Towards a Benchmark for Dependency Decision-Making
Fuente:
arXiv
Salvato in:
| Autori principali: | Singla, Tanmay, Çakar, Berk, Amusuo, Paschal C., Davis, James C. |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2026
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
Towards the Systematic Testing of Regular Expression Engines
di: Çakar, Berk, et al.
Pubblicazione: (2026)
di: Çakar, Berk, et al.
Pubblicazione: (2026)
A Guide to Stakeholder Analysis for Cybersecurity Researchers
di: Davis, James C, et al.
Pubblicazione: (2025)
di: Davis, James C, et al.
Pubblicazione: (2025)
ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale
di: Jiang, Wenxin, et al.
Pubblicazione: (2025)
di: Jiang, Wenxin, et al.
Pubblicazione: (2025)
ZTD$_{JAVA}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies
di: Amusuo, Paschal C., et al.
Pubblicazione: (2023)
di: Amusuo, Paschal C., et al.
Pubblicazione: (2023)
SoK: A Literature and Engineering Review of Regular Expression Denial of Service (ReDoS)
di: Bhuiyan, Masudul Hasan Masud, et al.
Pubblicazione: (2024)
di: Bhuiyan, Masudul Hasan Masud, et al.
Pubblicazione: (2024)
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
An Industry Interview Study of Software Signing for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2024)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2024)
AutoSOUP: Safety-Oriented Unit Proof Generation for Component-level Memory-Safety Verification
di: Amusuo, Paschal C., et al.
Pubblicazione: (2026)
di: Amusuo, Paschal C., et al.
Pubblicazione: (2026)
FalseCrashReducer: Mitigating False Positive Crashes in OSS-Fuzz-Gen Using Agentic AI
di: Amusuo, Paschal C., et al.
Pubblicazione: (2025)
di: Amusuo, Paschal C., et al.
Pubblicazione: (2025)
Introducing Systems Thinking as a Framework for Teaching and Assessing Threat Modeling Competency
di: Joshi, Siddhant S., et al.
Pubblicazione: (2024)
di: Joshi, Siddhant S., et al.
Pubblicazione: (2024)
An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland Security
di: Maxam III, William P., et al.
Pubblicazione: (2024)
di: Maxam III, William P., et al.
Pubblicazione: (2024)
DiVerify: Hardening Identity-Based Software Signing with Diverse-Context Scopes
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
Reactive Bottom-Up Testing
di: Muralee, Siddharth, et al.
Pubblicazione: (2025)
di: Muralee, Siddharth, et al.
Pubblicazione: (2025)
RiskHarvester: A Risk-based Tool to Prioritize Secret Removal Efforts in Software Artifacts
di: Basak, Setu Kumar, et al.
Pubblicazione: (2025)
di: Basak, Setu Kumar, et al.
Pubblicazione: (2025)
A Longitudinal Study of Usability in Identity-Based Software Signing
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
Operationalizing Research Software for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
Finding 709 Defects in 258 Projects: An Experience Report on Applying CodeQL to Open-Source Embedded Software (Experience Paper) -- Extended Report
di: Shen, Mingjie, et al.
Pubblicazione: (2023)
di: Shen, Mingjie, et al.
Pubblicazione: (2023)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
di: Schorlemmer, Taylor R., et al.
Pubblicazione: (2024)
di: Schorlemmer, Taylor R., et al.
Pubblicazione: (2024)
FirmReBugger: A Benchmark Framework for Monolithic Firmware Fuzzers
di: Duong, Mathew, et al.
Pubblicazione: (2026)
di: Duong, Mathew, et al.
Pubblicazione: (2026)
The Code the World Depends On: A First Look at Technology Makers' Open Source Software Dependencies
di: Patrick, Cadence, et al.
Pubblicazione: (2024)
di: Patrick, Cadence, et al.
Pubblicazione: (2024)
Visualisation for the CIS benchmark scanning results
di: Zhao, Zhenshuo, et al.
Pubblicazione: (2025)
di: Zhao, Zhenshuo, et al.
