kirancodes.me
To Proof Maintenance & Beyond!

Empirical Analysis of Vulnerabilities Life Cycle in Golang Ecosystem

Jinchang Hu, Lyuye Zhang, Chengwei Liu, Sen Yang, Song Huang, Yang Liu

Abstract

Open-source software (OSS) greatly facilitates program development for developers. However, the high number of vulnerabilities in open-source software is a major concern, including in Golang, a relatively new programming language. In contrast to other commonly used OSS package managers, Golang presents a distinctive feature whereby commits are prevalently used as dependency versions prior to their integration into official releases. This attribute can prove advantageous to users, as patch commits can be implemented in a timely manner before the releases. However, Golang employs a decentralized mechanism for managing dependencies, whereby dependencies are upheld and distributed in separate repositories. This approach can result in delays in the dissemination of patches and unresolved vulnerabilities.

BibTeX
@inproceedings{Hu-al:ICSE24,
  author    = {Jinchang Hu and
               Lyuye Zhang and
               Chengwei Liu and
               Sen Yang and
               Song Huang and
               Yang Liu},
  title     = {Empirical Analysis of Vulnerabilities Life Cycle in Golang Ecosystem},
  booktitle = {ICSE},
  pages     = {212:1--212:13},
  publisher = {{ACM}},
  year      = {2024},
}

Related papers