Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue Management
Lyuye Zhang, Jiahui Wu, Chengwei Liu, Kaixuan Li, Xiaoyu Sun, Lida Zhao, Chong Wang, Yang Liu
摘要
In the rapidly evolving landscape of software development, addressing security vulnerabilities in open-source software (OSS) has become critically important. However, existing research and tools from both academia and industry mainly relied on limited solutions, such as vulnerable version adjustment and adopting patches, to handle identified vulnerabilities. However, far more flexible and diverse countermeasures have been actively adopted in the open-source communities. A holistic empirical study is needed to explore the prevalence, distribution, preferences, and effectiveness of these diverse strategies.
To this end, in this paper, we conduct a comprehensive study on the taxonomy of vulnerability remediation tactics (RT) in OSS projects and investigate their pros and cons. This study addresses this oversight by conducting a comprehensive empirical analysis of 21,187 issues from GitHub, aiming to understand the range and efficacy of remediation tactics within the OSS community. We developed a hierarchical taxonomy of 44 distinct RT and evaluated their effectiveness and costs. Our findings highlight a significant reliance on community-driven strategies, like using alternative libraries and bypassing vulnerabilities, 44% of which are currently unsupported by cutting-edge tools. Additionally, this research exposes the community's preferences for certain fixing approaches by analyzing their acceptance and the reasons for rejection. It also underscores a critical gap in modern vulnerability databases, where 54% of CVEs lack fixing suggestions-a gap that can be significantly mitigated by leveraging the 93% of actionable solutions provided through GitHub issues.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Navigating the Labyrinth: Path-Sensitive Unit Test Generation with Large Language ModelsDianshu Liao, Xin Yin, Shidong Pan, Chao Ni 等ASE 2025 · 被引用 2 次
- Minimizing Breaking Changes and Redundancy in Mitigating Technical Lag for Java ProjectsRui Lu, Lyuye Zhang, Kaixuan Li, Min Zhang 等ICSE 2026 · 被引用 1 次
它引用的顶会 Paper17
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- VulRepair: a T5-based automated software vulnerability repairMichael Fu, Chakkrit Tantithamthavorn, Trung Le, Van Nguyen 等FSE 2022 · 被引用 206 次
- Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM EcosystemChengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen 等ICSE 2022 · 被引用 94 次
- Talos: Neutralizing Vulnerabilities with Security Workarounds for Rapid ResponseZhen Huang, Mariana D'Angelo, Dhaval Miyani, David LieS&P 2016 · 被引用 59 次
- Comparison and Evaluation on Static Application Security Testing (SAST) Tools for JavaKaixuan Li, Sen Chen, Lingling Fan, Ruitao Feng 等FSE 2023 · 被引用 43 次
相关 Paper
- Tracking patches for open source software vulnerabilitiesCongying Xu, Bihuan Chen, Chenhao Lu, Kaifeng Huang 等FSE 2022 · 被引用 34 次
- SoK: Taxonomy of Attacks on Open-Source Software Supply ChainsPiergiorgio Ladisa, Henrik Plate, Matias Martinez, Olivier BaraisS&P 2023
- Vision: Identifying Affected Library Versions for Open Source Software VulnerabilitiesSusheng Wu, Ruisi Wang, Kaifeng Huang, Yiheng Cao 等ASE 2024 · 被引用 1 次
- Understanding the Practice of Security Patch Management across Multiple Branches in OSS ProjectsXin Tan, Yuan Zhang, Jiajun Cao, Kun Sun 等WWW 2022 · 被引用 19 次
- A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security FeaturesJessy Ayala, Yu-Jye Tung, Joshua GarciaUSENIX Security 2025
