A Deep Dive Into How Open-Source Project Maintainers Review and Resolve Bug Bounty Reports
Fuente:
arXiv
Salvato in:
| Autori principali: | Ayala, Jessy, Ngo, Steven, Garcia, Joshua |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2024
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
Investigating Vulnerability Disclosures in Open-Source Software Using Bug Bounty Reports and Security Advisories
di: Ayala, Jessy, et al.
Pubblicazione: (2025)
di: Ayala, Jessy, et al.
Pubblicazione: (2025)
A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features
di: Ayala, Jessy, et al.
Pubblicazione: (2024)
di: Ayala, Jessy, et al.
Pubblicazione: (2024)
From Reviewers' Lens: Understanding Bug Bounty Report Invalid Reasons with LLMs
di: Zheng, Jiangrui, et al.
Pubblicazione: (2025)
di: Zheng, Jiangrui, et al.
Pubblicazione: (2025)
Incentives and Outcomes in Bug Bounties
di: Wang, Serena, et al.
Pubblicazione: (2025)
di: Wang, Serena, et al.
Pubblicazione: (2025)
Detecting Protracted Vulnerabilities in Open Source Projects
di: Sridharkumar, Arjun, et al.
Pubblicazione: (2026)
di: Sridharkumar, Arjun, et al.
Pubblicazione: (2026)
Finding 709 Defects in 258 Projects: An Experience Report on Applying CodeQL to Open-Source Embedded Software (Experience Paper) -- Extended Report
di: Shen, Mingjie, et al.
Pubblicazione: (2023)
di: Shen, Mingjie, et al.
Pubblicazione: (2023)
SEDAC: A CVAE-Based Data Augmentation Method for Security Bug Report Identification
di: Liao, Y., et al.
Pubblicazione: (2024)
di: Liao, Y., et al.
Pubblicazione: (2024)
MirrorFuzz: Leveraging LLM and Shared Bugs for Deep Learning Framework APIs Fuzzing
di: Ou, Shiwen, et al.
Pubblicazione: (2025)
di: Ou, Shiwen, et al.
Pubblicazione: (2025)
SmartPoC: Generating Executable and Validated PoCs for Smart Contract Bug Reports
di: Chen, Longfei, et al.
Pubblicazione: (2025)
di: Chen, Longfei, et al.
Pubblicazione: (2025)
PROMFUZZ: Leveraging LLM-Driven and Bug-Oriented Composite Analysis for Detecting Functional Bugs in Smart Contracts
di: Lin, Xingshuang, et al.
Pubblicazione: (2025)
di: Lin, Xingshuang, et al.
Pubblicazione: (2025)
Sandboxing Adoption in Open Source Ecosystems
di: Alhindi, Maysara, et al.
Pubblicazione: (2024)
di: Alhindi, Maysara, et al.
Pubblicazione: (2024)
Hunting CUDA Bugs at Scale with cuFuzz
di: ziad, Mohamed Tarek Ibn, et al.
Pubblicazione: (2026)
di: ziad, Mohamed Tarek Ibn, et al.
Pubblicazione: (2026)
Exposing Go's Hidden Bugs: A Novel Concolic Framework
di: Gorna, Karolina, et al.
Pubblicazione: (2025)
di: Gorna, Karolina, et al.
Pubblicazione: (2025)
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
di: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Pubblicazione: (2025)
di: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Pubblicazione: (2025)
An Analysis of Malicious Packages in Open-Source Software in the Wild
di: Zhou, Xiaoyan, et al.
Pubblicazione: (2024)
di: Zhou, Xiaoyan, et al.
Pubblicazione: (2024)
An Open Source Python Library for Anonymizing Sensitive Data
di: Díaz, Judith Sáinz-Pardo, et al.
Pubblicazione: (2024)
di: Díaz, Judith Sáinz-Pardo, et al.
Pubblicazione: (2024)
Tracing Vulnerability Propagation Across Open Source Software Ecosystems
di: Ruohonen, Jukka, et al.
Pubblicazione: (2025)
di: Ruohonen, Jukka, et al.
Pubblicazione: (2025)
Automatic Detection of Reference Counting Bugs in Linux Kernel Drivers
di: Hattori, Joe, et al.
Pubblicazione: (2026)
di: Hattori, Joe, et al.
Pubblicazione: (2026)
Can Highlighting Help GitHub Maintainers Track Security Fixes?
di: Liu, Xueqing, et al.
Pubblicazione: (2024)
di: Liu, Xueqing, et al.
Pubblicazione: (2024)
A Large-scale Fine-grained Analysis of Packages in Open-Source Software Ecosystems
di: Zhou, Xiaoyan, et al.
Pubblicazione: (2024)
di: Zhou, Xiaoyan, et al.
