3 papers
cs.CR2026
VeriPort: Automated and Verified Patch Backporting at Scale
Jonah Ghebremichael, Wenxin Jiang, Mikola Lysenko +3
One of the key challenges for securing the software supply chain is addressing known vulnerabilities in third-party open-source dependencies. Security patches are frequently only a…
cs.CR2026
Multi-Agent Taint Specification Extraction for Vulnerability Detection
Jonah Ghebremichael, Saastha Vasan, Saad Ullah +6
Static Application Security Testing (SAST) tools using taint analysis are widely viewed as providing higher-quality vulnerability detection results compared to traditional pattern-…
cs.CR2025
S3C2 Summit 2025-03: Industry Secure Supply Chain Summit
Elizabeth Lin, Jonah Ghebremichael, William Enck +5
Software supply chains, while providing immense economic and software development value, are only as strong as their weakest link. Over the past several years, there has been an ex…