{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T16:32:32Z","timestamp":1784392352550,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":62,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,4,12]],"date-time":"2024-04-12T00:00:00Z","timestamp":1712880000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,4,12]]},"DOI":"10.1145\/3597503.3639582","type":"proceedings-article","created":{"date-parts":[[2024,4,12]],"date-time":"2024-04-12T16:43:26Z","timestamp":1712940206000},"page":"1-12","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["Identifying Affected Libraries and Their Ecosystems for Open Source Software Vulnerabilities"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-2169-7032","authenticated-orcid":false,"given":"Susheng","family":"Wu","sequence":"first","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-9507-5066","authenticated-orcid":false,"given":"Wenyan","family":"Song","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-1513-8254","authenticated-orcid":false,"given":"Kaifeng","family":"Huang","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7238-7492","authenticated-orcid":false,"given":"Bihuan","family":"Chen","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3376-2581","authenticated-orcid":false,"given":"Xin","family":"Peng","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,4,12]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3125270"},{"key":"e_1_3_2_1_2_1","volume-title":"Retrieved","year":"2023","unstructured":"Apache. 2023. Lucene: a Java library providing powerful indexing and search features. Retrieved July 30, 2023 from https:\/\/lucene.apache.org"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510113"},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of the 16th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. 105--114","author":"Bozorgi Mehran","unstructured":"Mehran Bozorgi, Lawrence K. Saul, Stefan Savage, and Geoffrey M. Voelker. 2010. Beyond Heuristics: Learning to Classify Vulnerabilities and Predict Exploits. In Proceedings of the 16th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. 105--114."},{"key":"e_1_3_2_1_5_1","volume-title":"Retrieved","year":"2023","unstructured":"brettcannon, dstufft, pf_moore, and pradyunsg. 2023. Packaging: Core utilities for Python packages. Retrieved July 30, 2023 from https:\/\/github.com\/pypa\/packaging"},{"key":"e_1_3_2_1_6_1","first-page":"23","article-title":"From ranknet to lambdarank to lambdamart: An overview","volume":"11","author":"Burges Christopher JC","year":"2010","unstructured":"Christopher JC Burges. 2010. From ranknet to lambdarank to lambdamart: An overview. Learning 11, 23--581 (2010), 81.","journal-title":"Learning"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106285"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377813.3381360"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER53432.2022.00050"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484594"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2018.2816033"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.5555\/3361338.3361399"},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of the fourth international symposium on spatial data handing. 803--813","author":"Egenhofer Max","year":"1990","unstructured":"Max Egenhofer. 1990. A mathematical framework for the definition of topological relations. In Proceedings of the fourth international symposium on spatial data handing. 803--813."},{"key":"e_1_3_2_1_14_1","volume-title":"Retrieved","author":"Framework Spring","year":"2023","unstructured":"Spring Framework. 2023. Patch for Spring framework vulnerability. Retrieved July 14, 2023 from https:\/\/github.com\/spring-projects\/spring-framework\/commit\/0d0d75e25322d8161002d861fff3ec04ba8be5ac"},{"key":"e_1_3_2_1_15_1","volume-title":"Retrieved","author":"Framework Spring","year":"2023","unstructured":"Spring Framework. 2023. Patch for Spring framework vulnerability. Retrieved July 14, 2023 from https:\/\/github.com\/spring-projects\/spring-framework\/commit\/cce60c479c22101f24b2b4abebb6d79440b120d1"},{"key":"e_1_3_2_1_16_1","volume-title":"Retrieved","year":"2023","unstructured":"Gartner. 2023. Gartner Magic Quadrant for Application Security Testing. Retrieved July 14, 2023 from https:\/\/www.microfocus.com\/en-us\/assets\/cyberres\/magic-quadrant-for-application-security-testing"},{"key":"e_1_3_2_1_17_1","volume-title":"Retrieved","year":"2023","unstructured":"GitHub. 