Pubblicazione: (2024)
Centralized Defense: Logging and Mitigation of Kubernetes Misconfigurations with Open Source Tools
di: Russell, Eoghan, et al.
Pubblicazione: (2024)
di: Russell, Eoghan, et al.
Pubblicazione: (2024)
LineBreaker: Finding Token-Inconsistency Bugs with Large Language Models
di: Chen, Hongbo, et al.
Pubblicazione: (2024)
di: Chen, Hongbo, et al.
Pubblicazione: (2024)
Unlocking Reproducibility: Automating re-Build Process for Open-Source Software
di: Hassanshahi, Behnaz, et al.
Pubblicazione: (2025)
di: Hassanshahi, Behnaz, et al.
Pubblicazione: (2025)
The Code the World Depends On: A First Look at Technology Makers' Open Source Software Dependencies
di: Patrick, Cadence, et al.
Pubblicazione: (2024)
di: Patrick, Cadence, et al.
Pubblicazione: (2024)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing
di: Asmita, et al.
Pubblicazione: (2024)
di: Asmita, et al.
Pubblicazione: (2024)
Safety Interventions against Adversarial Patches in an Open-Source Driver Assistance System
di: Chen, Cheng, et al.
Pubblicazione: (2025)
di: Chen, Cheng, et al.
Pubblicazione: (2025)
Fixing 7,400 Bugs for 1$: Cheap Crash-Site Program Repair
di: Zheng, Han, et al.
Pubblicazione: (2025)
di: Zheng, Han, et al.
Pubblicazione: (2025)
HyperPUT: Generating Synthetic Faulty Programs to Challenge Bug-Finding Tools
di: Felici, Riccardo, et al.
Pubblicazione: (2022)
di: Felici, Riccardo, et al.
Pubblicazione: (2022)
The Auth Shim: A Lightweight Architectural Pattern for Integrating Enterprise SSO with Standalone Open-Source Applications
di: Agrawal, Yuvraj
Pubblicazione: (2025)
di: Agrawal, Yuvraj
Pubblicazione: (2025)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
di: Zheng, Xinyi, et al.
Pubblicazione: (2024)
di: Zheng, Xinyi, et al.
Pubblicazione: (2024)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
di: Cusick, James J.
Pubblicazione: (2025)
di: Cusick, James J.
Pubblicazione: (2025)
LLM-Enabled Open-Source Systems in the Wild: An Empirical Study of Vulnerabilities in GitHub Security Advisories
di: Shifat, Fariha Tanjim, et al.
Pubblicazione: (2026)
di: Shifat, Fariha Tanjim, et al.
Pubblicazione: (2026)
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
di: Tatschner, Stefan, et al.
Pubblicazione: (2025)
di: Tatschner, Stefan, et al.
Pubblicazione: (2025)
Rust for Embedded Systems: Current State, Challenges and Open Problems (Extended Report)
di: Sharma, Ayushi, et al.
Pubblicazione: (2023)
di: Sharma, Ayushi, et al.
Pubblicazione: (2023)
Patch2QL: Discover Cognate Defects in Open Source Software Supply Chain With Auto-generated Static Analysis Rules
di: Wang, Fuwei, et al.
Pubblicazione: (2024)
di: Wang, Fuwei, et al.
Pubblicazione: (2024)
Qualitative Coding Analysis through Open-Source Large Language Models: A User Study and Design Recommendations
di: Ngo, Tung T., et al.
Pubblicazione: (2026)
di: Ngo, Tung T., et al.
Pubblicazione: (2026)
Leveraging Large Language Models for Command Injection Vulnerability Analysis in Python: An Empirical Study on Popular Open-Source Projects
di: Wang, Yuxuan, et al.
Pubblicazione: (2025)
di: Wang, Yuxuan, et al.
Pubblicazione: (2025)
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
di: Montaruli, Biagio, et al.
Pubblicazione: (2025)
di: Montaruli, Biagio, et al.
Pubblicazione: (2025)
UBfuzz: Finding Bugs in Sanitizer Implementations
di: Li, Shaohua, et al.
Pubblicazione: (2024)
di: Li, Shaohua, et al.
Pubblicazione: (2024)
Documenti analoghi
-
Investigating Vulnerability Disclosures in Open-Source Software Using Bug Bounty Reports and Security Advisories
di: Ayala, Jessy, et al.
Pubblicazione: (2025) -
A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features
di: Ayala, Jessy, et al.
Pubblicazione: (2024) -
From Reviewers' Lens: Understanding Bug Bounty Report Invalid Reasons with LLMs
di: Zheng, Jiangrui, et al.
Pubblicazione: (2025) -
Incentives and Outcomes in Bug Bounties
di: Wang, Serena, et al.
Pubblicazione: (2025) -
Detecting Protracted Vulnerabilities in Open Source Projects
di: Sridharkumar, Arjun, et al.
Pubblicazione: (2026)