Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
Fuente:
arXiv
Guardado en:
| Autores principales: | Ruan, Bonan, Fu, Yeqi, Zhang, Chuqi, Liu, Jiahao, Zeng, Jun, Liang, Zhenkai |
|---|---|
| Formato: | Preprint |
| Publicado: |
2026
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
por: Ruan, Bonan, et al.
Publicado: (2024)
por: Ruan, Bonan, et al.
Publicado: (2024)
Unpacking Security Scanners for GitHub Actions Workflows
por: Fares, Madjda, et al.
Publicado: (2026)
por: Fares, Madjda, et al.
Publicado: (2026)
Characterizing and Modeling the GitHub Security Advisories Review Pipeline
por: Segal, Claudio, et al.
Publicado: (2026)
por: Segal, Claudio, et al.
Publicado: (2026)
On the effectiveness of Large Language Models for GitHub Workflows
por: Zhang, Xinyu, et al.
Publicado: (2024)
por: Zhang, Xinyu, et al.
Publicado: (2024)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
por: Ruan, Bonan, et al.
Publicado: (2025)
por: Ruan, Bonan, et al.
Publicado: (2025)
Security Weaknesses of Copilot-Generated Code in GitHub Projects: An Empirical Study
por: Fu, Yujia, et al.
Publicado: (2023)
por: Fu, Yujia, et al.
Publicado: (2023)
VulZoo: A Comprehensive Vulnerability Intelligence Dataset
por: Ruan, Bonan, et al.
Publicado: (2024)
por: Ruan, Bonan, et al.
Publicado: (2024)
Can Highlighting Help GitHub Maintainers Track Security Fixes?
por: Liu, Xueqing, et al.
Publicado: (2024)
por: Liu, Xueqing, et al.
Publicado: (2024)
LLM-Enabled Open-Source Systems in the Wild: An Empirical Study of Vulnerabilities in GitHub Security Advisories
por: Shifat, Fariha Tanjim, et al.
Publicado: (2026)
por: Shifat, Fariha Tanjim, et al.
Publicado: (2026)
Unveiling A Hidden Risk: Exposing Educational but Malicious Repositories in GitHub
por: Masud, Md Rayhanul, et al.
Publicado: (2024)
por: Masud, Md Rayhanul, et al.
Publicado: (2024)
Security in the Age of AI Teammates: An Empirical Study of Agentic Pull Requests on GitHub
por: Siddiq, Mohammed Latif, et al.
Publicado: (2026)
por: Siddiq, Mohammed Latif, et al.
Publicado: (2026)
When MCP Servers Attack: Taxonomy, Feasibility, and Mitigation
por: Zhao, Weibo, et al.
Publicado: (2025)
por: Zhao, Weibo, et al.
Publicado: (2025)
Is GitHub's Copilot as Bad as Humans at Introducing Vulnerabilities in Code?
por: Asare, Owura, et al.
Publicado: (2022)
por: Asare, Owura, et al.
Publicado: (2022)
Exploring User Privacy Awareness on GitHub: An Empirical Study
por: Alfieri, Costanza, et al.
Publicado: (2024)
por: Alfieri, Costanza, et al.
Publicado: (2024)
Bugdar: AI-Augmented Secure Code Review for GitHub Pull Requests
por: Naulty, John, et al.
Publicado: (2025)
por: Naulty, John, et al.
Publicado: (2025)
On the Prevalence and Usage of Commit Signing on GitHub: A Longitudinal and Cross-Domain Study
por: Sharma, Anupam, et al.
Publicado: (2025)
por: Sharma, Anupam, et al.
Publicado: (2025)
IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
por: Rahman, Md Nafiu, et al.
Publicado: (2026)
por: Rahman, Md Nafiu, et al.
Publicado: (2026)
Six Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware
por: He, Hao, et al.
Publicado: (2024)
por: He, Hao, et al.
Publicado: (2024)
Security Concerns in Generative AI Coding Assistants: Insights from Online Discussions on GitHub Copilot
por: Ferreyra, Nicolás E. Díaz, et al.
Publicado: (2026)
por: Ferreyra, Nicolás E. Díaz, et al.
Publicado: (2026)
Demystifying and Detecting Agentic Workflow Injection Vulnerabilities in GitHub Actions
por: Wang, Shenao, et al.
Publicado: (2026)
por: Wang, Shenao, et al.
Publicado: (2026)
Automating the Detection of Code Vulnerabilities by Analyzing GitHub Issues
por: Cipollone, Daniele, et al.
Publicado: (2025)
por: Cipollone, Daniele, et al.
Publicado: (2025)
Fuzzing the PHP Interpreter via Dataflow Fusion
por: Jiang, Yuancheng, et al.
