遇见数据集

Replication resources for paper: "A Large Scale Empirical Analysis on the Adherence Gap between Standards and Tools in SBOM"

收藏
Zenodo2026-01-26 更新2026-05-26 收录
官方服务:

资源简介:

Replication resources for paper: "A Large Scale Empirical Analysis on the Adherence Gap between Standards and Tools in SBOM" Usage The code repository is at https://github.com/dw763j/SAP, this zenodo includes the generated SBOMs and test code. The all-sboms.zip includes all the 27,795 SBOMs of 3,287 repositories generated by the six tools in either CycloneDX or SPDX standards as described in paper. The run-on-test-sboms.zip includes codes and some SBOMs for fast test purpose. Download and unzip run-on-test-sboms.zip, cd into the dir and run `pip install -r requirements.txt` and then run `python test-run.py`, you will get the analysis results on the test-sboms. If you want to rerun the whole process of SAP on all SBOMs, download and unzip the all-sboms.zip(around 50GB after unzip), and change the dirs in test-run.py(need to follow the language dir structure) and rerun again(clean up of the results dir is recommended).v1.1: minor code refactor. v1.2: minor code refactor.

论文《软件物料清单(Software Bill of Materials, SBOM)中标准与工具间依从性差距的大规模实证分析》的复现资源 使用方式 本项目代码仓库位于 https://github.com/dw763j/SAP,本Zenodo存档包含生成的SBOM与测试代码。 all-sboms.zip 中包含论文所述的、由6款工具生成的3287个代码仓库对应的27795份SBOM,格式涵盖CycloneDX与SPDX标准。 run-on-test-sboms.zip 则包含用于快速测试的代码与部分SBOM。 下载并解压run-on-test-sboms.zip,进入对应目录后执行`pip install -r requirements.txt`,随后运行`python test-run.py`,即可获得针对测试SBOM的分析结果。 若需在全量SBOM上复现SAP的完整流程,请下载并解压all-sboms.zip(解压后体积约50GB),修改test-run.py中的目录路径(需遵循对应语言的目录结构)后重新运行(建议提前清理结果目录)。 v1.1:小幅代码重构。 v1.2:小幅代码重构。

提供机构:
Zenodo
创建时间:
2025-03-10
二维码
社区交流群
二维码
科研交流群
商业服务