Pubblicazione: (2025)
What Makes a Good LLM Agent for Real-world Penetration Testing?
di: Deng, Gelei, et al.
Pubblicazione: (2026)
di: Deng, Gelei, et al.
Pubblicazione: (2026)
Classport: Designing Runtime Dependency Introspection for Java
di: Cofano, Serena, et al.
Pubblicazione: (2025)
di: Cofano, Serena, et al.
Pubblicazione: (2025)
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
di: Schorlemmer, Taylor R, et al.
Pubblicazione: (2024)
di: Schorlemmer, Taylor R, et al.
Pubblicazione: (2024)
Profile of Vulnerability Remediations in Dependencies Using Graph Analysis
di: Vera, Fernando, et al.
Pubblicazione: (2024)
di: Vera, Fernando, et al.
Pubblicazione: (2024)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
di: Liu, Shuhan, et al.
Pubblicazione: (2025)
di: Liu, Shuhan, et al.
Pubblicazione: (2025)
On-Chain Analysis of Smart Contract Dependency Risks on Ethereum
di: Jin, Monica, et al.
Pubblicazione: (2025)
di: Jin, Monica, et al.
Pubblicazione: (2025)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
di: Rahman, Imranur, et al.
Pubblicazione: (2024)
di: Rahman, Imranur, et al.
Pubblicazione: (2024)
Bytecode-centric Detection of Known-to-be-vulnerable Dependencies in Java Projects
di: Schott, Stefan, et al.
Pubblicazione: (2025)
di: Schott, Stefan, et al.
Pubblicazione: (2025)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
di: Schmid, Larissa, et al.
Pubblicazione: (2026)
di: Schmid, Larissa, et al.
Pubblicazione: (2026)
Uncovering Hidden Inclusions of Vulnerable Dependencies in Real-World Java Projects
di: Schott, Stefan, et al.
Pubblicazione: (2026)
di: Schott, Stefan, et al.
Pubblicazione: (2026)
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
di: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Pubblicazione: (2025)
di: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Pubblicazione: (2025)
Enhancing Android Malware Detection: The Influence of ChatGPT on Decision-centric Task
di: Li, Yao, et al.
Pubblicazione: (2024)
di: Li, Yao, et al.
Pubblicazione: (2024)
SAVANT: Vulnerability Detection in Application Dependencies through Semantic-Guided Reachability Analysis
di: Lingxiang, Wang, et al.
Pubblicazione: (2025)
di: Lingxiang, Wang, et al.
Pubblicazione: (2025)
Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
di: Swierzy, Ben, et al.
Pubblicazione: (2025)
di: Swierzy, Ben, et al.
Pubblicazione: (2025)
zkRansomware: Proof-of-Data Recoverability and Multi-round Game Theoretic Modeling of Ransomware Decisions
di: Hou, Xinyu, et al.
Pubblicazione: (2026)
di: Hou, Xinyu, et al.
Pubblicazione: (2026)
SafeToolBench: Pioneering a Prospective Benchmark to Evaluating Tool Utilization Safety in LLMs
di: Xia, Hongfei, et al.
Pubblicazione: (2025)
di: Xia, Hongfei, et al.
Pubblicazione: (2025)
NESSiE: The Necessary Safety Benchmark -- Identifying Errors that should not Exist
di: Bertram, Johannes, et al.
Pubblicazione: (2026)
di: Bertram, Johannes, et al.
Pubblicazione: (2026)
Documenti analoghi
-
Towards the Systematic Testing of Regular Expression Engines
di: Çakar, Berk, et al.
Pubblicazione: (2026) -
A Guide to Stakeholder Analysis for Cybersecurity Researchers
di: Davis, James C, et al.
Pubblicazione: (2025) -
ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale
di: Jiang, Wenxin, et al.
Pubblicazione: (2025) -
ZTD$_{JAVA}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies
di: Amusuo, Paschal C., et al.
Pubblicazione: (2023) -
SoK: A Literature and Engineering Review of Regular Expression Denial of Service (ReDoS)
di: Bhuiyan, Masudul Hasan Masud, et al.
Pubblicazione: (2024)