论文标题
用于测量开源软件包中的脆弱性和暴露
Towards Measuring Vulnerabilities and Exposures in Open-Source Packages
论文作者
论文摘要
当前的许多软件都取决于开源组件,而开源组件又对其他开源库具有复杂的依赖性。因此,开源中的漏洞可能会产生巨大影响。这项工作的目的是定量概述流行软件存储库和软件包管理人员中现有漏洞的频率和演变。为此,我们提供了开源景观及其最受欢迎的软件包经理的最新概述,我们讨论了将常见漏洞和暴露列表(CVE)列表(CVE)列表的条目映射到开源库的方法,并显示了与流行的编程语言相对于现有CVE条目的频率和分布。
Much of the current software depends on open-source components, which in turn have complex dependencies on other open-source libraries. Vulnerabilities in open source therefore have potentially huge impacts. The goal of this work is to get a quantitative overview of the frequency and evolution of existing vulnerabilities in popular software repositories and package managers. To this end, we provide an up-to-date overview of the open source landscape and its most popular package managers, we discuss approaches to map entries of the Common Vulnerabilities and Exposures (CVE) list to open-source libraries and we show the frequency and distribution of existing CVE entries with respect to popular programming languages.