py2src: Towards the Automatic (and Reliable) Identification of Sources for PyPI Package
Selecting which libraries (‘dependencies’ or ‘packages’ in the industry’s jargon) to adopt in a project is an essential task in software development. The quality of the corresponding source code is a key factor behind this selection (from security to timeliness). Yet, how easy is it to find the ‘actual’ source? How reliable is this information? To address this problem, I developed an approach called py2src to automatically identify GitHub source code repositories corresponding to packages in PyPI and automatically provide an indicator of the reliability of such information. I also report a preliminary empirical evaluation.
I am a Ph.D. student at the University of Trento. My research interests are software supply chain security and malware detection.
Tue 16 NovDisplayed time zone: Hobart change
18:30 - 20:15 | |||
18:30 20mTalk | A Program Synthesis Approach for Adding Architectural Tactics to An Existing Code Base Student Research Competition Ali Shokri Rochester Institute of Technology Pre-print | ||
18:50 20mTalk | Program Synthesis with Algorithm Pseudocode Guidance Student Research Competition Zihui Wang National University of Defense Technology | ||
19:10 20mTalk | py2src: Towards the Automatic (and Reliable) Identification of Sources for PyPI Package Student Research Competition Duc Ly Vu University of Trento, Italy Pre-print | ||
19:30 45mPanel | Judging and awards Student Research Competition |