SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
Fuente:
arXiv
Saved in:
| Main Authors: | Montaruli, Biagio, Ponta, Serena Elisa, Compagna, Luca, Balzarotti, Davide |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
One Detector Fits All: Robust and Adaptive Detection of Malicious Packages from PyPI to Enterprises
by: Montaruli, Biagio, et al.
Published: (2025)
by: Montaruli, Biagio, et al.
Published: (2025)
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
by: Toda, Takaaki, et al.
Published: (2026)
by: Toda, Takaaki, et al.
Published: (2026)
Impact assessment for vulnerabilities in open-source software libraries
by: Plate, Henrik, et al.
Published: (2015)
by: Plate, Henrik, et al.
Published: (2015)
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
A Manually-Curated Dataset of Fixes to Vulnerabilities of Open-Source Software
by: Ponta, Serena E., et al.
Published: (2019)
by: Ponta, Serena E., et al.
Published: (2019)
ModSec-AdvLearn: Countering Adversarial SQL Injections with Robust Machine Learning
by: Floris, Giuseppe, et al.
Published: (2023)
by: Floris, Giuseppe, et al.
Published: (2023)
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
by: Zhang, Junan, et al.
Published: (2023)
by: Zhang, Junan, et al.
Published: (2023)
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
by: Ponta, Serena E., et al.
Published: (2018)
by: Ponta, Serena E., et al.
Published: (2018)
Bytecode-centric Detection of Known-to-be-vulnerable Dependencies in Java Projects
by: Schott, Stefan, et al.
Published: (2025)
by: Schott, Stefan, et al.
Published: (2025)
Uncovering Hidden Inclusions of Vulnerable Dependencies in Real-World Java Projects
by: Schott, Stefan, et al.
Published: (2026)
by: Schott, Stefan, et al.
Published: (2026)
Cross-ecosystem categorization: A manual-curation protocol for the categorization of Java Maven libraries along Python PyPI Topics
by: Paramitha, Ranindya, et al.
Published: (2024)
by: Paramitha, Ranindya, et al.
Published: (2024)
Automated Testing of Broken Authentication Vulnerabilities in Web APIs with AuthREST
by: Corradini, Davide, et al.
Published: (2025)
by: Corradini, Davide, et al.
Published: (2025)
A Large-scale Fine-grained Analysis of Packages in Open-Source Software Ecosystems
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
MalGuard: Towards Real-Time, Accurate, and Actionable Detection of Malicious Packages in PyPI Ecosystem
by: Gao, Xingan, et al.
Published: (2025)
by: Gao, Xingan, et al.
Published: (2025)
Broken Quantum: A Systematic Formal Verification Study of Security Vulnerabilities Across the Open-Source Quantum Computing Simulator Ecosystem
by: Blain, Dominik
Published: (2026)
by: Blain, Dominik
Published: (2026)
Sandboxing Adoption in Open Source Ecosystems
by: Alhindi, Maysara, et al.
Published: (2024)
by: Alhindi, Maysara, et al.
Published: (2024)
Finding Privacy-relevant Source Code
by: Tang, Feiyang, et al.
Published: (2024)
by: Tang, Feiyang, et al.
Published: (2024)
Detecting Protracted Vulnerabilities in Open Source Projects
by: Sridharkumar, Arjun, et al.
Published: (2026)
by: Sridharkumar, Arjun, et al.
Published: (2026)
An Analysis of Malicious Packages in Open-Source Software in the Wild
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
Tracing Vulnerability Propagation Across Open Source Software Ecosystems
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications
by: Dharmaadi, I Putu Arya, et al.
Published: (2025)
by: Dharmaadi, I Putu Arya, et al.
Published: (2025)
Unlocking Reproducibility: Automating re-Build Process for Open-Source Software
by: Hassanshahi, Behnaz, et al.
Published: (2025)
by: Hassanshahi, Behnaz, et al.
Published: (2025)
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
by: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Published: (2025)
by: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Published: (2025)
Centralized Defense: Logging and Mitigation of Kubernetes Misconfigurations with Open Source Tools
by: Russell, Eoghan, et al.
Published: (2024)
by: Russell, Eoghan, et al.
Published: (2024)
Safety Interventions against Adversarial Patches in an Open-Source Driver Assistance System
by: Chen, Cheng, et al.
Published: (2025)
by: Chen, Cheng, et al.
Published: (2025)
CodableLLM: Automating Decompiled and Source Code Mapping for LLM Dataset Generation
by: Manuel, Dylan, et al.
Published: (2025)
by: Manuel, Dylan, et al.
Published: (2025)
LLM-Driven Adaptive Source-Sink Identification and False Positive Mitigation for Static Analysis
by: Lin, Shiyin
Published: (2025)
by: Lin, Shiyin
Published: (2025)
BacAlarm: Mining and Simulating Composite API Traffic to Prevent Broken Access Control Violations
by: Yang, Yanjing, et al.
Published: (2025)
by: Yang, Yanjing, et al.
Published: (2025)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
by: Cusick, James J.
Published: (2025)
by: Cusick, James J.
Published: (2025)
The Code the World Depends On: A First Look at Technology Makers' Open Source Software Dependencies
by: Patrick, Cadence, et al.
Published: (2024)
by: Patrick, Cadence, et al.
Published: (2024)
Investigating Vulnerability Disclosures in Open-Source Software Using Bug Bounty Reports and Security Advisories
by: Ayala, Jessy, et al.
Published: (2025)
by: Ayala, Jessy, et al.
Published: (2025)
An Open Source Python Library for Anonymizing Sensitive Data
by: Díaz, Judith Sáinz-Pardo, et al.
Published: (2024)
by: Díaz, Judith Sáinz-Pardo, et al.
Published: (2024)
Detecting Malicious Source Code in PyPI Packages with LLMs: Does RAG Come in Handy?
by: Ibiyo, Motunrayo, et al.
Published: (2025)
by: Ibiyo, Motunrayo, et al.
Published: (2025)
A Deep Dive Into How Open-Source Project Maintainers Review and Resolve Bug Bounty Reports
by: Ayala, Jessy, et al.
Published: (2024)
by: Ayala, Jessy, et al.
Published: (2024)
The Auth Shim: A Lightweight Architectural Pattern for Integrating Enterprise SSO with Standalone Open-Source Applications
by: Agrawal, Yuvraj
Published: (2025)
by: Agrawal, Yuvraj
Published: (2025)
Automated Generation of Accurate Privacy Captions From Android Source Code Using Large Language Models
by: Jain, Vijayanta, et al.
Published: (2026)
by: Jain, Vijayanta, et al.
Published: (2026)
A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features
by: Ayala, Jessy, et al.
Published: (2024)
by: Ayala, Jessy, et al.
Published: (2024)
Similar Items
-
One Detector Fits All: Robust and Adaptive Detection of Malicious Packages from PyPI to Enterprises
by: Montaruli, Biagio, et al.
Published: (2025) -
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
by: Toda, Takaaki, et al.
Published: (2026) -
Impact assessment for vulnerabilities in open-source software libraries
by: Plate, Henrik, et al.
Published: (2015) -
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
by: Guo, Wenbo, et al.
Published: (2026) -
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
by: Mehedi, Sk Tanzir, et al.
Published: (2025)