MétaCan
Menu
← Back to cohort
Record W7133323927 · doi:10.5281/zenodo.18845271

OSSVul - ReplicationPackage

2025· article· en· W7133323927 on OpenAlexaff
Sara Al Hajj Ibrahim

Bibliographic record

VenueZenodo (CERN European Organization for Nuclear Research) · 2025
Typearticle
Languageen
FieldComputer Science
TopicSoftware Engineering Research
Canadian institutionsUniversity of Toronto
Fundersnot available
KeywordsScripting languageSoftwareVulnerability (computing)Artifact (error)Component (thermodynamics)Identification (biology)Data collectionTimestamp

Abstract

fetched live from OpenAlex

OSS Vulnerability Dataset and Model Evaluation Framework This archive contains both datasets and experimental code used in a study on open-source software vulnerability detection. It integrates vulnerability information from the National Vulnerability Database (NVD) with software development artifacts extracted from GitHub and provides a unified framework for constructing datasets and evaluating multiple vulnerability detection models. The archive provides the data processing pipeline, curated datasets, and experimental scripts used in the study. Vulnerability detection is performed at the sample level with results aggregated at the CVE level to reflect practical vulnerability identification scenarios. Contents CVE Data Collection Model Data Collection Model Experiments CVE_data.xlsx CVE Data Collection This component includes scripts used to construct a unified CVE dataset. CVE records from 1999 to July 2024 were collected from the National Vulnerability Database (NVD) and consolidated into the file CVE_data.xlsx. References to GitHub artifacts, including commits, pull requests, and issues, were extracted from CVE entries and filtered to retain valid artifacts. Artifact creation timestamps and temporal metrics were computed for time-aware analysis. Model Data Collection This component provides scripts for constructing model-specific inputs. Datasets were generated at the artifact levels and include both vulnerable and non-vulnerable samples. Due to dataset size, intermediate CSV outputs were merged during preprocessing, and temporal ordering was preserved by splitting the data into RQ2 and RQ3 subsets, presented in experimental datasets. Model Experiments This component contains experimental code, configurations, and datasets used to evaluate the following vulnerability detection models: MemVul VulCurator PatchRNN LineVul DeepTraVul Experiments are conducted independently for each model using a consistent evaluation protocol. All models operate at the sample level, and a CVE is considered vulnerable if at least one associated sample is predicted as vulnerable. Notes All datasets and experimental scripts required to reproduce the reported results are included in this archive.The CVE dataset is provided in the file CVE_data.xlsx.This archive is intended to support reproducible research on software vulnerability detection.

Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.

How this classification was reachedexpand

Full frame machine prediction

Teacher imitation

Not calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.

metaresearch head score (Codex)0.005
metaresearch head score (Gemma)0.023
Version: metacan-v3-hybrid-931329e0061cValidation status: machine_predicted_unvalidated
Candidate categoriesMetaresearch
Consensus categoriesnone
DomainCandidate signal: Reproducibility · Consensus signal: none
Study designCandidate signal: Not applicable · Consensus signal: Not applicable
GenreCandidate signal: Dataset · Consensus signal: Dataset
Teacher disagreement score0.995
Threshold uncertainty score0.070

Distilled classifier scores by category (both heads)

CategoryCodexGemma
Metaresearch0.0050.023
Meta-epidemiology (narrow)0.0020.001
Meta-epidemiology (broad)0.0010.002
Bibliometrics0.0040.003
Science and technology studies0.0010.001
Scholarly communication0.0030.003
Open science0.0030.003
Research integrity0.0010.002
Insufficient payload (model declined to judge)0.0210.014

Machine scores (provisional)

The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.

Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.

Opus teacher head0.021
GPT teacher head0.254
Teacher spread0.232 · how far apart the two teachers sit on this one work
Validation statusscore_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from it

Classification

machine, unvalidated

Machine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.

Study designNot applicable
DomainReproducibility
GenreDataset

How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".

Quick stats

Citations0
Published2025
Admission routes1
Has abstractyes

Explore more

Same venueZenodo (CERN European Organization for Nuclear Research)→Same topicSoftware Engineering Research→French-language works237,207→