Back to Debian
GSoC 2026

Attack of the Clones: Fight Back Using Code Duplication Detection From Security Patches

This project aims to detect vulnerable code clones in the Debian archive by automatically extracting signatures from security patches. Using a two-signal approach that separates vulnerable patterns from fix patterns, the system generates high-specificity queries to search the entire archive via Debian CodeSearch. A verification pipeline with language-aware filtering ensures that detected clones are truly unpatched instances of the vulnerability. The project delivers a complete, scalable pipeline that integrates with Debian Security Tracker workflows and produces actionable reports, significantly reducing manual effort and improving vulnerability propagation detection across the ecosystem.

Project details

Contributor

Gajendra Nath Soren

Mentors

Not available

Technologies

Not listed in the archive