遇见数据集

remediation

收藏
Zenodo2026-09-26 更新2026-10-01 收录
官方服务:

资源简介:

TacticFix Artifact This artifact accompanies our study of tactic-aware vulnerability remediation. It contains the TacticFix implementation, benchmark, executable oracles, retrieval data, evaluation scripts, prompts, and archived per-case results. The artifact includes: A canonical benchmark of 118 real-world vulnerability-remediation cases: 93 npm, 15 PyPI, and 10 Maven cases. Six remediation tactics: version adjustment, alternative libraries, bypassing, configuration changes, patching, and re-initialization. Executable vulnerability oracles and regression checks. Frozen GitHub issue context and a prebuilt ChromaDB retrieval index. Evaluation harnesses for TacticFix, general-purpose agents, LLM baselines, version-based tools, model backends, and ablation variants. Per-case outputs and documentation of benchmark, prompt, RAG, and result provenance. To validate the packaged benchmark, result files, oracle paths, and retrieval collections, run: python3 scripts/validate_artifact.py For the complete offline smoke test, including 455 oracle fault-injection checks, run: ./run_smoke_test.sh Fresh end-to-end evaluations require the corresponding language toolchains, model credentials, and cloned target repositories. Generated environments, third-party repository clones, package caches, and credentials are intentionally excluded. Please see README.md for setup and execution instructions, and docs/ for detailed benchmark, prompt, RAG, CodeQL, and result documentation.

提供机构:
Zenodo
创建时间:
2026-09-26
二维码
社区交流群
二维码
科研交流群
商业服务