Investigating Vulnerability Disclosures in Open-Source Software Using Bug Bounty Reports and Security Advisories
Fuente:
arXiv
Saved in:
| Main Authors: | Ayala, Jessy, Tung, Yu-Jye, Garcia, Joshua |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features
by: Ayala, Jessy, et al.
Published: (2024)
by: Ayala, Jessy, et al.
Published: (2024)
A Deep Dive Into How Open-Source Project Maintainers Review and Resolve Bug Bounty Reports
by: Ayala, Jessy, et al.
Published: (2024)
by: Ayala, Jessy, et al.
Published: (2024)
From Reviewers' Lens: Understanding Bug Bounty Report Invalid Reasons with LLMs
by: Zheng, Jiangrui, et al.
Published: (2025)
by: Zheng, Jiangrui, et al.
Published: (2025)
LLM-Enabled Open-Source Systems in the Wild: An Empirical Study of Vulnerabilities in GitHub Security Advisories
by: Shifat, Fariha Tanjim, et al.
Published: (2026)
by: Shifat, Fariha Tanjim, et al.
Published: (2026)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
by: Cusick, James J.
Published: (2025)
by: Cusick, James J.
Published: (2025)
Incentives and Outcomes in Bug Bounties
by: Wang, Serena, et al.
Published: (2025)
by: Wang, Serena, et al.
Published: (2025)
Using LLMs for Security Advisory Investigations: How Far Are We?
by: Abdullah, Bayu Fedra, et al.
Published: (2025)
by: Abdullah, Bayu Fedra, et al.
Published: (2025)
Tracing Vulnerability Propagation Across Open Source Software Ecosystems
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
by: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Published: (2025)
by: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Published: (2025)
Automated Mapping of Vulnerability Advisories onto their Fix Commits in Open Source Repositories
by: Hommersom, Daan, et al.
Published: (2021)
by: Hommersom, Daan, et al.
Published: (2021)
Detecting Protracted Vulnerabilities in Open Source Projects
by: Sridharkumar, Arjun, et al.
Published: (2026)
by: Sridharkumar, Arjun, et al.
Published: (2026)
Generating Proof-of-Vulnerability Tests to Help Enhance the Security of Complex Software
by: Kanchi, Shravya, et al.
Published: (2026)
by: Kanchi, Shravya, et al.
Published: (2026)
An Overview of Cyber Security Funding for Open Source Software
by: Ruohonen, Jukka, et al.
Published: (2024)
by: Ruohonen, Jukka, et al.
Published: (2024)
A Manually-Curated Dataset of Fixes to Vulnerabilities of Open-Source Software
by: Ponta, Serena E., et al.
Published: (2019)
by: Ponta, Serena E., et al.
Published: (2019)
SEDAC: A CVAE-Based Data Augmentation Method for Security Bug Report Identification
by: Liao, Y., et al.
Published: (2024)
by: Liao, Y., et al.
Published: (2024)
An Analysis of Malicious Packages in Open-Source Software in the Wild
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
Securing Tomorrow's Smart Cities: Investigating Software Security in Internet of Vehicles and Deep Learning Technologies
by: Jain, Ridhi, et al.
Published: (2024)
by: Jain, Ridhi, et al.
Published: (2024)
SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis
by: Marquer, Yoann, et al.
Published: (2026)
by: Marquer, Yoann, et al.
Published: (2026)
Characterizing and Modeling the GitHub Security Advisories Review Pipeline
by: Segal, Claudio, et al.
Published: (2026)
by: Segal, Claudio, et al.
Published: (2026)
Unlocking Reproducibility: Automating re-Build Process for Open-Source Software
by: Hassanshahi, Behnaz, et al.
Published: (2025)
by: Hassanshahi, Behnaz, et al.
Published: (2025)
Finding 709 Defects in 258 Projects: An Experience Report on Applying CodeQL to Open-Source Embedded Software (Experience Paper) -- Extended Report
by: Shen, Mingjie, et al.
Published: (2023)
by: Shen, Mingjie, et al.
Published: (2023)
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
by: Ponta, Serena E., et al.
Published: (2018)
by: Ponta, Serena E., et al.
Published: (2018)
VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
by: Cheng, Yiran, et al.
Published: (2024)
by: Cheng, Yiran, et al.
Published: (2024)
A Large-scale Fine-grained Analysis of Packages in Open-Source Software Ecosystems
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
An Empirical Study on the Security Vulnerabilities of GPTs
by: Wu, Tong, et al.
Published: (2025)
by: Wu, Tong, et al.
Published: (2025)
Security study based on the Chatgptplugin system: ldentifying Security Vulnerabilities
by: Ren, Ruomai
Published: (2025)
by: Ren, Ruomai
Published: (2025)
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
by: Tatschner, Stefan, et al.
Published: (2025)
by: Tatschner, Stefan, et al.
Published: (2025)
Game Rewards Vulnerabilities: Software Vulnerability Detection with Zero-Sum Game and Prototype Learning
by: Wen, Xin-Cheng, et al.
Published: (2024)
by: Wen, Xin-Cheng, et al.
Published: (2024)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
The Code the World Depends On: A First Look at Technology Makers' Open Source Software Dependencies
by: Patrick, Cadence, et al.
Published: (2024)
by: Patrick, Cadence, et al.
Published: (2024)
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025)
by: Hegewald, Richard, et al.
Published: (2025)
Fixing Security Vulnerabilities with AI in OSS-Fuzz
by: Zhang, Yuntong, et al.
Published: (2024)
by: Zhang, Yuntong, et al.
Published: (2024)
SecDOAR: A Software Reference Architecture for Security Data Orchestration, Analysis and Reporting
by: Chauhan, Muhammad Aufeef, et al.
Published: (2024)
by: Chauhan, Muhammad Aufeef, et al.
Published: (2024)
An Introduction to Adaptive Software Security
by: Nia, Mehran Alidoost
Published: (2023)
by: Nia, Mehran Alidoost
Published: (2023)
OpenSCV: An Open Hierarchical Taxonomy for Smart Contract Vulnerabilities
by: Vidal, Fernando Richter, et al.
Published: (2023)
by: Vidal, Fernando Richter, et al.
Published: (2023)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
by: Ruan, Bonan, et al.
Published: (2025)
by: Ruan, Bonan, et al.
Published: (2025)
Deep Learning Aided Software Vulnerability Detection: A Survey
by: Uddin, Md Nizam, et al.
Published: (2025)
by: Uddin, Md Nizam, et al.
Published: (2025)
SHERLOCK: A Deep Learning Approach To Detect Software Vulnerabilities
by: Jawwadh, Saadh, et al.
Published: (2025)
by: Jawwadh, Saadh, et al.
Published: (2025)
R+R: Security Vulnerability Dataset Quality Is Critical
by: Yadav, Anurag Swarnim, et al.
Published: (2025)
by: Yadav, Anurag Swarnim, et al.
Published: (2025)
Similar Items
-
A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features
by: Ayala, Jessy, et al.
Published: (2024) -
A Deep Dive Into How Open-Source Project Maintainers Review and Resolve Bug Bounty Reports
by: Ayala, Jessy, et al.
Published: (2024) -
From Reviewers' Lens: Understanding Bug Bounty Report Invalid Reasons with LLMs
by: Zheng, Jiangrui, et al.
Published: (2025) -
LLM-Enabled Open-Source Systems in the Wild: An Empirical Study of Vulnerabilities in GitHub Security Advisories
by: Shifat, Fariha Tanjim, et al.
Published: (2026) -
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
by: Cusick, James J.
Published: (2025)