Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

35 results about "Software build" patented technology

In the field of software development, the term build is similar to that of any other field. That is, the construction of something that has an observable and tangible result. Historically, build has often referred either to the process of converting source code files into standalone software artifact(s) that can be run on a computer, or the result of doing so. However, this is not the case with technologies such as Perl, Ruby or Python which are examples of interpreted languages.

Computer-based system to validate build integrity of software products

Techniques are described for validating build integrity of software products, such as applications or containers. More specifically, this disclosure describes a build integrity validation system that analyzes build artifacts resulting from a software build process to create source code assertions, and compares the assertions against the source code from which the build artifacts were produced. The build integrity validation system validates that a particular build artifact is producible by the source code to ensure that no additional code was introduced during the build process. The build integrity validation system may also reverse the analysis to validate that the source code is able to produce the build artifacts to ensure that no code was removed or modified during the build process. The build integrity validation system identifies and reports identified discrepancies between the source code and the build artifacts resulting from the software build process of the source code.
Owner:WELLS FARGO BANK NA

Hardware enforcement of boundaries on the control, space, time, modularity, reference, initialization, and mutability aspects of software

Modifications to existing computer hardware, compiler changes or source-to-source transforms performed during the software build process, and a collection of libraries and modifications to existing standard system software and libraries. The invention allows a program author to enforce various kinds of locality of causality in software to provide enforcement of boundaries for the following aspects of a computer program: control, space, time, modularity, reference, initialization, and mutability. Where these properties do not suffice to guarantee a property at static time, dynamic checks may be added and the constraints on control flow prevent such dynamic checks from being avoided by the program.
Owner:WHOLE SKY TECH CO

Securing secrets in software build workflows involving modular build code

Techniques are described for securing secrets in software build workflows. In some implementations, build instructions call for execution of a first program module and a second program module, where the first program module has been approved to make a privileged request, but the second program module has not. The first program module can be stored in a trusted repository, separately from the second program module. When the first program module is loaded for execution, a cryptographic signature can be validated to determine that the first program module is authentic and as a condition for passing a privileged credential to the first program module. The second program module has no access to the privileged credential. Instead, when the second program module is loaded for execution, a determination can be made whether the second program module makes any privileged requests. Any privileged requests from the second program module will not be fulfilled.
Owner:SALESFORCE INC

Correlating outbound traffic and file events with a CI / CD pipeline

The disclosed system and process involve correlating outbound traffic with a CI / CD pipeline. CI / CD Pipelines consist of multiple jobs, and each job's steps execute on the same runner host. Network monitors relay information about domain names and network connections during job execution to the data store. Once all pipeline jobs are complete, the correlation server links domain names and connections to determine endpoints. This correlation, showing outbound traffic for each step, is accessible to the pipeline owner for review. An alert is triggered for new endpoints relative to the baseline. Owners can block unexpected endpoints based on explicitly defined lists. The correlation server also identifies file events, aiding in detecting suspicious file and software build overwrite events for combating software supply chain attacks. Observed file and network events contribute to generating a Software Bill of Materials (SBOM) through runtime events.
Owner:STEP SECURITY INC

Decision engine for software integrity and releasability

Discussed herein are devices, systems, machine-readable media, and methods for assessing a software build for a vulnerability, generating release recommendations, and implementing a remedial action to mitigate security risks. A method includes receiving a Software Bill of Materials (SBOM) that lists one or more libraries used in a software build, receiving a user-specified administration policy, generating an over overall provenance bundle from a metadata of the one or more libraries used in the software build, implementing a gradient boosted tree algorithm using both the overall provenance bundle and the user-specified administration policy to generate a software releasability recommendation, receiving the software releasability recommendation into a Large Language Model (LLM) to generate a recommendation report detailing one or more software vulnerabilities, and implementing the software releasability recommendation by releasing the software build or blocking the release of the software build based on the software releasability recommendation.
Owner:RAYTHEON CO

Hardware enforcement of boundaries on the control, space, time, modularity, reference, initialization, and mutability aspects of software

Modifications to existing computer hardware, compiler changes or source-to-source transforms performed during the software build process, and a collection of libraries and modifications to existing standard system software and libraries. The invention allows a program author to enforce various kinds of locality of causality in software to provide enforcement of boundaries for the following aspects of a computer program: control, space, time, modularity, reference, initialization, and mutability. Where these properties do not suffice to guarantee a property at static time, dynamic checks may be added and the constraints on control flow prevent such dynamic checks from being avoided by the program.
Owner:WHOLE SKY TECH CO

