SunLab-GMU / PySecDBLinks
The official repository of ICSME'23 paper "Exploring Security Commits in Python"
☆18Updated 2 years ago
Alternatives and similar repositories for PySecDB
Users that are interested in PySecDB are comparing it to the libraries listed below
Sorting:
- A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and o…☆79Updated last week
- VulZoo: A Comprehensive Vulnerability Intelligence Dataset | ASE 2024 Demo☆65Updated 7 months ago
- OSS-Fuzz vulnerabilities for OSV.☆166Updated this week
- ☆51Updated last year
- Data about all known supply-chain attacks through history☆61Updated 5 months ago
- VFCFinder: Searching for the Missing Vulnerability Fixing Commits☆30Updated last year
- Home page of project "KB"☆130Updated 7 months ago
- ☆26Updated 2 years ago
- Statically Detecting Vulnerable Data Flows in Browser Extensions at Scale☆77Updated 3 years ago
- An ever-growing list of resources for data-driven vulnerability assessment and prioritization☆129Updated 2 years ago
- Analysis of syscall sequence pattern from exploit codes for advanced system call sequence filtering for enhanced container security☆16Updated 2 years ago
- 🪐 A Database of Existing Security Vulnerabilities Patches to Enable Evaluation of Techniques (single-commit; multi-language)☆42Updated 7 months ago
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.1, purl, and vers…☆129Updated 3 months ago
- Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners☆13Updated this week
- using ML models for red teaming☆44Updated 2 years ago
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆153Updated last year
- Testability Pattern Catalogs for SAST☆31Updated 8 months ago
- A framework for identifying vulnerabilities in VS Code extensions☆18Updated last year
- An open-source dataset of malicious software packages found in the wild, 100% vetted by humans.☆253Updated last week
- Automatically fuzz Rust projects from scratch☆58Updated 4 months ago
- Community reconstruction of the legacy JSON NVD Data Feeds. This project uses and redistributes data from the NVD API but is neither endo…☆183Updated last week
- The source code (including datasets) of V1SCAN (USENIX Security 2023; will be uploaded).☆41Updated 2 years ago
- A dataset of software supply chain compromises. Please help us maintain it!☆130Updated 3 years ago
- SAST + LLM Interprocedural Context Extractor☆139Updated 2 weeks ago
- JAW: A Graph-based Security Analysis Framework for Client-side JavaScript☆112Updated 2 months ago
- Modular static malicious JavaScript detection system☆74Updated 4 years ago
- AutoVAS is an automated vulnerability analysis system with a deep learning approach.☆35Updated 4 years ago
- A fork of Bandit tool with patterns to identifying malicious python code.☆28Updated 3 years ago
- Grammar-based HTTP/2 fuzzer with mutation ability☆47Updated 3 years ago
- A place to systematically store software bill of materials (SBOM) documents.☆47Updated 2 years ago