The paper claims that merging static and dynamic call graphs improves vulnerability reachability analysis in software composition analysis, but the evaluation does not directly measure false positive reduction.
Do developers update their library dependencies?
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
citation-role summary
background 1
citation-polarity summary
fields
cs.SE 1years
2019 1verdicts
REJECT 1roles
background 1polarities
unclear 1representative citing papers
citing papers explorer
-
The Dynamics of Software Composition Analysis
The paper claims that merging static and dynamic call graphs improves vulnerability reachability analysis in software composition analysis, but the evaluation does not directly measure false positive reduction.