Mirror management method, system, and computing device

This application relates to the field of computer software technology, providing an image management method, system, and computing device. The method is applied to a computing device equipped with a software integration system, including: responding to a code repository corresponding to the software integration system receiving a commit instruction, detecting the change status of the image configuration file; the change status is used to identify whether any instruction text in the image configuration file has changed; if the change status is "changed," loading the changed image configuration file; generating an image build instruction based on each instruction text in the image configuration file; generating an image file according to the image build instruction; and storing the image file in the image repository of the software integration system. Based on this solution, the computing device utilizes changes to the image configuration file to trigger the automatic generation and updating of image files, decoupling the image file generation process from the software package delivery request, avoiding repeated image building for each package delivery, and improving software build efficiency.
Owner:XFUSION DIGITAL TECH CO LTD

Typo squatting, dependency confusion, and brandjacking detection

A software build environment is scanned for one or more potentially malicious code paths. In response to scanning the software build environment for the one or more potentially malicious code paths, one or more potentially malicious code paths are identified. The identified one or more potentially malicious code paths comprise at least one of: a typo squat code path, a dependency confusion code path, and a brandjack code path. In response to identifying the one or more potentially malicious code paths a microprocessor does at least one of: generate a notification identifying the one or more potentially malicious code paths, automatically change and / or remove the one or more potentially malicious code paths and deny the start of a build process.
Owner:MICRO FOCUS LLC

Automated software build capacity incorporating code generated in software development environments with varying levels of security

Systems and methods are provided for automatically building software in a secure environment. A system includes a software development environment, having an associated security level. The software development environment generates an encrypted software module containing a software module and a cryptographic hash representing a content of the software module and provides it to a software repository. The software repository, in response to receipt of a build plan, decrypts the encrypted software module to recover the software module and the cryptographic hash representing the content of the software module, generates a new cryptographic hash for the software module, and verifies that the new cryptographic hash matches the cryptographic hash representing the content of the software module. A build environment receives the plurality of software modules from the software repository and generates a software build from the plurality of software modules based upon the build plan.
Owner:NORTHROP GRUMMAN SYSTEMS CORP

Managing software artifact snapshot repositories using definition files

Techniques are provided for managing software artifact snapshot repositories using definition files. One method comprises obtaining a definition file for a software artifact snapshot repository to be created in association with a given software application, wherein the definition file comprises information characterizing software artifacts used by the given software application to be included in the software artifact snapshot repository; and creating the software artifact snapshot repository, using the definition file, with the one or more software artifacts, wherein a software build of the given software application obtains at least some of the software artifacts using the created software artifact snapshot repository. At least some of the software artifacts included in the software artifact snapshot repository may be automatically updated in response to determining that a content of the software artifact snapshot repository does not match a current version of the definition file.
Owner:DELL PROD LP

External formula editing component calling method and device for artificial intelligence proposition, equipment and storage medium

The embodiment of the invention discloses an external formula editing component calling method and device for an artificial intelligence proposition, equipment and a storage medium. The external formula editing component calling method comprises the following steps: in response to a request of an application platform, creating an OLE container on the application platform, and creating a component identifier of an external formula editing component; the external formula editing component comprises a desktop formula editor component or a third-party office software built-in formula component; in response to a formula editing requirement of an application platform, obtaining a component identifier through the COM component registry; dynamically loading the external formula editing component into an OLE container based on the component identifier; and the function calling of the application platform on the external formula editing component is realized through the IIDspatch interface of the external formula editing component. By means of the mode, cross-platform calling of the external formula editing assembly is achieved, a user can call the external formula editing assembly on the application platform, operation is convenient and efficient, and the problem of formula errors caused by cross-platform use is avoided.
Owner:SHENZHEN SEA SKY LAND TECH

Computer-based system to validate build integrity of software products

Techniques are described for validating build integrity of software products, such as applications or containers. More specifically, this disclosure describes a build integrity validation system that analyzes build artifacts resulting from a software build process to create source code assertions, and compares the assertions against the source code from which the build artifacts were produced. The build integrity validation system validates that a particular build artifact is producible by the source code to ensure that no additional code was introduced during the build process. The build integrity validation system may also reverse the analysis to validate that the source code is able to produce the build artifacts to ensure that no code was removed or modified during the build process. The build integrity validation system identifies and reports identified discrepancies between the source code and the build artifacts resulting from the software build process of the source code.
Owner:WELLS FARGO BANK NA

