SBOM Generation Tools in the Python Ecosystem: an In-Detail Analysis
Fuente:
arXiv
Saved in:
| Main Authors: | Cofano, Serena, Benedetti, Giacomo, Dell'Amico, Matteo |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
The Impact of SBOM Generators on Vulnerability Assessment in Python: A Comparison and a Novel Approach
by: Benedetti, Giacomo, et al.
Published: (2024)
by: Benedetti, Giacomo, et al.
Published: (2024)
Classport: Designing Runtime Dependency Introspection for Java
by: Cofano, Serena, et al.
Published: (2025)
by: Cofano, Serena, et al.
Published: (2025)
UniBOM -- A Unified SBOM Analysis and Visualisation Tool for IoT Systems and Beyond
by: Safronov, Vadim, et al.
Published: (2025)
by: Safronov, Vadim, et al.
Published: (2025)
zkSBOM: Privacy-Preserving SBOM Sharing with Zero-Knowledge Sets
by: Sorger, Tom, et al.
Published: (2026)
by: Sorger, Tom, et al.
Published: (2026)
VeriSBOM: Secure and Verifiable SBOM Sharing Via Zero-Knowledge Proofs
by: Castiglione, Gianpietro, et al.
Published: (2026)
by: Castiglione, Gianpietro, et al.
Published: (2026)
Automating SBOM Generation with Zero-Shot Semantic Similarity
by: Pereira, Devin, et al.
Published: (2024)
by: Pereira, Devin, et al.
Published: (2024)
Cross-Ecosystem Vulnerability Analysis for Python Applications
by: Alexopoulos, Georgios, et al.
Published: (2026)
by: Alexopoulos, Georgios, et al.
Published: (2026)
A Practical Solution to Systematically Monitor Inconsistencies in SBOM-based Vulnerability Scanners
by: Rosso, Martin, et al.
Published: (2025)
by: Rosso, Martin, et al.
Published: (2025)
SBOMproof: Beyond Alleged SBOM Compliance for Supply Chain Security of Container Images
by: Bufalino, Jacopo, et al.
Published: (2025)
by: Bufalino, Jacopo, et al.
Published: (2025)
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
by: Sharma, Aman, et al.
Published: (2024)
by: Sharma, Aman, et al.
Published: (2024)
VDGraph: A Graph-Theoretic Approach to Unlock Insights from SBOM and SCA Data
by: Xia, Howell, et al.
Published: (2025)
by: Xia, Howell, et al.
Published: (2025)
Evaluating Tool Cloning in Agentic-AI Ecosystems
by: Kim, Taein, et al.
Published: (2026)
by: Kim, Taein, et al.
Published: (2026)
A Time Series Analysis of Malware Uploads to Programming Language Ecosystems
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
by: Ponta, Serena E., et al.
Published: (2018)
by: Ponta, Serena E., et al.
Published: (2018)
Developers Are Victims Too : A Comprehensive Analysis of The VS Code Extension Ecosystem
by: Edirimannage, Shehan, et al.
Published: (2024)
by: Edirimannage, Shehan, et al.
Published: (2024)
A Large-scale Fine-grained Analysis of Packages in Open-Source Software Ecosystems
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
CrossCommitVuln-Bench: A Dataset of Multi-Commit Python Vulnerabilities Invisible to Per-Commit Static Analysis
by: Majumdar, Arunabh
Published: (2026)
by: Majumdar, Arunabh
Published: (2026)
Sandboxing Adoption in Open Source Ecosystems
by: Alhindi, Maysara, et al.
Published: (2024)
by: Alhindi, Maysara, et al.
Published: (2024)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
An Investigation of Patch Porting Practices of the Linux Kernel Ecosystem
by: Li, Xingyu, et al.
Published: (2024)
by: Li, Xingyu, et al.
Published: (2024)
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
by: Tatschner, Stefan, et al.
Published: (2025)
by: Tatschner, Stefan, et al.
Published: (2025)
HyperPUT: Generating Synthetic Faulty Programs to Challenge Bug-Finding Tools
by: Felici, Riccardo, et al.
Published: (2022)
by: Felici, Riccardo, et al.
