RiskHarvester: A Risk-based Tool to Prioritize Secret Removal Efforts in Software Artifacts
Fuente:
arXiv
Guardado en:
| Autores principales: | Basak, Setu Kumar, Pardeshi, Tanmay, Reaves, Bradley, Williams, Laurie |
|---|---|
| Formato: | Preprint |
| Publicado: |
2025
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts
por: Basak, Setu Kumar, et al.
Publicado: (2024)
por: Basak, Setu Kumar, et al.
Publicado: (2024)
Comparing Effectiveness and Efficiency of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) Tools in a Large Java-based System
por: Seth, Aishwarya, et al.
Publicado: (2023)
por: Seth, Aishwarya, et al.
Publicado: (2023)
Verifiable Provenance of Software Artifacts with Zero-Knowledge Compilation
por: Ron, Javier, et al.
Publicado: (2026)
por: Ron, Javier, et al.
Publicado: (2026)
Automatic Selection of Protections to Mitigate Risks Against Software Applications
por: Canavese, Daniele, et al.
Publicado: (2025)
por: Canavese, Daniele, et al.
Publicado: (2025)
Building a Cybersecurity Risk Metamodel for Improved Method and Tool Integration
por: Ponsard, Christophe
Publicado: (2024)
por: Ponsard, Christophe
Publicado: (2024)
OmniBOR: A System for Automatic, Verifiable Artifact Resolution across Software Supply Chains
por: Seshadri, Bharathi, et al.
Publicado: (2024)
por: Seshadri, Bharathi, et al.
Publicado: (2024)
Toward Automated Security Risk Detection in Large Software Using Call Graph Analysis
por: Pecka, Nicholas, et al.
Publicado: (2025)
por: Pecka, Nicholas, et al.
Publicado: (2025)
How Reliable Are FOSS Popularity Metrics? Analyzing the Effort Required for Spoofing Common Software Popularity Metrics
por: Swierzy, Ben, et al.
Publicado: (2025)
por: Swierzy, Ben, et al.
Publicado: (2025)
IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
por: Rahman, Md Nafiu, et al.
Publicado: (2026)
por: Rahman, Md Nafiu, et al.
Publicado: (2026)
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
por: Kalu, Kelechi G., et al.
Publicado: (2025)
por: Kalu, Kelechi G., et al.
Publicado: (2025)
The Secret Life of CVEs
por: Przymus, Piotr, et al.
Publicado: (2025)
por: Przymus, Piotr, et al.
Publicado: (2025)
Trusting code in the wild: Exploring contributor reputation measures to review dependencies in the Rust ecosystem
por: Hamer, Sivana, et al.
Publicado: (2024)
por: Hamer, Sivana, et al.
Publicado: (2024)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
por: Rahman, Imranur, et al.
Publicado: (2024)
por: Rahman, Imranur, et al.
Publicado: (2024)
Your ATs to Ts: MITRE ATT&CK Attack Technique to P-SSCRM Task Mapping
por: Hamer, Sivana, et al.
Publicado: (2025)
por: Hamer, Sivana, et al.
Publicado: (2025)
TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications
por: Yang, Guan-Yan, et al.
Publicado: (2025)
por: Yang, Guan-Yan, et al.
Publicado: (2025)
A Security Risk Assessment Method for Distributed Ledger Technology (DLT) based Applications: Three Industry Case Studies
por: Baninemeh, Elena, et al.
Publicado: (2024)
por: Baninemeh, Elena, et al.
Publicado: (2024)
Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ Utils
por: Hamer, Sivana, et al.
Publicado: (2025)
por: Hamer, Sivana, et al.
Publicado: (2025)
RiskTagger: An LLM-based Agent for Automatic Annotation of Web3 Crypto Money Laundering Behaviors
por: Lin, Dan, et al.
Publicado: (2025)
por: Lin, Dan, et al.
Publicado: (2025)
TELSAFE: Security Gap Quantitative Risk Assessment Framework
por: Siddiqui, Sarah Ali, et al.
Publicado: (2025)
por: Siddiqui, Sarah Ali, et al.
Publicado: (2025)
On-Chain Analysis of Smart Contract Dependency Risks on Ethereum
por: Jin, Monica, et al.
Publicado: (2025)
por: Jin, Monica, et al.
Publicado: (2025)
"I Don't Use AI for Everything": Exploring Utility, Attitude, and Responsibility of AI-empowered Tools in Software Development
por: Pan, Shidong, et al.
Publicado: (2024)
por: Pan, Shidong, et al.
