VulGuard: An Unified Tool for Evaluating Just-In-Time Vulnerability Prediction Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Nguyen, Duong, Tran-Duc, Manh, Le-Cong, Thanh, Le, Triet Huynh Minh, Babar, M. Ali, Huynh, Quyet-Thang
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915405073743872
author Nguyen, Duong
Tran-Duc, Manh
Le-Cong, Thanh
Le, Triet Huynh Minh
Babar, M. Ali
Huynh, Quyet-Thang
author_facet Nguyen, Duong
Tran-Duc, Manh
Le-Cong, Thanh
Le, Triet Huynh Minh
Babar, M. Ali
Huynh, Quyet-Thang
contents We present VulGuard, an automated tool designed to streamline the extraction, processing, and analysis of commits from GitHub repositories for Just-In-Time vulnerability prediction (JIT-VP) research. VulGuard automatically mines commit histories, extracts fine-grained code changes, commit messages, and software engineering metrics, and formats them for downstream analysis. In addition, it integrates several state-of-the-art vulnerability prediction models, allowing researchers to train, evaluate, and compare models with minimal setup. By supporting both repository-scale mining and model-level experimentation within a unified framework, VulGuard addresses key challenges in reproducibility and scalability in software security research. VulGuard can also be easily integrated into the CI/CD pipeline. We demonstrate the effectiveness of the tool in two influential open-source projects, FFmpeg and the Linux kernel, highlighting its potential to accelerate real-world JIT-VP research and promote standardized benchmarking. A demo video is available at: https://youtu.be/j96096-pxbs
format Preprint
id arxiv_https___arxiv_org_abs_2507_16685
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle VulGuard: An Unified Tool for Evaluating Just-In-Time Vulnerability Prediction Models
Nguyen, Duong
Tran-Duc, Manh
Le-Cong, Thanh
Le, Triet Huynh Minh
Babar, M. Ali
Huynh, Quyet-Thang
Software Engineering
We present VulGuard, an automated tool designed to streamline the extraction, processing, and analysis of commits from GitHub repositories for Just-In-Time vulnerability prediction (JIT-VP) research. VulGuard automatically mines commit histories, extracts fine-grained code changes, commit messages, and software engineering metrics, and formats them for downstream analysis. In addition, it integrates several state-of-the-art vulnerability prediction models, allowing researchers to train, evaluate, and compare models with minimal setup. By supporting both repository-scale mining and model-level experimentation within a unified framework, VulGuard addresses key challenges in reproducibility and scalability in software security research. VulGuard can also be easily integrated into the CI/CD pipeline. We demonstrate the effectiveness of the tool in two influential open-source projects, FFmpeg and the Linux kernel, highlighting its potential to accelerate real-world JIT-VP research and promote standardized benchmarking. A demo video is available at: https://youtu.be/j96096-pxbs
title VulGuard: An Unified Tool for Evaluating Just-In-Time Vulnerability Prediction Models
topic Software Engineering
url https://arxiv.org/abs/2507.16685