All publications

Workshop · 2014

The Vulnerability Dataset of a Large Software Ecosystem

Dimitris Mitropoulos, Georgios Gousios, Panagiotis Papadopoulos, Vassilios Karakoidas, Panos Louridas, Diomidis Spinellis

The same Maven-wide static analysis, cut to its security findings and released as a vulnerability dataset — every project version, its security-related FindBugs results, its size and its dependencies.

Published in
Proceedings of the 3rd International Workshop on Building Analysis Datasets and Gathering Experience Returns for Security (BADGERS 2014), colocated with ESORICS 2014
Citations
6 on Google Scholar, read 5 September 2026 — 19 of 30 by count
Cite as
MKPLGS14
the bug catalog

The idea

Security bugs differ from other defects in consequence rather than in kind: one of them lets an attacker redirect the whole application, and a disclosure measurably moves a vendor's market value. FindBugs sorts its findings into nine categories, two of which — Security and Malicious Code — are about exactly that. Isolating those across an entire ecosystem gives a dataset for studying how vulnerabilities behave over time, rather than how a single project's did.

Contributions

  • A dataset of security-related static-analysis findings over the whole Maven Central repository — 115,214 JARs, approximately 265 GB — with per-version metadata.
  • The construction process, designed as a distributed pipeline for that volume.
  • Worked examples of the research questions the data can answer.

Where it sits

It is the security-focused companion to the bug catalog, and supplies the data for Dismal Code, which studies how those bugs evolve.

Written from the paper itself — the PDF linked above, which this site hosts.