Martin Monperrus
3 indexed papers
Publications per year
Top categories
Frequent co-authors
Research Timeline
The paper introduces 'software supply chain smells,' structural indicators of security risks in third-party dependencies, and presents Dirty-Waters, a tool that detects these smells, finding that different ecosystems (Maven vs. NPM) exhibit distinct security weaknesses.
This paper provides the first comprehensive study of cryptographic API misuse detection in Go, evaluating four state-of-the-art tools and discovering 7,473 instances of cryptographic API misuses across 328 open-source projects.
zkSBOM introduces a zero-knowledge mechanism for sharing Software Bills of Materials (SBOMs) that allows consumers to check for vulnerabilities without suppliers revealing the full, sensitive contents of the SBOM.
Papers
zkSBOM: Privacy-Preserving SBOM Sharing with Zero-Knowledge Sets
Tom Sorger, Eric Cornelissen, Aman Sharma, Javier Ron +2 more
zkSBOM introduces a zero-knowledge mechanism for sharing Software Bills of Materials (SBOMs) that allows consumers to check for vulnerabilities without suppliers revealing the full, sensitive contents…