| dc.contributor.author | Dann, Andreas | |
| dc.contributor.author | Plate, Henrik | |
| dc.contributor.author | Hermann, Ben | |
| dc.contributor.author | Ponta, Serena Elisa | |
| dc.contributor.author | Bodden, Eric | |
| dc.contributor.editor | Grunske, Lars | |
| dc.contributor.editor | Siegmund, Janet | |
| dc.contributor.editor | Vogelsang, Andreas | |
| dc.date.accessioned | 2022-01-19T12:56:55Z | |
| dc.date.available | 2022-01-19T12:56:55Z | |
| dc.date.issued | 2022 | |
| dc.identifier.isbn | 978-3-88579-714-2 | |
| dc.identifier.issn | 1617-5468 | |
| dc.identifier.uri | http://dl.gi.de/handle/20.500.12116/37983 | |
| dc.description.abstract | This short paper presents a study investigating the impact of typical development practices, like re-compilation, re-bundling, on the performance of vulnerability scanners to detect known vulnerabilities in used open-source dependencies. In particular, the paper studies (i) types of modifications that affect the detection of vulnerable open-source dependencies and (ii) their impact on the performance of vulnerability scanners through an empirical study on 7024 Java projects developed at SAP. | en |
| dc.language.iso | en | |
| dc.publisher | Gesellschaft für Informatik e.V. | |
| dc.relation.ispartof | Software Engineering 2022 | |
| dc.relation.ispartofseries | Lecture Notes in Informatics (LNI) - Proceedings, Volume P-320 | |
| dc.subject | Security maintenance | |
| dc.subject | Open-Source Software | |
| dc.subject | Security Vulnerabilities | |
| dc.title | Identifying Challenges for OSS Vulnerability Scanners - A Study & Test Suite (Short Summary) | en |
| dc.type | Text/Conference Paper | |
| dc.pubPlace | Bonn | |
| mci.reference.pages | 21-23 | |
| mci.conference.sessiontitle | Wissenschaftliches Hauptprogramm | |
| mci.conference.location | Berlin/Virtuell | |
| mci.conference.date | 21.-25. Feburar 2022 | |
| dc.identifier.doi | 10.18420/se2022-ws-003 | |