osssanitizer / maloss
Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages
☆127Updated 2 years ago
Alternatives and similar repositories for maloss:
Users that are interested in maloss are comparing it to the libraries listed below
- Artifact accompanying our ICSE '22 paper "Practical Automated Detection of Malicious npm Packages"☆42Updated 2 years ago
- The repository has collected about 10,000 malicious pypi packages. This dataset is the work of the ASE 2023 paper "An Empirical Study of…☆73Updated last month
- Source Code Vulnerability Detection Tools(SCVDT)provides a vulnerable code database, vulnerability detection service for Java and C/C++ p…☆110Updated 3 years ago
- ODGen is a JavaScript Static Analysis tool to detect multiple types of vulnerabilities in Node.js packages.☆151Updated 11 months ago
- ☆54Updated last year
- This repository contains a list of papers about software supply chain☆25Updated 7 months ago
- A deep learning model for localizing bugs in C/C++ source code (USENIX'23)☆142Updated last year
- Home page of project "KB"☆116Updated last month
- ☆36Updated last year
- HiddenCPG: Large-Scale Vulnerable Clone Detection Using Subgraph Isomorphism of Code Property Graphs☆41Updated 2 years ago
- ISSTA'23 - Third-party Library Dependency for Large-scale SCA in the C/C++ Ecosystem: How Far Are We?