11 papers
VeriPort: Automated and Verified Patch Backporting at Scale
Jonah Ghebremichael, Wenxin Jiang, Mikola Lysenko +3
One of the key challenges for securing the software supply chain is addressing known vulnerabilities in third-party open-source dependencies. Security patches are frequently only a…
How Quickly Do Development Teams Update Their Vulnerable Dependencies?
Imranur Rahman, Ranindya Paramitha, Nusrat Zahan +2
Industry practitioners are increasingly concerned with software that contains vulnerable versions of third-party dependencies that are included both directly and transitively. To a…
S3C2 Summit 2025-09: Industry Secure Supply Chain Summit
Md Atiqur Rahman, Yasemin Acar, Michel Cucker +5
Today's digital ecosystem relies heavily on software supply chains, which enable developers to reuse code and ship software at scale. However, a single vulnerable component can jeo…
S3C2 Summit 2025-07: Government Secure Supply Chain Summit
Sivana Hamer, Pat Morrison, William Enck +6
Software supply chains, while providing immense economic and software development value, are only as strong as their weakest link. Over the past several years, there has been an ex…
Which Is Better For Reducing Outdated and Vulnerable Dependencies: Pinning or Floating?
Imranur Rahman, Jill Marley, William Enck +1
Developers consistently use version constraints to specify acceptable versions of the dependencies for their project. Pinning dependencies can reduce the likelihood of breaking cha…
WAAA! Web Adversaries Against Agentic Browsers
Sohom Datta, Alex Nahapetyan, William Enck +1
Large language models (LLMs) are increasingly being integrated into web browsers to create agentic browsing systems that execute actions on behalf of the user. Prior work consideri…