Javascript must be enabled to continue!
Correlation Between GitHub Stars and Code Vulnerabilities
View through CrossRef
In the software industry, open-source repositories are widely utilized to speed up software development. GitHub is a big source of open-source repositories and offers users to star the code repository. Stars are used in GitHub to represent appreciation and popularity. Studies have revealed that repositories may be of lower quality and may have vulnerabilities that hackers may exploit. It is not known whether the popularity of the GitHub repositories in terms of stars confirms the security and invulnerability of the program code. This paper analyzed the correlation between stars of GitHub’s code repositories and the vulnerabilities in their code by using static code analyzer. The study examined the vulnerabilities in ten popular C++ source repositories on GitHub and discovered 3487 vulnerabilities in the dataset, which were split into four categories based on severity. There was not a single repository in the dataset that was free of flaws. On the detected vulnerabilities, a Kruskal-Wallis H test reveals a significant difference between the different code repositories of the dataset. The Spearman's rank correlation coefficient test found no correlation between repositories’ stars and the frequency of vulnerabilities, implying that the popularity of code repositories on GitHub in terms of high star ratings does not imply their security integrity. Overall, the findings suggest that code repositories should be thoroughly evaluated before being used in software development. The novelty of this paper resides in the development of new knowledge as well as the study pattern that may be used to other investigations.
Research Center of Computing and Biomedical Informatics
Title: Correlation Between GitHub Stars and Code Vulnerabilities
Description:
In the software industry, open-source repositories are widely utilized to speed up software development.
GitHub is a big source of open-source repositories and offers users to star the code repository.
Stars are used in GitHub to represent appreciation and popularity.
Studies have revealed that repositories may be of lower quality and may have vulnerabilities that hackers may exploit.
It is not known whether the popularity of the GitHub repositories in terms of stars confirms the security and invulnerability of the program code.
This paper analyzed the correlation between stars of GitHub’s code repositories and the vulnerabilities in their code by using static code analyzer.
The study examined the vulnerabilities in ten popular C++ source repositories on GitHub and discovered 3487 vulnerabilities in the dataset, which were split into four categories based on severity.
There was not a single repository in the dataset that was free of flaws.
On the detected vulnerabilities, a Kruskal-Wallis H test reveals a significant difference between the different code repositories of the dataset.
The Spearman's rank correlation coefficient test found no correlation between repositories’ stars and the frequency of vulnerabilities, implying that the popularity of code repositories on GitHub in terms of high star ratings does not imply their security integrity.
Overall, the findings suggest that code repositories should be thoroughly evaluated before being used in software development.
The novelty of this paper resides in the development of new knowledge as well as the study pattern that may be used to other investigations.
Related Results
Joint Beamforming and Aerial IRS Positioning Design for IRS-assisted MISO System with Multiple Access Points
Joint Beamforming and Aerial IRS Positioning Design for IRS-assisted MISO System with Multiple Access Points
<p><code>Intelligent reflecting surface (IRS) is a promising concept for </code><code><u>6G</u></code><code> wireless communications...
Joint Beamforming and Aerial IRS Positioning Design for IRS-assisted MISO System with Multiple Access Points
Joint Beamforming and Aerial IRS Positioning Design for IRS-assisted MISO System with Multiple Access Points
<p><code>Intelligent reflecting surface (IRS) is a promising concept for </code><code><u>6G</u></code><code> wireless communications...
A taxonomy of endpoint vulnerabilities and affected blockchain architecture layers
A taxonomy of endpoint vulnerabilities and affected blockchain architecture layers
AbstractBlockchain technology has gained significant attention and adoption due to its decentralized nature, and promising secure and immutable transactions. The interpretation of ...
Wolf–Rayet stars in the Small Magellanic Cloud as testbed for massive star evolution
Wolf–Rayet stars in the Small Magellanic Cloud as testbed for massive star evolution
Context. The majority of the Wolf–Rayet (WR) stars represent the stripped cores of evolved massive stars who lost most of their hydrogen envelope. Wind stripping in single stars is...
Chandra X-ray analysis of Herbig Ae/Be stars
Chandra X-ray analysis of Herbig Ae/Be stars
ABSTRACT
Herbig Ae/Be (HAeBe) stars are intermediate-mass pre-main-sequence stars, characterized by infrared (IR) excess and emission lines. They are observed to emi...
Systematic Evaluation of AI-Generated Python Code: A Comparative Study across Progressive Programming Tasks
Systematic Evaluation of AI-Generated Python Code: A Comparative Study across Progressive Programming Tasks
Abstract
Background: AI-based code assistants are on the rise in software development as powerful technologies offering streamlining of code generation and better-quality c...
A large-scale analysis of bioinformatics code on GitHub
A large-scale analysis of bioinformatics code on GitHub
AbstractIn recent years, the explosion of genomic data and bioinformatic tools has been accompanied by a growing conversation around reproducibility of results and usability of sof...
Open clusters
Open clusters
Context.Stellar physical properties of star clusters are poorly known and the cluster parameters are often very uncertain.Aims.Our goals are to perform a spectrophotometric study o...

