Proceedings of the ACM Web Conference 2022 2022
DOI: 10.1145/3485447.3512236
|View full text |Cite
|
Sign up to set email alerts
|

Understanding the Practice of Security Patch Management across Multiple Branches in OSS Projects

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4

Citation Types

0
4
0

Year Published

2022
2022
2024
2024

Publication Types

Select...
3
1
1

Relationship

0
5

Authors

Journals

citations
Cited by 5 publications
(4 citation statements)
references
References 15 publications
0
4
0
Order By: Relevance
“…Fitzgerald et al [33] proposed a knowledge flow graph that connects libraries, files, projects, authors, and code instances together to measure the multi-facet Free/libre open source ecosystem. Tan et al [44] found that over 80% of affected CVE-Branch pairs remained unpatched in OSS projects. Xu et al [49] studied CLV issues in PyPI and Maven ecosystems, identifying 82, 951 projects dependent on vulnerable C project versions.…”
Section: Related Workmentioning
confidence: 99%
“…Fitzgerald et al [33] proposed a knowledge flow graph that connects libraries, files, projects, authors, and code instances together to measure the multi-facet Free/libre open source ecosystem. Tan et al [44] found that over 80% of affected CVE-Branch pairs remained unpatched in OSS projects. Xu et al [49] studied CLV issues in PyPI and Maven ecosystems, identifying 82, 951 projects dependent on vulnerable C project versions.…”
Section: Related Workmentioning
confidence: 99%
“…Goggins et al [3] conducted a four-year research study and provide insight into the work of the CHAOSS project, including both the metrics used as well as the open-source implementation Augur. 6 Since they elaborate on the OSS community's as well as other stakeholders' opinions (collected during their field study) regarding suitable definitions of health and sustainability, their work might prove useful for selecting and adapting our own metrics.…”
Section: Related Workmentioning
confidence: 99%
“…Various research articles [1,6] focus on the collection and provision of security-related metrics and information on open-source projects. Although the health of OSS projects comprises several different aspects, security is a vital part, affecting both integrity and sustainability.…”
Section: Related Workmentioning
confidence: 99%
“…The detection and reporting of vulnerabilities and threats in open-source software has been the subject of extensive research for several years already [6]- [8]. In a recent paper, Tan et al report the deployment of security patches on stable branches of open-source projects [9]. Similar to our approach, the authors map CVE entries based on the name of an opensource package.…”
Section: Related Workmentioning
confidence: 99%