Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue Management
Fuente:
arXiv
Saved in:
| Main Authors: | Zhang, Lyuye, Wu, Jiahui, Liu, Chengwei, Li, Kaixuan, Sun, Xiaoyu, Zhao, Lida, Wang, Chong, Liu, Yang |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
VFArchē: A Dual-Mode Framework for Locating Vulnerable Functions in Open-Source Software
by: Zhang, Lyuye, et al.
Published: (2025)
by: Zhang, Lyuye, et al.
Published: (2025)
Detecting Essence Code Clones via Information Theoretic Analysis
by: Zhao, Lida, et al.
Published: (2025)
by: Zhao, Lida, et al.
Published: (2025)
Drop the Golden Apples: Identifying Third-Party Reuse by DB-Less Software Composition Analysis
by: Zhang, Lyuye, et al.
Published: (2025)
by: Zhang, Lyuye, et al.
Published: (2025)
JC-Finder: Detecting Java Clone-based Third-Party Library by Class-level Tree Analysis
by: Zhao, Lida, et al.
Published: (2025)
by: Zhao, Lida, et al.
Published: (2025)
Uncovering and Mitigating the Impact of Frozen Package Versions for Fixed-Release Linux
by: Tang, Wei, et al.
Published: (2024)
by: Tang, Wei, et al.
Published: (2024)
Empirical Analysis of Vulnerabilities Life Cycle in Golang Ecosystem
by: Hu, Jinchang, et al.
Published: (2023)
by: Hu, Jinchang, et al.
Published: (2023)
ACFIX: Guiding LLMs with Mined Common RBAC Practices for Context-Aware Repair of Access Control Vulnerabilities in Smart Contracts
by: Zhang, Lyuye, et al.
Published: (2024)
by: Zhang, Lyuye, et al.
Published: (2024)
Open Source, Hidden Costs: A Systematic Literature Review on OSS License Management
by: Li, Boyuan, et al.
Published: (2025)
by: Li, Boyuan, et al.
Published: (2025)
Minimizing Breaking Changes and Redundancy in Mitigating Technical Lag for Java Projects
by: Lu, Rui, et al.
Published: (2025)
by: Lu, Rui, et al.
Published: (2025)
A Systematic Study on Generating Web Vulnerability Proof-of-Concepts Using Large Language Models
by: Zhao, Mengyao, et al.
Published: (2025)
by: Zhao, Mengyao, et al.
Published: (2025)
PatchFinder: A Two-Phase Approach to Security Patch Tracing for Disclosed Vulnerabilities in Open-Source Software
by: Li, Kaixuan, et al.
Published: (2024)
by: Li, Kaixuan, et al.
Published: (2024)
SkillClone: Multi-Modal Clone Detection and Clone Propagation Analysis in the Agent Skill Ecosystem
by: Zhu, Jiaying, et al.
Published: (2026)
by: Zhu, Jiaying, et al.
Published: (2026)
Real-World Usability of Vulnerability Proof-of-Concepts: A Comprehensive Study
by: Dang, Wenjing, et al.
Published: (2025)
by: Dang, Wenjing, et al.
Published: (2025)
LLMs Meet Library Evolution: Evaluating Deprecated API Usage in LLM-based Code Completion
by: Wang, Chong, et al.
Published: (2024)
by: Wang, Chong, et al.
Published: (2024)
IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Package Information from Cyber Intelligence
by: Guo, Wenbo, et al.
Published: (2024)
by: Guo, Wenbo, et al.
Published: (2024)
An Empirical Study of Security-Policy Related Issues in Open Source Projects
by: Kanaji, Rintaro, et al.
Published: (2025)
by: Kanaji, Rintaro, et al.
Published: (2025)
A Taxonomy of Prompt Defects in LLM Systems
by: Tian, Haoye, et al.
Published: (2025)
by: Tian, Haoye, et al.
Published: (2025)
Fixseeker: An Empirical Driven Graph-based Approach for Detecting Silent Vulnerability Fixes in Open Source Software
by: Cheng, Yiran, et al.
Published: (2025)
by: Cheng, Yiran, et al.
Published: (2025)
Evolaris: A Roadmap to Self-Evolving Software Intelligence Management
by: Liu, Chengwei, et al.
Published: (2025)
by: Liu, Chengwei, et al.
Published: (2025)
Static Application Security Testing (SAST) Tools for Smart Contracts: How Far Are We?
by: Li, Kaixuan, et al.
Published: (2024)
by: Li, Kaixuan, et al.
Published: (2024)
Catch the Butterfly: Peeking into the Terms and Conflicts among SPDX Licenses
by: Liu, Tao, et al.