Securing an application programming interface (“API”) during the build of a software development kit (“SDK”)

Described is a technique for securing a private secret key during a software build process for a software development kit (SDK) that includes a code implementation for an application programming interface (API), where the private secret key is for use in signing the payload of an API request for the API. Consistent with examples, a keychain service stores a private secret key. In at least one source code file for a SDK, the source code includes a macro definition, which, upon executing by a compiler, obtains a value for the private secret key. In a programming shell environment, a shell script is executed. Execution of the shell script results in executing a nested script, which queries the keychain service for the private secret key. The shell script then passes the private secret key to a build script of an automated software build tool / system, which injects the private secret key into the source code file at compile time by execution of the macro, resulting in a software product capable of using the private secret key to sign or encrypt the payload of one or more API requests.
Owner:SNAP INC

Continuous root cause analysis system for mobile apps via QA-SRE feedback loops

System (100) for continuous root cause analysis of mobile applications via integrated QA-SRE feedback loops, wherein the system comprises the following: a data aggregation module configured to collect structured and unstructured data from test environments, production logs, telemetry, and user feedback; a correlation engine configured to analyze and link quality assurance (QA) test failures with production-level anomalies using pattern recognition and historical mapping; an anomaly detection module that can be operated to detect deviations in application performance using artificial intelligence or machine learning algorithms; a root cause analysis module configured to isolate defects by analyzing stack traces, log events, system resource usage, and device metadata; a feedback loop manager configured to facilitate automated bidirectional communication between QA teams and Site Reliability Engineering (SRE) teams; a recommendation engine configured to generate prioritized problem-solving suggestions based on historical bug data and code commit histories; a context-aware logging module configured to capture runtime environment metadata during both test and production execution; and a central orchestration dashboard coupled with a version control integrator and configured to visualize system insights and link problems to specific software builds or deployments; the system enables real-time detection, diagnosis, and resolution of application problems throughout the entire lifecycle of the mobile application.
Owner:TUNIKUNTLA VENKATA SESHA SAI PRAVEEN

Embedded system build tool and platform

PendingUS20260099325A1Version controlCode compilationSoftware engineeringSoftware build
A software build tool system and method for generating and validating a software build for execution on a target hardware device of an embedded system. The system includes: a user interface subsystem configured for receiving build parameter data pertaining to software from a user; a build tool subsystem configured for receiving the build parameter data from the user interface subsystem and building the software to generate a software build for execution on a target hardware device of an embedded system; and a memory reporter subsystem configured for receiving the software build generated by the build tool subsystem and providing access to target hardware build validation data resulting from and / or used as a part of the software build during execution.
Owner:FCA US LLC

System for network segment isolation with variable configurations in a vehicle

System and method for an in-vehicle network comprising a microcontroller unit (MCU) located within the vehicle, which includes an internal Ethernet switch and an auxiliary core manager, wherein the MCU hosts one or more software builds and the auxiliary core manager manages the internal Ethernet switch and the software builds. An external Ethernet switch located within the vehicle connects one or more ports of the internal Ethernet switch to one or more devices through one or more virtual local area networks (VLANs), wherein, upon a reflash event, the auxiliary core manager generates a VLAN configuration and filter rule for the internal switch that associates the software builds with the MCU ports based on a MAC and IP address of each MCU port.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

Context aware multi-stage software builds

A computer-implemented method according to one approach, is for customizing the selection of stages in a multi-stage software build. The computer-implemented method includes: using information associated with the multi-stage software build to develop situational context of the multi-stage software build. The situational context is converted into a build context and the build context is further converted into a number of build stages. Moreover, the build stages are automatically edited, and the edited stages are executed.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Systems and methods for eager software build

A method and apparatus of a device that builds a target using a plurality of processing units is described. In an exemplary embodiment, the device receives a build file for the target, where the build file identifies a plurality of dependencies and the first target is depended on a second target. In addition, the device generates a directed acyclic graph for the first target from the plurality of dependencies. Furthermore, the device transforms the directed acyclic graph by transforming the first set of dependencies to a second set of dependencies and the second set of dependency includes the first dependency that is from a first node in the first target to a second node of a second target. The device additionally identifies a plurality of independent executable tasks, where each of the plurality of independent executable tasks is executable without an unresolved dependency and at least one of the plurality of executable tasks is associated with the second set of dependencies of the transformed directed acyclic graph. The device further schedules the plurality of independent executable tasks on the plurality of processing units. In addition, the device concurrently executes the plurality of independent executable tasks.
Owner:APPLE INC