Publicado: (2024)
Unveiling A Hidden Risk: Exposing Educational but Malicious Repositories in GitHub
por: Masud, Md Rayhanul, et al.
Publicado: (2024)
por: Masud, Md Rayhanul, et al.
Publicado: (2024)
Evaluating Large Language Models in detecting Secrets in Android Apps
por: Alecci, Marco, et al.
Publicado: (2025)
por: Alecci, Marco, et al.
Publicado: (2025)
Understanding the Supply Chain and Risks of Large Language Model Applications
por: Ma, Yujie, et al.
Publicado: (2025)
por: Ma, Yujie, et al.
Publicado: (2025)
Out of Sight, Still at Risk: The Lifecycle of Transitive Vulnerabilities in Maven
por: Przymus, Piotr, et al.
Publicado: (2025)
por: Przymus, Piotr, et al.
Publicado: (2025)
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
por: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Publicado: (2025)
por: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Publicado: (2025)
How Far are App Secrets from Being Stolen? A Case Study on Android
por: Wei, Lili, et al.
Publicado: (2025)
por: Wei, Lili, et al.
Publicado: (2025)
A First Look at Privacy Risks of Android Task-executable Voice Assistant Applications
por: Pan, Shidong, et al.
Publicado: (2025)
por: Pan, Shidong, et al.
Publicado: (2025)
Decoding Secret Memorization in Code LLMs Through Token-Level Characterization
por: Nie, Yuqing, et al.
Publicado: (2024)
por: Nie, Yuqing, et al.
Publicado: (2024)
Automatically Detecting Checked-In Secrets in Android Apps: How Far Are We?
por: Li, Kevin, et al.
Publicado: (2024)
por: Li, Kevin, et al.
Publicado: (2024)
Software Security in Software-Defined Networking: A Systematic Literature Review
por: Diouf, Moustapha Awwalou, et al.
Publicado: (2025)
por: Diouf, Moustapha Awwalou, et al.
Publicado: (2025)
An Ontology-Based Approach to Security Risk Identification of Container Deployments in OT Contexts
por: Landeck, Yannick, et al.
Publicado: (2026)
por: Landeck, Yannick, et al.
Publicado: (2026)
Threat Modelling and Risk Analysis for Large Language Model (LLM)-Powered Applications
por: Tete, Stephen Burabari
Publicado: (2024)
por: Tete, Stephen Burabari
Publicado: (2024)
A Broad Comparative Evaluation of Software Debloating Tools
por: Brown, Michael D., et al.
Publicado: (2023)
por: Brown, Michael D., et al.
Publicado: (2023)
Towards a Benchmark for Dependency Decision-Making
por: Singla, Tanmay, et al.
Publicado: (2026)
por: Singla, Tanmay, et al.
Publicado: (2026)
Just another copy and paste? Comparing the security vulnerabilities of ChatGPT generated code and StackOverflow answers
por: Hamer, Sivana, et al.
Publicado: (2024)
por: Hamer, Sivana, et al.
Publicado: (2024)
Evaluating Software Supply Chain Security in Research Software
por: Hegewald, Richard, et al.
Publicado: (2025)
por: Hegewald, Richard, et al.
Publicado: (2025)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
por: O'Donoghue, Eric, et al.
Publicado: (2025)
por: O'Donoghue, Eric, et al.
Publicado: (2025)
SOK: Exploring Hallucinations and Security Risks in AI-Assisted Software Development with Insights for LLM Deployment
por: Haque, Ariful, et al.
Publicado: (2025)
por: Haque, Ariful, et al.
Publicado: (2025)
Gotcha! This Model Uses My Code! Evaluating Membership Leakage Risks in Code Models
por: Yang, Zhou, et al.
Publicado: (2023)
por: Yang, Zhou, et al.
Publicado: (2023)
Ejemplares similares
-
AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts
por: Basak, Setu Kumar, et al.
Publicado: (2024) -
Comparing Effectiveness and Efficiency of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) Tools in a Large Java-based System
por: Seth, Aishwarya, et al.
Publicado: (2023) -
Verifiable Provenance of Software Artifacts with Zero-Knowledge Compilation
por: Ron, Javier, et al.
Publicado: (2026) -
Automatic Selection of Protections to Mitigate Risks Against Software Applications
por: Canavese, Daniele, et al.
Publicado: (2025) -
Building a Cybersecurity Risk Metamodel for Improved Method and Tool Integration
por: Ponsard, Christophe
Publicado: (2024)