Supporting Upstream Vulnerability Triage in Fork-Based Development: A Brazilian Government Experience

Resumo


Open-source software reuse accelerates the development of complex systems, but it also introduces software supply chain risks when downstream projects evolve independently from their upstream codebases. This challenge is particularly relevant in fork-based development, where security fixes disclosed upstream must be assessed, prioritized, and adapted under project-specific constraints. This paper reports a Brazilian government experience in monitoring upstream vulnerabilities for a secure mobile communication app derived from Matrix/Element open-source clients. We present an automated workflow that combines CPE-based queries to the National Vulnerability Database with advisory mining from the GitHub Advisory Database, enriches vulnerability records with CWE information, and extracts metadata from upstream vulnerability-fixing commits. Rather than replacing human assessment, the workflow provides structured evidence for AppSec-mediated decision-making among development, security testing, and DevSecOps teams. The experience shows how upstream vulnerability monitoring can support downstream triage, remediation planning, patch inspection, and documented downstream security assessment. Our findings highlight that vulnerability management in fork-based projects is not only a technical detection problem, but also an organizational coordination challenge involving evidence-driven, contextual analysis, and security governance.

Referências

Akhoundali, J., Nouri, S. R., Rietveld, K., and Gadyatskaya, O. (2024). Morefixes: A large-scale dataset of cve fix commits mined through enhanced repository discovery. In Proceedings of the 20th International Conference on Predictive Models and Data Analytics in Software Engineering, PROMISE 2024, page 42–51, New York, NY, USA. Association for Computing Machinery.

Alomari, H. W., Vendome, C., and Gyawali, H. (2025). A slicing-based approach for detecting and patching vulnerable code clones. In 2025 IEEE/ACM 33rd International Conference on Program Comprehension (ICPC), pages 60–72, Los Alamitos, CA, USA. IEEE Computer Society.

Bhandari, G., Naseer, A., and Moonen, L. (2021). Cvefixes: automated collection of vulnerabilities and their fixes from open-source software. In Proceedings of the 17th International Conference on Predictive Models and Data Analytics in Software Engineering, PROMISE 2021, page 30–39, New York, NY, USA. Association for Computing Machinery.

Businge, J., Openja, M., Nadi, S., and Berger, T. (2022). Reuse and maintenance practices among divergent forks in three software ecosystems. Empirical Softw. Engg., 27(2).

Cheng, Y., Zhang, T., Shar, L. K., Yang, S., Dong, C., Lo, D., Lv, S., Shi, Z., and Sun, L. (2026). Vercation: Precise vulnerable open-source software version identification based on static analysis and llm. IEEE Transactions on Software Engineering, 52(2):376–394.

Element (2023). Digital sovereignty is built on an open standard that enables federation. [link]. Accessed: 2026-05-01.

Hommersom, D., Sabetta, A., Coppola, B., Nucci, D. D., and Tamburri, D. A. (2024). Automated mapping of vulnerability advisories onto their fix commits in open source repositories. ACM Trans. Softw. Eng. Methodol., 33(5).

Imamura, D., Ishio, T., Kula, R. G., and Matsumoto, K. (2022). Bug-fix variants: Visualizing unique source code changes across github forks. In 2022 Working Conference on Software Visualization (VISSOFT), pages 157–161.

Li, F. and Paxson, V. (2017). A large-scale empirical study of security patches. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS ’17, page 2201–2215, New York, NY, USA. Association for Computing Machinery.

Martins, J. A., Rego, P. A., de Macêdo, J. A., Silva, F. A., and Lagrota, V. (2026). Matrix protocol: a comprehensive systematic mapping study. Journal of Cloud Computing, 15(1):20.

Mohayeji, H., Agaronian, A., Constantinou, E., Zannone, N., and Serebrenik, A. (2025). Securing dependencies: A comprehensive study of dependabot’s impact on vulnerability mitigation. Empirical Softw. Engg., 30(3).

Nguyen, T. G., Le-Cong, T., Kang, H. J., Le, X.-B. D., and Lo, D. (2022). Vulcurator: a vulnerability-fixing commit detector. In Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, ESEC/FSE 2022, page 1726–1730, New York, NY, USA. Association for Computing Machinery.

Ponta, S. E., Plate, H., and Sabetta, A. (2020). Detection, assessment and mitigation of vulnerabilities in open source dependencies. Empirical Softw. Engg., 25(5):3175–3215.

Salman, H. E. (2021). Feature-based insight for forks in social coding platforms. Inf. Softw. Technol., 140(C).

Sun, Q., Xu, L., Xiao, Y., Li, F., Su, H., Liu, Y., Huang, H., and Huo, W. (2022). Verjava: Vulnerable version identification for java oss with a two-stage analysis. In 2022 IEEE International Conference on Software Maintenance and Evolution (ICSME), pages 329–339.

Sung, C., Lahiri, S. K., Kaufman, M., Choudhury, P., Wolk, J., and Wang, C. (2020). Towards understanding and fixing upstream merge induced conflicts in divergent forks: an industrial case study. In Proceedings of the ACM/IEEE 42nd International Conference on Software Engineering: Companion Proceedings, ICSE ’20, page 320–321, New York, NY, USA. Association for Computing Machinery.

Williams, L., Benedetti, G., Hamer, S., Paramitha, R., Rahman, I., Tamanna, M., Tystahl, G., Zahan, N., Morrison, P., Acar, Y., Cukier, M., Kästner, C., Kapravelos, A., Wermke, D., and Enck, W. (2025). Research directions in software supply chain security. ACM Trans. Softw. Eng. Methodol., 34(5).

Woo, S., Park, S., Kim, S., Lee, H., and Oh, H. (2021). Centris: A precise and scalable approach for identifying modified open-source software reuse. In Proceedings of the 43rd International Conference on Software Engineering, ICSE ’21, page 860–872. IEEE Press.
Publicado
01/09/2026
DAMASCENO, José Renan F.; ROCHA, Lincoln; REGO, Paulo. Supporting Upstream Vulnerability Triage in Fork-Based Development: A Brazilian Government Experience. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 1134-1149. DOI: https://doi.org/10.5753/sbseg.2026.29301.

Artigos mais lidos do(s) mesmo(s) autor(es)

1 2 3 > >>