SECURITY METHOD FOR PROGRAMMING A COMPUTER PROGRAM ON A CONTROL UNIT

The invention relates to a security method for programming a computer program on a control unit, comprising the following steps executed by a processor in a software build environment in the order mentioned: a. Providing a complete computer program containing user data in a first data format; b. Converting the payload data from a first data format into a second data format and using a flash toolchain adapting the data for infrastructure data and creating a plurality of separate flash containers therefrom, where security mechanisms are checked and checksums are created using the Flashtoolchain, and wherein such a flash container in the second data format comprises payload data with at least one logical block based on at least part of the provided computer program, as well as infrastructure data; c. Flashing at least one flash container created using the flash tool chain from the SoftwareBuild environment to a control unit using a flash tool; d. Uploading at least a portion of the at least one flash container from the control unit to the SoftwareBuild environment; and e. in the SoftwareBuild environment, comparing the uploaded portion of the payload with the originally provided payload and forming a difference. With the validation procedure proposed here, the error-free adaptation of the infrastructure data of a control unit can be reliably verified.
Owner:CARIAD SE

Analyzing scripts to create and enforce security policies in dynamic development pipelines

Disclosed embodiments relate to systems and methods for enforcing security policies in dynamic development pipelines. Techniques include accessing a build script, including a set of instructions for a software build process, parsing the build script to identify a set of scripted build instructions, determining a set of expected build actions based on the scripted build instructions, and constructing a representation of the set of expected build actions. The techniques may further include automatically generating a tiered security policy based on the representation of the set of expected build actions, monitoring a dynamic pipeline running the build script, and enforcing the security policy for the dynamic pipeline environment.
Owner:CYBER ARK SOFTWARE LTD

Information processing method, device and system

The embodiment of the invention provides an information processing method, device and system. The information processing method comprises the steps that a system management request submitted for a target operating system is received; reading reference configuration information and target configuration information associated with the target operating system in a source code tree configuration file according to the system management request; determining an associated operating system having a version iteration relationship with the target operating system, and determining a target source code tree warehouse corresponding to the target operating system and an associated source code tree warehouse corresponding to the associated operating system; and on the basis of the reference configuration information and the target configuration information, software construction source code trees contained in the target source code tree warehouse and the associated source code tree warehouse are updated.
Owner:ALIBABA CLOUD COMPUTING CO LTD

Patch sharing mechanism in open-source environments

Certain users can be notified to manage collaboration for a software build. For example, a service can detect a copy of a file of a software build from an open-source environment being copied into a local repository of a first client device of a first user that is part of authorized users authorized to access the file. The first client device can apply a modification to the copy of the file to generate a modified copy of the file. In response to detecting the file, and prior to the first client device merging the modified copy of the file with the open-source environment, the service can identify a second user of the authorized users. The service can transmit, to a second client device of the second user, a storage notification indicating that the copy of the file has been stored on the first client device for applying the modification.
Owner:RED HAT LLC

Artificial intelligence-driven autonomous development and operations governance system for compliance-aware software delivery

The present invention relates to an artificial intelligence-driven autonomous governance system for compliance-aware software delivery in development and operations environments. The disclosed system is implemented as a dedicated governance device comprising policy ingestion units, deployment signal acquisition units, compliance analysis processors, deployment control units, and secure audit storage units that collectively operate to monitor, evaluate, and enforce regulatory compliance throughout the software lifecycle. Regulatory definitions and organizational compliance rules are normalized into machine-interpretable representations and correlated with software build artifacts, configuration parameters, dependency relationships, and runtime telemetry associated with software deployment events. Machine learning-based compliance reasoning is applied to determine compliance states and associated confidence values, which are used to autonomously authorize, restrict, delay, or terminate deployment actions in real time. The system further incorporates adaptive learning mechanisms that refine compliance inference parameters based on historical outcomes and regulatory updates, as well as secure audit logging for traceability and verification.
Owner:SUDDALA VENKATA RAJA ANIL KUMAR

