VulGuard: An Unified Tool for Evaluating Just-In-Time Vulnerability Prediction Models
Fuente:
arXiv
Salvato in:
| Autori principali: | , , , , , |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2025
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866915405073743872 |
|---|---|
| author | Nguyen, Duong Tran-Duc, Manh Le-Cong, Thanh Le, Triet Huynh Minh Babar, M. Ali Huynh, Quyet-Thang |
| author_facet | Nguyen, Duong Tran-Duc, Manh Le-Cong, Thanh Le, Triet Huynh Minh Babar, M. Ali Huynh, Quyet-Thang |
| contents | We present VulGuard, an automated tool designed to streamline the extraction, processing, and analysis of commits from GitHub repositories for Just-In-Time vulnerability prediction (JIT-VP) research. VulGuard automatically mines commit histories, extracts fine-grained code changes, commit messages, and software engineering metrics, and formats them for downstream analysis. In addition, it integrates several state-of-the-art vulnerability prediction models, allowing researchers to train, evaluate, and compare models with minimal setup. By supporting both repository-scale mining and model-level experimentation within a unified framework, VulGuard addresses key challenges in reproducibility and scalability in software security research. VulGuard can also be easily integrated into the CI/CD pipeline. We demonstrate the effectiveness of the tool in two influential open-source projects, FFmpeg and the Linux kernel, highlighting its potential to accelerate real-world JIT-VP research and promote standardized benchmarking. A demo video is available at: https://youtu.be/j96096-pxbs |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2507_16685 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | VulGuard: An Unified Tool for Evaluating Just-In-Time Vulnerability Prediction Models Nguyen, Duong Tran-Duc, Manh Le-Cong, Thanh Le, Triet Huynh Minh Babar, M. Ali Huynh, Quyet-Thang Software Engineering We present VulGuard, an automated tool designed to streamline the extraction, processing, and analysis of commits from GitHub repositories for Just-In-Time vulnerability prediction (JIT-VP) research. VulGuard automatically mines commit histories, extracts fine-grained code changes, commit messages, and software engineering metrics, and formats them for downstream analysis. In addition, it integrates several state-of-the-art vulnerability prediction models, allowing researchers to train, evaluate, and compare models with minimal setup. By supporting both repository-scale mining and model-level experimentation within a unified framework, VulGuard addresses key challenges in reproducibility and scalability in software security research. VulGuard can also be easily integrated into the CI/CD pipeline. We demonstrate the effectiveness of the tool in two influential open-source projects, FFmpeg and the Linux kernel, highlighting its potential to accelerate real-world JIT-VP research and promote standardized benchmarking. A demo video is available at: https://youtu.be/j96096-pxbs |
| title | VulGuard: An Unified Tool for Evaluating Just-In-Time Vulnerability Prediction Models |
| topic | Software Engineering |
| url | https://arxiv.org/abs/2507.16685 |