2023. GitHub Advisory Database. Retrieved July 14, 2023 from https:\/\/github.com\/github\/advisory-database"},{"key":"e_1_3_2_1_18_1","volume-title":"Retrieved","year":"2023","unstructured":"GitHub. 2023. Publish GHSA-gfwj-fwqj-fp3v. Retrieved July 27, 2023 from https:\/\/github.com\/github\/advisory-database\/commit\/21baa3d"},{"key":"e_1_3_2_1_19_1","volume-title":"Retrieved","year":"2023","unstructured":"GitLab. 2023. GitLab Advisory Database. Retrieved July 14, 2023 from https:\/\/gitlab.com\/gitlab-org\/security-products\/gemnasium-db"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICECCS.2019.00011"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3498537"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC51774.2021.00138"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2017.52"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3524610.3527893"},{"key":"e_1_3_2_1_25_1","volume-title":"Automatically Identifying CVE Affected Versions with Patches and Developer Logs","author":"He Yongzhong","year":"2023","unstructured":"Yongzhong He, Yiming Wang, Sencun Zhu, Wei Wang, Yunjia Zhang, Qiang Li, and Aimin Yu. 2023. Automatically Identifying CVE Affected Versions with Patches and Developer Logs. IEEE Transactions on Dependable and Secure Computing (2023)."},{"key":"e_1_3_2_1_26_1","volume-title":"Characterizing usages, updates and risks of third-party libraries in Java projects. Empirical Software Engineering 27, 4","author":"Huang Kaifeng","year":"2022","unstructured":"Kaifeng Huang, Bihuan Chen, Congying Xu, Ying Wang, Bowen Shi, Xin Peng, Yijian Wu, and Yang Liu. 2022. Characterizing usages, updates and risks of third-party libraries in Java projects. Empirical Software Engineering 27, 4 (2022)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3475716.3475769"},{"key":"e_1_3_2_1_28_1","volume-title":"Retrieved","year":"2023","unstructured":"Jenkins.io. 2023. Jenkins Security Advisory. Retrieved July 14, 2023 from https:\/\/www.jenkins.io\/security\/advisory\/2022-05-17\/#SECURITY-1969"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3003570"},{"key":"e_1_3_2_1_30_1","volume-title":"Retrieved","year":"2023","unstructured":"leonard. 2023. Beautiful Soup. Retrieved July 14, 2023 from https:\/\/pypi.org\/project\/beautifulsoup4\/"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510142"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1561\/1500000016"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00094"},{"key":"e_1_3_2_1_34_1","volume-title":"Retrieved","year":"2023","unstructured":"mend.io. 2023. Mend.io (formerly known as WhiteSource). Retrieved July 14, 2023 from https:\/\/www.mend.io\/vulnerability-database\/"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER56733.2023.00028"},{"key":"e_1_3_2_1_36_1","volume-title":"Proceedings of the 27th USENIX Security Symposium. 919--936","author":"Mu Dongliang","year":"2018","unstructured":"Dongliang Mu, Alejandro Cuevas, Limin Yang, Hang Hu, Xinyu Xing, Bing Mao, and Gang Wang. 2018. Understanding the reproducibility of crowd-reported security vulnerabilities. In Proceedings of the 27th USENIX Security Symposium. 919--936."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-015-9408-2"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/2484313.2484377"},{"key":"e_1_3_2_1_39_1","volume-title":"Retrieved","author":"NVD.","year":"2023","unstructured":"NVD. 2023. NVD. Retrieved July 14, 2023 from https:\/\/nvd.nist.gov"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00088"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSM.2015.7332492"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2018.00054"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"crossref","unstructured":"Stephen Robertson Hugo Zaragoza et al. 2009. The probabilistic relevance framework: BM25 and beyond. Foundations and Trends\u00ae in Information Retrieval 3 4 (2009) 333--389.","DOI":"10.1561\/1500000019"},{"key":"e_1_3_2_1_44_1","volume-title":"Proceedings of the 24th USENIX Security Symposium. 1041--1056","author":"Sabottke Carl","year":"2015","unstructured":"Carl Sabottke, Octavian Suciu, and Tudor Dumitra\u015f. 2015. Vulnerability disclosure in the age of social media: Exploiting twitter for predicting {Real-World} exploits. In Proceedings of the 24th USENIX Security Symposium. 1041--1056."