Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue Management

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Lyuye, Wu, Jiahui, Liu, Chengwei, Li, Kaixuan, Sun, Xiaoyu, Zhao, Lida, Wang, Chong, Liu, Yang
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913766449348608
author Zhang, Lyuye
Wu, Jiahui
Liu, Chengwei
Li, Kaixuan
Sun, Xiaoyu
Zhao, Lida
Wang, Chong
Liu, Yang
author_facet Zhang, Lyuye
Wu, Jiahui
Liu, Chengwei
Li, Kaixuan
Sun, Xiaoyu
Zhao, Lida
Wang, Chong
Liu, Yang
contents In the rapidly evolving landscape of software development, addressing security vulnerabilities in open-source software (OSS) has become critically important. However, existing research and tools from both academia and industry mainly relied on limited solutions, such as vulnerable version adjustment and adopting patches, to handle identified vulnerabilities. However, far more flexible and diverse countermeasures have been actively adopted in the open-source communities. A holistic empirical study is needed to explore the prevalence, distribution, preferences, and effectiveness of these diverse strategies. To this end, in this paper, we conduct a comprehensive study on the taxonomy of vulnerability remediation tactics (RT) in OSS projects and investigate their pros and cons. This study addresses this oversight by conducting a comprehensive empirical analysis of 21,187 issues from GitHub, aiming to understand the range and efficacy of remediation tactics within the OSS community. We developed a hierarchical taxonomy of 44 distinct RT and evaluated their effectiveness and costs. Our findings highlight a significant reliance on community-driven strategies, like using alternative libraries and bypassing vulnerabilities, 44% of which are currently unsupported by cutting-edge tools. Additionally, this research exposes the community's preferences for certain fixing approaches by analyzing their acceptance and the reasons for rejection. It also underscores a critical gap in modern vulnerability databases, where 54% of CVEs lack fixing suggestions, a gap that can be significantly mitigated by leveraging the 93% of actionable solutions provided through GitHub issues.
format Preprint
id arxiv_https___arxiv_org_abs_2503_23357
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue Management
Zhang, Lyuye
Wu, Jiahui
Liu, Chengwei
Li, Kaixuan
Sun, Xiaoyu
Zhao, Lida
Wang, Chong
Liu, Yang
Software Engineering
In the rapidly evolving landscape of software development, addressing security vulnerabilities in open-source software (OSS) has become critically important. However, existing research and tools from both academia and industry mainly relied on limited solutions, such as vulnerable version adjustment and adopting patches, to handle identified vulnerabilities. However, far more flexible and diverse countermeasures have been actively adopted in the open-source communities. A holistic empirical study is needed to explore the prevalence, distribution, preferences, and effectiveness of these diverse strategies. To this end, in this paper, we conduct a comprehensive study on the taxonomy of vulnerability remediation tactics (RT) in OSS projects and investigate their pros and cons. This study addresses this oversight by conducting a comprehensive empirical analysis of 21,187 issues from GitHub, aiming to understand the range and efficacy of remediation tactics within the OSS community. We developed a hierarchical taxonomy of 44 distinct RT and evaluated their effectiveness and costs. Our findings highlight a significant reliance on community-driven strategies, like using alternative libraries and bypassing vulnerabilities, 44% of which are currently unsupported by cutting-edge tools. Additionally, this research exposes the community's preferences for certain fixing approaches by analyzing their acceptance and the reasons for rejection. It also underscores a critical gap in modern vulnerability databases, where 54% of CVEs lack fixing suggestions, a gap that can be significantly mitigated by leveraging the 93% of actionable solutions provided through GitHub issues.
title Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue Management
topic Software Engineering
url https://arxiv.org/abs/2503.23357