An LLM-driven dependency vulnerability detector reports 83.8% precision, 73.8% recall, and 78.5% F1 on 55 Java projects, outperforming two SCA baselines.
Tracking Patches for Open Source Software Vulnerabilities
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
Open source software (OSS) vulnerabilities threaten the security of software systems that use OSS. Vulnerability databases provide valuable information (e.g., vulnerable version and patch) to mitigate OSS vulnerabilities. There arises a growing concern about the information quality of vulnerability databases. However, it is unclear what the quality of patches in existing vulnerability databases is; and existing manual or heuristic-based approaches for patch tracking are either too expensive or too specific to apply to all OSS vulnerabilities.
citation-role summary
citation-polarity summary
fields
cs.SE 1years
2025 1verdicts
CONDITIONAL 1roles
background 1polarities
background 1representative citing papers
citing papers explorer
-
SAVANT: Vulnerability Detection in Application Dependencies through Semantic-Guided Reachability Analysis
An LLM-driven dependency vulnerability detector reports 83.8% precision, 73.8% recall, and 78.5% F1 on 55 Java projects, outperforming two SCA baselines.