There is a newer version of the record available.

Published August 9, 2023 | Version v1
Dataset Restricted

A manually-curated categorisation of Java Maven libraries along Python PyPI Topics (dataset)

  • 1. University of Trento
  • 2. Vrije Universiteit

Description

This dataset reports 256 manually-curated open-source Java libraries from Maven Central with high- or critical-severity CVEs. Each library was assigned a category based on its main functionality. Categories mirror the Topic classifier from the Python Package Index (PyPI), allowing cross-language comparisons of libraries with equivalent functionality.


The results of this process are:

  1. the protocol designed to interpret sources for category assessment, and arbitrate the results;
  2. the sources and metadata, including CVEs, collected for the categorisation;
  3. the set of categorised libraries and CVE statistics, including a higher-level classification into Local or Remote network functionalities.

This can be used as ground truth for (cross-language, statistical) studies on the libraries from functional and security perspectives.

Files

Restricted

The record is publicly accessible, but files are restricted. Log in to check if you have access.

Request access

If you would like to request access to these files, please fill out the form below.

You need to satisfy these conditions in order for this request to be accepted:

Reviewing for the submission to Open Science in Software Engineering.

You are currently not logged in. Do you have an account? Log in here

Additional details

Funding

European Commission
ProSVED - Projection of Security Vulnerabilities caused by Exploits in Dependencies 101067199
European Commission
AssureMOSS - Assurance and certification in secure Multi-party Open Software and Services. 952647