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3551349.3556933"},{"key":"e_1_3_2_1_46_1","volume-title":"Retrieved","author":"SNYK.","year":"2023","unstructured":"SNYK. 2023. SNYK Open Source Vulnerability Database. Retrieved July 14, 2023 from https:\/\/security.snyk.io\/"},{"key":"e_1_3_2_1_47_1","volume-title":"Proceedings of the 31st USENIX Security Symposium. 377--394","author":"Suciu Octavian","year":"2022","unstructured":"Octavian Suciu, Connor Nelson, Zhuoer Lyu, Tiffany Bao, and Tudor Dumitra\u015f. 2022. Expected exploitability: Predicting the development of functional vulnerability exploits. In Proceedings of the 31st USENIX Security Symposium. 377--394."},{"key":"e_1_3_2_1_48_1","volume-title":"Retrieved","year":"2023","unstructured":"synopsys. 2023. Synopsys Software Composition Analysis. Retrieved July 14, 2023 from https:\/\/www.synopsys.com\/software-integrity\/security-testing\/software-composition-analysis\/knowledgebase.html"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484593"},{"key":"e_1_3_2_1_50_1","volume-title":"Tree-sitter: An incremental parsing system for programming tools. Retrieved","year":"2023","unstructured":"tree sitter. 2023. Tree-sitter: An incremental parsing system for programming tools. Retrieved May 1, 2023 from https:\/\/tree-sitter.github.io\/tree-sitter\/"},{"key":"e_1_3_2_1_51_1","volume-title":"Retrieved","year":"2023","unstructured":"Veracode. 2023. Veracode Vulnerability Database. Retrieved July 14, 2023 from https:\/\/sca.analysiscenter.veracode.com\/vulnerability-database\/search"},{"key":"e_1_3_2_1_52_1","first-page":"2021","volume-title":"Retrieved","year":"2023","unstructured":"Vulmon. 2023. CVE-2021-22118. Retrieved July 14, 2023 from https:\/\/vulmon.com\/vendoradvisory?qidtp=red_hat_cve_database&qid=CVE-2021-22118"},{"key":"e_1_3_2_1_53_1","volume-title":"Proceedings of the IEEE International Conference on Software Analysis, Evolution and Reengineering. 589--600","author":"Wang Shichao","year":"2022","unstructured":"Shichao Wang, Yun Zhang, Liagfeng Bao, Xin Xia, and Minghui Wu. 2022. VC-Match: A Ranking-based Approach for Automatic Security Patches Localization for OSS Vulnerabilities. In Proceedings of the IEEE International Conference on Software Analysis, Evolution and Reengineering. 589--600."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME46990.2020.00014"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2023.107178"},{"key":"e_1_3_2_1_56_1","volume-title":"Retrieved","year":"2023","unstructured":"wikipedia. 2023. Crossover Study. Retrieved July 14, 2023 from https:\/\/en.wikipedia.org\/wiki\/Crossover_study"},{"key":"e_1_3_2_1_57_1","volume-title":"Retrieved","year":"2023","unstructured":"Wikipedia. 2023. Evaluation Measures (information retrieval). Retrieved July 14, 2023 from https:\/\/en.wikipedia.org\/wiki\/Evaluation_measures_(information_retrieval)#Mean_average_precision"},{"key":"e_1_3_2_1_58_1","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security 20)","author":"Xiao Yang","year":"2020","unstructured":"Yang Xiao, Bihuan Chen, Chendong Yu, Zhengzi Xu, Zimu Yuan, Feng Li, Binghong Liu, Yang Liu, Wei Huo, Wei Zou, et al. 2020. {MVP}: Detecting Vulnerabilities using {Patch-Enhanced} Vulnerability Signatures. In Proceedings of the 29th USENIX Security Symposium (USENIX Security 20). 1165--1182."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549125"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3551349.3556921"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678638"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSR52588.2021.00016"}],"event":{"name":"ICSE '24: IEEE\/ACM 46th International Conference on Software Engineering","location":"Lisbon Portugal","acronym":"ICSE '24","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS","Faculty of Engineering of University of Porto"]},"container-title":["Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597503.3639582","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3597503.3639582","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:50:12Z","timestamp":1750287012000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597503.3639582"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,12]]},"references-count":62,"alternative-id":["10.1145\/3597503.3639582","10.1145\/3597503"],"URL":"https:\/\/doi.org\/10.1145\/3597503.3639582","relation":{},"subject":[],"published":{"date-parts":[[2024,4,12]]},"assertion":[{"value":"2024-04-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}