CodeQL detected 171 CVEs total, with 83 caught by a prior version before the fix; detections were often actionable within the vulnerable file but not stable across tool versions.
On the critical path to implant backdoors and the effectiveness of potential mitigation techniques: Early learnings from XZ
4 Pith papers cite this work. Polarity classification is still indexing.
citation-role summary
citation-polarity summary
roles
background 1polarities
background 1representative citing papers
Large-scale study shows SBOM vulnerability scanners have 92% false positives from unreachable code, cut 61.9% by adding function call analysis.
An evidence-driven protocol binds deterministic builds with TEE attestations to deliver verifiable integrity and provenance for CI artifacts without requiring consumer re-execution.
Human-Certified Module Repositories (HCMRs) are proposed as a new architectural model blending human oversight with automated analysis to certify reusable software modules for safe assembly by humans and AI agents.
citing papers explorer
-
Longitudinal Analyses of SAST Tools: A CodeQL Case Study
CodeQL detected 171 CVEs total, with 83 caught by a prior version before the fix; detections were often actionable within the vulnerable file but not stable across tool versions.
-
A Reality Check on SBOM-based Vulnerability Management: An Empirical Study and A Path Forward
Large-scale study shows SBOM vulnerability scanners have 92% false positives from unreachable code, cut 61.9% by adding function call analysis.
-
An Evidence-driven Protocol for Trustworthy CI Pipelines
An evidence-driven protocol binds deterministic builds with TEE attestations to deliver verifiable integrity and provenance for CI artifacts without requiring consumer re-execution.
-
Human-Certified Module Repositories for the AI Age
Human-Certified Module Repositories (HCMRs) are proposed as a new architectural model blending human oversight with automated analysis to certify reusable software modules for safe assembly by humans and AI agents.