containers: An Empirical Study
von: Liu, Weijie, et al.
Veröffentlicht: (2025)
von: Liu, Weijie, et al.
Veröffentlicht: (2025)
Translating C To Rust: Lessons from a User Study
von: Li, Ruishi, et al.
Veröffentlicht: (2024)
von: Li, Ruishi, et al.
Veröffentlicht: (2024)
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
von: Montaruli, Biagio, et al.
Veröffentlicht: (2025)
von: Montaruli, Biagio, et al.
Veröffentlicht: (2025)
Establishing Workload Identity for Zero Trust CI/CD: From Secrets to SPIFFE-Based Authentication
von: Avirneni, Surya Teja
Veröffentlicht: (2025)
von: Avirneni, Surya Teja
Veröffentlicht: (2025)
When "Correct" Is Not Safe: Can We Trust Functionally Correct Patches Generated by Code Agents?
von: Peng, Yibo, et al.
Veröffentlicht: (2025)
von: Peng, Yibo, et al.
Veröffentlicht: (2025)
In Specs we Trust? Conformance-Analysis of Implementation to Specifications in Node-RED and Associated Security Risks
von: Schneider, Simon, et al.
Veröffentlicht: (2025)
von: Schneider, Simon, et al.
Veröffentlicht: (2025)
Toward Secure Web to ERP Payment Flows: A Case Study of HTTP Header Trust Failures in SAP Based Systems
von: Dini, Vick
Veröffentlicht: (2026)
von: Dini, Vick
Veröffentlicht: (2026)
deepSURF: Detecting Memory Safety Vulnerabilities in Rust Through Fuzzing LLM-Augmented Harnesses
von: Androutsopoulos, Georgios, et al.
Veröffentlicht: (2025)
von: Androutsopoulos, Georgios, et al.
Veröffentlicht: (2025)
A unit-based symbolic execution method for detecting memory corruption vulnerabilities in executable codes
von: Baradaran, Sara, et al.
Veröffentlicht: (2022)
von: Baradaran, Sara, et al.
Veröffentlicht: (2022)
Symbolic Execution Meets Multi-LLM Orchestration: Detecting Memory Vulnerabilities in Incomplete Rust CVE Snippets
von: Abdelrazek, Zeyad, et al.
Veröffentlicht: (2026)
von: Abdelrazek, Zeyad, et al.
Veröffentlicht: (2026)
Exploring Security Practices in Infrastructure as Code: An Empirical Study
von: Verdet, Alexandre, et al.
Veröffentlicht: (2023)
von: Verdet, Alexandre, et al.
Veröffentlicht: (2023)
Exploring User Privacy Awareness on GitHub: An Empirical Study
von: Alfieri, Costanza, et al.
Veröffentlicht: (2024)
von: Alfieri, Costanza, et al.
Veröffentlicht: (2024)
From Generalist to Specialist: Exploring CWE-Specific Vulnerability Detection
von: Atiiq, Syafiq Al, et al.
Veröffentlicht: (2024)
von: Atiiq, Syafiq Al, et al.
Veröffentlicht: (2024)
Classport: Designing Runtime Dependency Introspection for Java
von: Cofano, Serena, et al.
Veröffentlicht: (2025)
von: Cofano, Serena, et al.
Veröffentlicht: (2025)
Beyond Trusting Trust: Multi-Model Validation for Robust Code Generation
von: McDanel, Bradley
Veröffentlicht: (2025)
von: McDanel, Bradley
Veröffentlicht: (2025)
Exploring the Security Threats of Retriever Backdoors in Retrieval-Augmented Code Generation
von: Li, Tian, et al.
Veröffentlicht: (2025)
von: Li, Tian, et al.
Veröffentlicht: (2025)
Exploring the Security Threats of Knowledge Base Poisoning in Retrieval-Augmented Code Generation
von: Lin, Bo, et al.
Veröffentlicht: (2025)
von: Lin, Bo, et al.
Veröffentlicht: (2025)
A Developer-Centric Study Exploring Mobile Application Security Practices and Challenges
von: Peruma, Anthony, et al.
Veröffentlicht: (2024)
von: Peruma, Anthony, et al.
Veröffentlicht: (2024)
Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
von: Swierzy, Ben, et al.
Veröffentlicht: (2025)
von: Swierzy, Ben, et al.
Veröffentlicht: (2025)
"I Don't Use AI for Everything": Exploring Utility, Attitude, and Responsibility of AI-empowered Tools in Software Development
von: Pan, Shidong, et al.
Veröffentlicht: (2024)
von: Pan, Shidong, et al.
Veröffentlicht: (2024)
SAVANT: Vulnerability Detection in Application Dependencies through Semantic-Guided Reachability Analysis
von: Lingxiang, Wang, et al.
Veröffentlicht: (2025)
von: Lingxiang, Wang, et al.
Veröffentlicht: (2025)
Ähnliche Einträge
-
Just another copy and paste? Comparing the security vulnerabilities of ChatGPT generated code and StackOverflow answers
von: Hamer, Sivana, et al.
Veröffentlicht: (2024) -
Your ATs to Ts: MITRE ATT&CK Attack Technique to P-SSCRM Task Mapping
von: Hamer, Sivana, et al.
Veröffentlicht: (2025) -
Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ Utils
von: Hamer, Sivana, et al.
Veröffentlicht: (2025) -
Analyzing Challenges in Deployment of the SLSA Framework for Software Supply Chain Security
von: Tamanna, Mahzabin, et al.
Veröffentlicht: (2024) -
SandCell: Sandboxing Rust Beyond Unsafe Code
von: Zhang, Jialun, et al.
Veröffentlicht: (2025)