Empirical Analysis of Vulnerabilities Life Cycle in Golang Ecosystem
Jinchang Hu, Lyuye Zhang, Chengwei Liu, Sen Yang, Song Huang, Yang Liu
摘要
Open-source software (OSS) greatly facilitates program development for developers. However, the high number of vulnerabilities in open-source software is a major concern, including in Golang, a relatively new programming language. In contrast to other commonly used OSS package managers, Golang presents a distinctive feature whereby commits are prevalently used as dependency versions prior to their integration into official releases. This attribute can prove advantageous to users, as patch commits can be implemented in a timely manner before the releases. However, Golang employs a decentralized mechanism for managing dependencies, whereby dependencies are upheld and distributed in separate repositories. This approach can result in delays in the dissemination of patches and unresolved vulnerabilities. To tackle the aforementioned concern, a comprehensive investigation was undertaken to examine the life cycle of vulnerability in Golang, commencing from its introduction and culminating with its rectification. To this end, a framework was established by gathering data from diverse sources and systematically amalgamating them with an algorithm to compute the lags in vulnerability patching. It turned out that 66.10% of modules in the Golang ecosystem were affected by vulnerabilities. Within the vulnerability life cycle, we found two kinds of lag impeding the propagation of vulnerability fixing. By analyzing reasons behind non-lagged and lagged vulnerabilities, timely releasing and indexing patch versions could significantly enhance ecosystem security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue ManagementLyuye Zhang, Jiahui Wu, Chengwei Liu, Kaixuan Li 等ISSTA 2025 · 被引用 3 次
- Which Is Better For Reducing Outdated and Vulnerable Dependencies: Pinning or FloatingƒImranur Rahman, Jill Marley, William Enck, Laurie A. WilliamsASE 2025 · 被引用 1 次
- Minimizing Breaking Changes and Redundancy in Mitigating Technical Lag for Java ProjectsRui Lu, Lyuye Zhang, Kaixuan Li, Min Zhang 等ICSE 2026 · 被引用 1 次
- Today's Cat Is Tomorrow's Dog: Accounting for Time-Based Changes in the Labels of ML Vulnerability Detection ApproachesRanindya Paramitha, Yuan Feng, Fabio MassacciFSE 2025
- "I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm PackagesRajdeep Ghosh, Shiladitya De, Mainack MondalUSENIX Security 2025
它引用的顶会 Paper15
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM EcosystemChengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen 等ICSE 2022 · 被引用 94 次
- Towards Understanding Third-party Library Dependency in C/C++ EcosystemWei Tang, Zhengzi Xu, Chengwei Liu, Jiahui Wu 等ASE 2022 · 被引用 64 次
- Software Composition Analysis for Vulnerability Detection: An Empirical Study on Java ProjectsLida Zhao, Sen Chen, Zhengzi Xu, Chengwei Liu 等FSE 2023 · 被引用 42 次
- Understanding the Threats of Upstream Vulnerabilities to Downstream Projects in the Maven EcosystemYulun Wu, Zeliang Yu, Ming Wen, Qiang Li 等ICSE 2023 · 被引用 41 次
相关 Paper
- Death Is Not the End: a Longitudinal Study on the Impact of Automatic Updates on Container Vulnerability LifespansSimge Tekin, Octavian Suciu, Sungsu Kwag, Yonghwi Kwon 等S&P 2026 · 被引用 1 次
- Unveiling the Characteristics and Impact of Security Patch EvolutionZifan Xie, Ming Wen, Zichao Wei, Hai JinASE 2024 · 被引用 2 次
- Mitigating Persistence of Open-Source Vulnerabilities in Maven EcosystemLyuye Zhang, Chengwei Liu, Sen Chen, Zhengzi Xu 等ASE 2023 · 被引用 25 次
- Locating the Security Patches for Disclosed OSS Vulnerabilities with Vulnerability-Commit Correlation RankingXin Tan, Yuan Zhang, Chenyuan Mi, Jiajun Cao 等CCS 2021 · 被引用 43 次
- An Investigation of the Android Kernel Patch EcosystemZheng Zhang, Hang Zhang, Zhiyun Qian, Billy LauUSENIX Security 2021 · 被引用 45 次