Published: (2022)
Unity is Strength: Enhancing Precision in Reentrancy Vulnerability Detection of Smart Contract Analysis Tools
by: Wang, Zexu, et al.
Published: (2024)
by: Wang, Zexu, et al.
Published: (2024)
Leveraging Security Observability to Strengthen Security of Digital Ecosystem Architecture
by: Ramachandran, Renjith
Published: (2024)
by: Ramachandran, Renjith
Published: (2024)
MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools
by: Tan, Zhuoran, et al.
Published: (2026)
by: Tan, Zhuoran, et al.
Published: (2026)
From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
by: Zhou, Dongchao, et al.
Published: (2025)
by: Zhou, Dongchao, et al.
Published: (2025)
Tracing Vulnerability Propagation Across Open Source Software Ecosystems
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Impact assessment for vulnerabilities in open-source software libraries
by: Plate, Henrik, et al.
Published: (2015)
by: Plate, Henrik, et al.
Published: (2015)
AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts
by: Basak, Setu Kumar, et al.
Published: (2024)
by: Basak, Setu Kumar, et al.
Published: (2024)
SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
by: Pohl, Timo, et al.
Published: (2025)
by: Pohl, Timo, et al.
Published: (2025)
A Multi-Store Privacy Measurement of Virtual Reality App Ecosystem
by: Yan, Chuan, et al.
Published: (2025)
by: Yan, Chuan, et al.
Published: (2025)
A Ground-Truth-Based Evaluation of Vulnerability Detection Across Multiple Ecosystems
by: Mandl, Peter, et al.
Published: (2026)
by: Mandl, Peter, et al.
Published: (2026)
An Empirical Study on Remote Code Execution in Machine Learning Model Hosting Ecosystems
by: Siddiq, Mohammed Latif, et al.
Published: (2026)
by: Siddiq, Mohammed Latif, et al.
Published: (2026)
Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem
by: Song, Hao, et al.
Published: (2025)
by: Song, Hao, et al.
Published: (2025)
Track and Trace: Automatically Uncovering Cross-chain Transactions in the Multi-blockchain Ecosystems
by: Lin, Dan, et al.
Published: (2025)
by: Lin, Dan, et al.
Published: (2025)
Mining the YARA Ecosystem: From Ad-Hoc Sharing to Data-Driven Threat Intelligence
by: Esteban, Dectot--Le Monnier de Gouville, et al.
Published: (2026)
by: Esteban, Dectot--Le Monnier de Gouville, et al.
Published: (2026)
SafeToolBench: Pioneering a Prospective Benchmark to Evaluating Tool Utilization Safety in LLMs
by: Xia, Hongfei, et al.
Published: (2025)
by: Xia, Hongfei, et al.
Published: (2025)
AutoDFBench 1.0: A Benchmarking Framework for Digital Forensic Tool Testing and Generated Code Evaluation
by: Wickramasekara, Akila, et al.
Published: (2025)
by: Wickramasekara, Akila, et al.
Published: (2025)
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
by: Montaruli, Biagio, et al.
Published: (2025)
by: Montaruli, Biagio, et al.
Published: (2025)
TREBLE: Fast Software Updates by Creating an Equilibrium in an Active Software Ecosystem of Globally Distributed Stakeholders
by: Yim, Keun Soo, et al.
Published: (2024)
by: Yim, Keun Soo, et al.
Published: (2024)
Similar Items
-
The Impact of SBOM Generators on Vulnerability Assessment in Python: A Comparison and a Novel Approach
by: Benedetti, Giacomo, et al.
Published: (2024) -
Classport: Designing Runtime Dependency Introspection for Java
by: Cofano, Serena, et al.
Published: (2025) -
UniBOM -- A Unified SBOM Analysis and Visualisation Tool for IoT Systems and Beyond
by: Safronov, Vadim, et al.
Published: (2025) -
zkSBOM: Privacy-Preserving SBOM Sharing with Zero-Knowledge Sets
by: Sorger, Tom, et al.
Published: (2026) -
VeriSBOM: Secure and Verifiable SBOM Sharing Via Zero-Knowledge Proofs
by: Castiglione, Gianpietro, et al.
Published: (2026)