Workshop · 2014
The Vulnerability Dataset of a Large Software Ecosystem
Dimitris Mitropoulos, Georgios Gousios, Panagiotis Papadopoulos, Vassilios Karakoidas, Panos Louridas, Diomidis Spinellis
The same Maven-wide static analysis, cut to its security findings and released as a vulnerability dataset — every project version, its security-related FindBugs results, its size and its dependencies.
- Published in
- Proceedings of the 3rd International Workshop on Building Analysis Datasets and Gathering Experience Returns for Security (BADGERS 2014), colocated with ESORICS 2014
- Citations
- 6 on Google Scholar, read 5 September 2026 — 19 of 30 by count
- Cite as
- MKPLGS14
The idea
Security bugs differ from other defects in consequence rather than in kind: one of them lets an attacker redirect the whole application, and a disclosure measurably moves a vendor's market value. FindBugs sorts its findings into nine categories, two of which — Security and Malicious Code — are about exactly that. Isolating those across an entire ecosystem gives a dataset for studying how vulnerabilities behave over time, rather than how a single project's did.
Contributions
- A dataset of security-related static-analysis findings over the whole Maven Central repository — 115,214 JARs, approximately 265 GB — with per-version metadata.
- The construction process, designed as a distributed pipeline for that volume.
- Worked examples of the research questions the data can answer.
Where it sits
It is the security-focused companion to the bug catalog, and supplies the data for Dismal Code, which studies how those bugs evolve.
Written from the paper itself — the PDF linked above, which this site hosts.