Skip to main content

Showing 1–2 of 2 results for author: Bono, F

Searching in archive cs. Search in all archives.
.
  1. arXiv:2505.07522  [pdf, ps, other

    cs.SE

    Byam: Fixing Breaking Dependency Updates with Large Language Models

    Authors: Frank Reyes, May Mahmoud, Federico Bono, Sarah Nadi, Benoit Baudry, Martin Monperrus

    Abstract: Application Programming Interfaces (APIs) facilitate the integration of third-party dependencies within the code of client applications. However, changes to an API, such as deprecation, modification of parameter names or types, or complete replacement with a new API, can break existing client code. These changes are called breaking dependency updates; It is often tedious for API users to identify… ▽ More

    Submitted 25 September, 2025; v1 submitted 12 May, 2025; originally announced May 2025.

  2. arXiv:2407.18760  [pdf, ps, other

    cs.CR cs.SE

    Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order

    Authors: Frank Reyes, Federico Bono, Aman Sharma, Benoit Baudry, Martin Monperrus

    Abstract: Java projects frequently rely on package managers such as Maven to manage complex webs of external dependencies. While these tools streamline development, they also introduce subtle risks to the software supply chain. In this paper, we present Maven-Hijack, a novel attack that exploits the order in which Maven packages dependencies and the way the Java Virtual Machine resolves classes at runtime.… ▽ More

    Submitted 28 August, 2025; v1 submitted 26 July, 2024; originally announced July 2024.

    Comments: 8 pages, added a mitigation chapter

    Journal ref: Proceedings of ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED), 2025