{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/a-manually-curated-dataset-of-fixes-to","title":"A Manually-Curated Dataset of Fixes to Vulnerabilities of Open-Source Software","arxiv_id":"1902.02595","date":"2019-02-07","proceeding":null,"authors":["Serena E. Ponta","Henrik Plate","Antonino Sabetta","Michele Bezzi","Cédric Dangremont"],"abstract":"Advancing our understanding of software vulnerabilities, automating their\nidentification, the analysis of their impact, and ultimately their mitigation\nis necessary to enable the development of software that is more secure. While\noperating a vulnerability assessment tool that we developed and that is\ncurrently used by hundreds of development units at SAP, we manually collected\nand curated a dataset of vulnerabilities of open-source software and the\ncommits fixing them. The data was obtained both from the National Vulnerability\nDatabase (NVD) and from project-specific Web resources that we monitor on a\ncontinuous basis. From that data, we extracted a dataset that maps 624 publicly\ndisclosed vulnerabilities affecting 205 distinct open-source Java projects,\nused in SAP products or internal tools, onto the 1282 commits that fix them.\nOut of 624 vulnerabilities, 29 do not have a CVE identifier at all and 46,\nwhich do have a CVE identifier assigned by a numbering authority, are not\navailable in the NVD yet. The dataset is released under an open-source license,\ntogether with supporting scripts that allow researchers to automatically\nretrieve the actual content of the commits from the corresponding repositories\nand to augment the attributes available for each instance. Also, these scripts\nallow to complement the dataset with additional instances that are not security\nfixes (which is useful, for example, in machine learning applications). Our\ndataset has been successfully used to train classifiers that could\nautomatically identify security-relevant commits in code repositories. The\nrelease of this dataset and the supporting code as open-source will allow\nfuture research to be based on data of industrial relevance; also, it\nrepresents a concrete step towards making the maintenance of this dataset a\nshared effort involving open-source communities, academia, and the industry.","url_abs":"http://arxiv.org/abs/1902.02595v3","url_pdf":"http://arxiv.org/pdf/1902.02595v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"a-manually-curated-dataset-of-fixes-to","repo_url":"https://github.com/SAP/vulnerability-assessment-kb","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"none","reach":null},{"paper_slug":"a-manually-curated-dataset-of-fixes-to","repo_url":"https://github.com/copernico/msr2019","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"none","reach":null}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}