Coder Social home page Coder Social logo

yhtcug / efda Goto Github PK

View Code? Open in Web Editor NEW

This project forked from srcclr/efda

0.0 1.0 0.0 28.18 MB

Evaluation Framework for Dependency Analysis (EFDA)

License: Apache License 2.0

Go 0.04% Java 0.03% JavaScript 0.01% Ruby 0.01% Objective-C 0.02% PHP 0.01% Python 0.01% Scala 0.01% C# 0.08% Makefile 0.79% Shell 4.23% M4 0.82% C 93.87% Roff 0.05% C++ 0.01% CMake 0.04%

efda's Introduction

Evaluation Framework for Dependency Analysis

If you are...

  • Using open-source libraries,
  • Using package managers to manage project dependencies,
  • Concern about security vulnerabilities in the libraries you use,
  • Deciding what product to use for checking open-source vulnerabilities,

then this open-source project is tailored for you!

Evaluation Framework For Dependency Analysis is a project that allows users to test the dependency analysis tool of their choice and see how accurate the tool is. We hope that with this project, users can compare the different dependency analysis/open-source security scanners out in the market and decide which tool works best for them.

This project comprises of projects implemented on different languages, build systems and possibly different type of setups for each build system. Each project also has a README file to describe the expected output of testing against the project (number of direct dependencies, transitive dependencies, etc).

What is included in this project?

Projects implemented in:

  • Golang
  • Java
  • Ruby
  • Python
  • JavaScript
  • Objective-C
  • PHP
  • Scala
  • C/C++
  • C#

An EFDA Spreadsheet that allows you to track the languages/package managers/features supported by the dependency analysis tool of your choice, customize the importance of each feature, and compute a score for the tool.

EFDA Spreadsheet screenshot

Frequently Asked Questions

I don't see any project implemented on the build system of my choice. Can I contribute?

Yes of course! If you do not see the programming language/build system or even a particular tricky setup of a build system of your choice, feel free to send a pull request to us.

Are the results reliable?

The projects are made simple on purpose. The point is to create projects with dependencies that we can easily track so that we can easily verify the output is correct. This means the projects usually consist of only a few dependencies and little code.

We are also testing the support for different project setups. For example, in the java/maven/ directory, you can find projects with different types of Maven setup e.g. multi-modules, interpolated variables etc. A good dependency analysis tool should be able to support features provided by the build system.

efda's People

Contributors

ayrx avatar codelion avatar curphey avatar dariusf avatar domainexpert avatar hendychua avatar spencerxiao avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.