Automated Identification of Vulnerability-Fixing Patches
Develop an automated method that, given a known vulnerability in an open-source software project, identifies the exact source-code commit (patch) in the project's revision control history that fixes the vulnerability, without relying on manual curation.
References
Revision control software makes patches possible by recording all the historical changes. However, automatic identification of patches is an unsolved problem.
— ARVO: Atlas of Reproducible Vulnerabilities for Open Source Software
(2408.02153 - Mei et al., 4 Aug 2024) in Section 2.2 (Patch Locating)