Open Source Vulnerabilities (OSV) database
收藏资源简介:
Open Source Vulnerabilities (OSV)数据库是由多个公开来源收集的数据集,本文中使用的数据集是基于该数据库的一个快照,包含了CRAN、Go、Maven、npm、PyPI和RubyGems六个流行编程语言生态系统的信息。数据集记录了在这些生态系统中检测到的恶意软件上传情况,以及相关的安全通告和媒体报道。该数据集旨在分析软件生态系统的安全风险,特别是恶意软件上传的长期趋势。
The Open Source Vulnerabilities (OSV) database is a dataset compiled from multiple public sources. The dataset utilized in this study is a snapshot derived from this database, which contains information across six widely adopted programming language ecosystems: CRAN, Go, Maven, npm, PyPI, and RubyGems. This dataset documents detected malware uploads within these ecosystems, alongside associated security advisories and media reports. Its primary objective is to analyze the security risks of software ecosystems, with a specific focus on the long-term trends of malware uploads.