Publicado: (2024)
por: Jiang, Yuancheng, et al.
Publicado: (2024)
TraceAegis: Securing LLM-Based Agents via Hierarchical and Behavioral Anomaly Detection
por: Liu, Jiahao, et al.
Publicado: (2025)
por: Liu, Jiahao, et al.
Publicado: (2025)
Granite: Granular Runtime Enforcement for GitHub Actions Permissions
por: Moazen, Mojtaba, et al.
Publicado: (2025)
por: Moazen, Mojtaba, et al.
Publicado: (2025)
Security Vulnerabilities in AI-Generated Code: A Large-Scale Analysis of Public GitHub Repositories
por: Schreiber, Maximilian, et al.
Publicado: (2025)
por: Schreiber, Maximilian, et al.
Publicado: (2025)
MASKDROID: Robust Android Malware Detection with Masked Graph Representations
por: Zheng, Jingnan, et al.
Publicado: (2024)
por: Zheng, Jingnan, et al.
Publicado: (2024)
Decoupling Identity from Access: Credential Broker Patterns for Secure CI/CD
por: Avirneni, Surya Teja
Publicado: (2025)
por: Avirneni, Surya Teja
Publicado: (2025)
Eradicating the Unseen: Detecting, Exploiting, and Remediating a Path Traversal Vulnerability across GitHub
por: Akhoundali, Jafar, et al.
Publicado: (2025)
por: Akhoundali, Jafar, et al.
Publicado: (2025)
DevOps-Gym: Benchmarking AI Agents in Software DevOps Cycle
por: Tang, Yuheng, et al.
Publicado: (2026)
por: Tang, Yuheng, et al.
Publicado: (2026)
Exploring the Impact of Integrating UI Testing in CI/CD Workflows on GitHub
por: Gan, Xiaoxiao, et al.
Publicado: (2025)
por: Gan, Xiaoxiao, et al.
Publicado: (2025)
Generating API Parameter Security Rules with LLM for API Misuse Detection
por: Liu, Jinghua, et al.
Publicado: (2024)
por: Liu, Jinghua, et al.
Publicado: (2024)
Enhancing Security of AI-Based Code Synthesis with GitHub Copilot via Cheap and Efficient Prompt-Engineering
por: Res, Jakub, et al.
Publicado: (2024)
por: Res, Jakub, et al.
Publicado: (2024)
Intent-Aware Authorization for Zero Trust CI/CD
por: Avirneni, Surya Teja
Publicado: (2025)
por: Avirneni, Surya Teja
Publicado: (2025)
Toward Automated Security Risk Detection in Large Software Using Call Graph Analysis
por: Pecka, Nicholas, et al.
Publicado: (2025)
por: Pecka, Nicholas, et al.
Publicado: (2025)
Reinforcement Learning-Driven Adaptation Chains: A Robust Framework for Multi-Cloud Workflow Security
por: Soveizi, Nafiseh, et al.
Publicado: (2025)
por: Soveizi, Nafiseh, et al.
Publicado: (2025)
Integrating Log-Based Security Analytics in Agile Workflows: A Real-World Experience Report
por: Thool, Arpit, et al.
Publicado: (2026)
por: Thool, Arpit, et al.
Publicado: (2026)
LLM Security Guard for Code
por: Kavian, Arya, et al.
Publicado: (2024)
por: Kavian, Arya, et al.
Publicado: (2024)
SIR-Bench: Evaluating Investigation Depth in Security Incident Response Agents
por: Begimher, Daniel, et al.
Publicado: (2026)
por: Begimher, Daniel, et al.
Publicado: (2026)
A Large-Scale Evolvable Dataset for Model Context Protocol Ecosystem and Security Analysis
por: Lin, Zhiwei, et al.
Publicado: (2025)
por: Lin, Zhiwei, et al.
Publicado: (2025)
ChainFuzzer: Greybox Fuzzing for Workflow-Level Multi-Tool Vulnerabilities in LLM Agents
por: Wu, Jiangrong, et al.
Publicado: (2026)
por: Wu, Jiangrong, et al.
Publicado: (2026)
Ejemplares similares
-
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
por: Ruan, Bonan, et al.
Publicado: (2024) -
Unpacking Security Scanners for GitHub Actions Workflows
por: Fares, Madjda, et al.
Publicado: (2026) -
Characterizing and Modeling the GitHub Security Advisories Review Pipeline
por: Segal, Claudio, et al.
Publicado: (2026) -
On the effectiveness of Large Language Models for GitHub Workflows
por: Zhang, Xinyu, et al.
Publicado: (2024) -
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
por: Ruan, Bonan, et al.
Publicado: (2025)