Vancir / Awesome-Software-Supply-Chain-Security
Awesome materials for software supply chain security
☆17Updated 4 years ago
Alternatives and similar repositories for Awesome-Software-Supply-Chain-Security:
Users that are interested in Awesome-Software-Supply-Chain-Security are comparing it to the libraries listed below
- A set of Code-ql/Joern queries to find vulnerabilities☆57Updated 3 years ago
- Works about detecting vulnerable using ML.☆83Updated 4 years ago
- ☆24Updated 11 months ago
- Code for UI, backend, engine and statistical analysis for RE☆20Updated 3 years ago
- Assisting Static Analysis with Large Language Models: A ChatGPT Experiment☆30Updated last year
- Pairing Security Advisories with Vulnerable Functions Using Open-Source LLMs - DIMVA '24☆15Updated 5 months ago
- Source Code Vulnerability Detection Tools(SCVDT)provides a vulnerable code database, vulnerability detection service for Java and C/C++ p…☆112Updated 3 years ago
- ☆72Updated 3 years ago
- aurora-d☆20Updated 2 years ago
- Code and artifacts related to the Asia CCS 2022 paper☆35Updated 3 years ago
- ReDeBug Source Code.☆24Updated last year
- Collate and collect binary related materials, including papers, tools, etc. Now,there are the following categories: 1、Fuzzing☆56Updated 5 years ago
- 模糊测试种子库 comprehensive croups for fuzzing seeds with carfefully selected(rate=coverage/filesize)☆22Updated 3 years ago
- ☆25Updated last year
- B2SFinder is a binary-to-source matching tool for OSS reuse detection on COTS software. This project contains the core code of B2SFinder …☆53Updated 5 years ago
- A GPT-Based Fuzz Driver Generator☆46Updated last year
- The released code of FuzzGuard in USENIX Security 2020.☆28Updated 4 years ago
- ObjLupAnsys is a tool to detect prototype pollution vulnerabilities in Node.js packages. This project is written in Python and JavaScript…☆22Updated 3 years ago
- Auto-generated CodeQL rules for matching CVE vulnerabilities and variants.☆161Updated 4 months ago
- ☆36Updated 2 years ago
- FirmSec Dataset☆10Updated 3 years ago
- ☆29Updated last year
- ISSTA'23 - Third-party Library Dependency for Large-scale SCA in the C/C++ Ecosystem: How Far Are We?☆29Updated last year
- Detecting Flow of Sensitive Data in Mini-Programs with Static Taint Analysis☆74Updated 10 months ago
- Source-binary patch presence test system.☆82Updated 2 years ago
- Some test samples for CPG execution logic.☆20Updated 10 months ago
- KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities (Best Practical Paper Award of RAID 2024)☆44Updated 3 weeks ago
- source code analysis workshop☆15Updated 3 years ago
- An automated static taint analysis tool for the Lua web framework.☆13Updated 4 months ago
- Prototype of the paper "APICraft: Fuzz Driver Generation for Closed-source SDK Libraries".☆64Updated 3 years ago