Published: (2024)
by: Liu, Tao, et al.
Published: (2024)
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
Understanding Open Source Contributor Profiles in Popular Machine Learning Libraries
by: Liu, Jiawen, et al.
Published: (2024)
by: Liu, Jiawen, et al.
Published: (2024)
From Docs to Descriptions: Smell-Aware Evaluation of MCP Server Descriptions
by: Wang, Peiran, et al.
Published: (2026)
by: Wang, Peiran, et al.
Published: (2026)
LLM4Vuln: A Unified Evaluation Framework for Decoupling and Enhancing LLMs' Vulnerability Reasoning
by: Sun, Yuqiang, et al.
Published: (2024)
by: Sun, Yuqiang, et al.
Published: (2024)
On Categorizing Open Source Software Security Vulnerability Reporting Mechanisms on GitHub
by: Kancharoendee, Sushawapak, et al.
Published: (2025)
by: Kancharoendee, Sushawapak, et al.
Published: (2025)
Fixing Security Vulnerabilities with AI in OSS-Fuzz
by: Zhang, Yuntong, et al.
Published: (2024)
by: Zhang, Yuntong, et al.
Published: (2024)
Unicorns Do Not Exist: Employing and Appreciating Community Managers in Open Source
by: Sonabend, Raphael, et al.
Published: (2024)
by: Sonabend, Raphael, et al.
Published: (2024)
EASELAN: An Open-Source Framework for Multimodal Biosignal Annotation and Data Management
by: Rammohan, Rathi Adarshi, et al.
Published: (2025)
by: Rammohan, Rathi Adarshi, et al.
Published: (2025)
Can Highlighting Help GitHub Maintainers Track Security Fixes?
by: Liu, Xueqing, et al.
Published: (2024)
by: Liu, Xueqing, et al.
Published: (2024)
Systematic Literature Review of Commercial Participation in Open Source Software
by: Li, Xuetao, et al.
Published: (2024)
by: Li, Xuetao, et al.
Published: (2024)
A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features
by: Ayala, Jessy, et al.
Published: (2024)
by: Ayala, Jessy, et al.
Published: (2024)
Seeing is Fixing: Cross-Modal Reasoning with Multimodal LLMs for Visual Software Issue Fixing
by: Huang, Kai, et al.
Published: (2025)
by: Huang, Kai, et al.
Published: (2025)
On the Flakiness of LLM-Generated Tests for Industrial and Open-Source Database Management Systems
by: Berndt, Alexander, et al.
Published: (2026)
by: Berndt, Alexander, et al.
Published: (2026)
A Large-scale Investigation of Semantically Incompatible APIs behind Compatibility Issues in Android Apps
by: Pan, Shidong, et al.
Published: (2024)
by: Pan, Shidong, et al.
Published: (2024)
Managing Security Issues in Software Containers: From Practitioners Perspective
by: Sroor, Maha, et al.
Published: (2025)
by: Sroor, Maha, et al.
Published: (2025)
CoReQA: Uncovering Potentials of Language Models in Code Repository Question Answering
by: Chen, Jialiang, et al.
Published: (2025)
by: Chen, Jialiang, et al.
Published: (2025)
A Comparative Study of Android Performance Issues in Real-world Applications and Literature
by: Liao, Dianshu, et al.
Published: (2024)
by: Liao, Dianshu, et al.
Published: (2024)
CommitShield: Tracking Vulnerability Introduction and Fix in Version Control Systems
by: Wu, Zhaonan, et al.
Published: (2025)
by: Wu, Zhaonan, et al.
Published: (2025)
How to Gain Commit Rights in Modern Top Open Source Communities?
by: Tan, Xin, et al.
Published: (2024)
by: Tan, Xin, et al.
Published: (2024)
Similar Items
-
VFArchē: A Dual-Mode Framework for Locating Vulnerable Functions in Open-Source Software
by: Zhang, Lyuye, et al.
Published: (2025) -
Detecting Essence Code Clones via Information Theoretic Analysis
by: Zhao, Lida, et al.
Published: (2025) -
Drop the Golden Apples: Identifying Third-Party Reuse by DB-Less Software Composition Analysis
by: Zhang, Lyuye, et al.
Published: (2025) -
JC-Finder: Detecting Java Clone-based Third-Party Library by Class-level Tree Analysis
by: Zhao, Lida, et al.
Published: (2025) -
Uncovering and Mitigating the Impact of Frozen Package Versions for Fixed-Release Linux
by: Tang, Wei, et al.
Published: (2024)