System and method for implementing trusted multi-party build process using confidential computing

Systems and methods for implementing a trusted multi-party build process using confidential computing. A method for implementing a multi-party software build process using confidential computing includes encrypting a disk image of software configured to implement the software build process using one or more secret keys, storing the one or more secret keys and a key release policy, the key release policy defines one or more conditions for releasing one or more secret keys to an entity associated with the software build process, and launches the software environment and executes cryptographic measurements of the software environment within a trusted execution environment (TEE) using hardware configured to support operation of the TEE, a verification and key release policy based on cryptographic measurements of the software environment selectively provides one or more secret keys and uses the one or more secret keys to decrypt the disk image, verify the integrity of the disk image, and initiate a software build process.
Owner:ROBERT BOSCH GMBH

Remote orchestrator for software build and test tool

A remote build orchestrator for building and testing a software program is described and includes a generator service for generating a build graph from a definition of the software program input to the remote build orchestrator, the build graph comprising a plurality of actions, wherein the actions are defined by inputs, outputs, and commands, and wherein outputs of actions that are dependent on other actions for inputs are represented in the build graph by placeholders; an unwinder service for receiving the build graph from the generator service and processing the build graph into a series of requests for execution of the actions; and a remote build execution service for executing the actions in response to the received requests and returning results of the executing to the unwinder service.
Owner:GM CRUISE HOLDINGS LLC

Providing access to metadata modifications to facilitate software build reproduction

Software builds can be constructed based on previously recorded modifications to metadata. For example, a computing device can record modification logs. Each of the modification logs can be associated with a modification to metadata for a software repository. The computing device can also receive, from a client device, a request for the metadata for the software repository at a particular time. The computing device can provide access, for the client device, to one or more modification logs of the modification logs associated with the particular time. The one or more modification logs can be used by the client device to produce a software build having characteristics of the metadata at the particular time.
Owner:RED HAT LLC

Multi-modal artificial intelligence root cause analysis

A data processing system implements obtaining build logs that include information associated with a software build problem; analyzing the logs to generate a knowledge graph identifying the relationship between various entities in the logs; extracting a signature of a candidate root cause of the build problem from the knowledge graph representing a subset of nodes and edges of the knowledge graph; providing the signature of the candidate root cause to a graphical language model to obtain a prediction of a category of root cause failure selected from among a plurality of root cause failures; constructing a prompt for a language model to generate a root cause failure analysis that describes the root cause of the build problem, the prompt including the category of root cause; receiving the root cause failure analysis from the language model; and performing one or more actions in response to receiving the root cause failure analysis.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Techniques for incremental software build

Techniques for incrementally building a new version of a software application based on a cloud native distributed CI systems with snapshot of a past build for a qualified past version of the same software application are described herein. The techniques include receiving a first request to generate a first build unit for a first version of the software application and determining a first environment parameter associated with the request. A version history graph associated with the software application is also received, and based on this graph, a second version of the software application is determined. The techniques may further include generating the first build unit based on a distance measure associated with the first version and the second version. The techniques may also include determining the underlying external storage provisioner in Kubernetes base continuous integration systems and provision the snapshots by calling appropriate drivers.
Owner:CISCO TECHNOLOGY INC

A cloud-oriented software construction environment reuse method

The present invention provides a cloud-oriented software build environment reuse method, which relates to the field of software build and continuous integration. For continuous integration services deployed on the cloud, a software build environment library is constructed to store hierarchical software build environments, and a quickly reusable software build environment is provided. By reusing the software build environment, the computing, network and time overheads of software build environment preparation are reduced as much as possible, thereby improving the efficiency of continuous integration services and reducing the cost of continuous integration services.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Systems and methods for implementing a trusted multiparty build process using confidential computing

A method for implementing a multi-party software build process using confidential computing includes encrypting, using one or more secret keys, a disk image of software configured to implement the software build process, storing the one or more secret keys and a key release policy that defines one or more conditions for releasing the one or more secret keys to entities associated with the software build process, and, using hardware configured to support operation of a trusted execution environment (TEE), launching a software environment within the TEE and performing a cryptographic measurement of the software environment, selectively providing the one or more secret keys based on validation of the cryptographic measurement of the software environment and the key release policy, and, using the one or more secret keys for decrypting the disk image, verifying integrity of the disk image, and launching the software build process.
Owner:ROBERT BOSCH GMBH