formalsec / graphjs
MDG-based static vulnerability scanner specialized in analyzing npm packages and detecting taint-style and prototype pollution vulnerabilities.
☆17Updated last month
Alternatives and similar repositories for graphjs
Users that are interested in graphjs are comparing it to the libraries listed below
Sorting:
- This is an evaluation set for the problem of directed/targeted test input generation. We use it to benchmark the ability of Large Languag…☆32Updated 2 months ago
- VulTrigger is a tool to for identifying vulnerability-triggering statements across functions and investigating the effectiveness of funct…☆33Updated last year
- tool of llm-based indirect-call analyzer☆21Updated 2 months ago
- LLMDFA: Analyzing Dataflow in Code with Large Language Models (NeurIPS 2024)☆111Updated 2 months ago
- ISSTA'23 - Third-party Library Dependency for Large-scale SCA in the C/C++ Ecosystem: How Far Are We?☆29Updated last year
- open science repo of "Neural Transfer Learning for Repairing Security Vulnerabilities in C Code" https://arxiv.org/pdf/2104.08308☆63Updated last year
- HiddenCPG: Large-Scale Vulnerable Clone Detection Using Subgraph Isomorphism of Code Property Graphs☆43Updated 2 years ago
- WhiteFox: White-Box Compiler Fuzzing Empowered by Large Language Models (OOPSLA 2024)☆57Updated 5 months ago
- LLMSAN: Sanitizing Large Language Models in Bug Detection with Data-Flow (EMNLP Findings 2024)☆70Updated 2 weeks ago
- Vul4J: A Dataset of Reproducible Java Vulnerabilities☆85Updated 2 months ago
- For our ISSTA22 paper "DocTer: Documentation-Guided Fuzzing for Testing Deep Learning API Functions" by Danning Xie, Yitong Li, Mijung Ki…☆35Updated 2 years ago
- Program Vulnerability Repair via Inductive Inference☆20Updated last year
- Fuzzing Deep-Learning Libraries via Automated Relational API Inference (ESEC/FSE 2022)☆37Updated last year
- This repository is to support contributions for tools and new data entries for the D2A dataset hosted in DAX☆71Updated 2 years ago
- MegaVul - The largest, high-quality, extensible, continuously updated, C/C++/Java vulnerability dataset☆73Updated 4 months ago
- PatchFinder: A Two-Phase Approach to Security Patch Tracing for Disclosed Vulnerabilities in Open Source Software (ISSTA 2024)☆19Updated last month
- The source code of project "LLift" (Enhancing static analysis with LLM)☆70Updated last year
- TensorFlow API analysis tool and malicious model detection tool☆27Updated 2 months ago
- ☆21Updated 2 months ago
- ☆22Updated 2 years ago
- Assisting Static Analysis with Large Language Models: A ChatGPT Experiment☆34Updated last year
- ☆42Updated 6 months ago
- A GPT-Based Fuzz Driver Generator☆46Updated last year
- A manually vetted dataset for security vulnerability detection in Java projects☆50Updated 3 weeks ago
- The official repository of "GraphSPD: Graph-Based Security Patch Detection with Enriched Code Semantics". The paper will appear in the IE…☆44Updated last year
- A practical fuzzing tool for SMT solvers☆11Updated 9 months ago
- ☆74Updated 2 years ago
- Qilin: A New Framework for Supporting Fine-Grained Context-Sensitivity in Java Pointer Analysis☆134Updated last month
- Research artifact for Oakland (S&P) 2024, "Titan: Efficient Multi-target Directed Greybox Fuzzing"☆53Updated 3 months ago
- ☆26Updated 2 years ago