Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

42 results about "Software delivery" patented technology

E2E scene test optimization method and system based on target man-machine cooperation

The invention relates to the technical field of software engineering and automatic testing, in particular to an E2E scene test optimization method and system based on target man-machine cooperation. According to the scheme, an optimization target is manually set, an initial test case and a business process are input, and a test resource library is constructed; the system automatically analyzes a service path, generates a use case dependency graph and a key path, and determines a core scene through manual verification; a candidate optimization strategy is generated by the system, and a target strategy is determined through manual screening according to resources and priorities; the system carries out simplification, merging and scheduling optimization on the use cases, and deploys and executes the use cases after manual sampling verification of coverage; the system collects execution data in real time and generates an evaluation report, and whether a use case is supplemented or a strategy is adjusted is determined after manual analysis; and finally updating the resource library and the strategy model, establishing a dynamic feedback mechanism, and triggering continuous optimization during system iteration. According to the method, the E2E test efficiency and the software delivery quality are remarkably improved through man-machine cooperation and closed-loop optimization.
Owner:RUIJIAN TECHNOLOGY (BEIJING) CO LTD

Method for realizing DevSecOps in container arrangement cluster

The invention discloses a method for realizing DevSecOps in a container arrangement cluster. The method comprises the following steps: S1, Jenkins dynamically generates an assembly line container in the container arrangement cluster; s2, mounting network storage on an assembly line construction container, decompressing the Gitleaks and Dependency-Check installation packages, then putting the Gitleaks and Dependency-Check installation packages into a network storage directory, and enabling the assembly line to use the Gitleaks and Dependency-Check installation packages in a sharing mode; s3, the SonarQube is integrated with a Dependency-Check display report, and the Dependency-Check display report is integrated with the SonarQube; and S4, writing JenkinsFile, and connecting all tools in series for use. According to the method, DevOps in a traditional virtual machine environment is transformed into DevSecOps in a container orchestration cluster environment, so that the efficiency and accuracy of security examination are improved, the labor cost is reduced, the high efficiency and security of software delivery are realized, and the container orchestration cluster is protected from being damaged by security threats.
Owner:QIMING INFORMATION TECH

Method and system for building and leveraging a knowledge fabric to improve software delivery lifecycle (SDLC) productivity

Provided is a method and system (108) for building and leveraging a knowledge fabric (110) in a Software Development Lifecycle (SDLC). A plurality of SDLC artifacts are received from a plurality of heterogeneous data sources (102). The plurality of SDLC artifacts are then correlated to build an end-to-end correlation and are clustered to generate an SDLC knowledge fabric (110). This includes extracting semantic and contextual data from the plurality of SDLC artifacts using Natural Language Processing (NLP) and deep text analytics and transforming the extracted semantic and contextual data to knowledge graphs. One or more actionable items (112) are then derived using the SDLC knowledge fabric (110) and the one or more actionable items (112) are used to improve overall process efficiency and accelerate software delivery in the SDLC.
Owner:L&T TECH CENT +1

Known-deployed file metadata repository and analysis engine

A known-deployed file metadata repository (KDFMR) and analysis engine enumerates reference lists of files stored on a software delivery point (SDP) and compares the enumerated list of files and associated metadata to previously stored values in the KDFMR. If newly stored or modified files are identified, the analysis engine acquires the files from the SDP. Each file is analyzed to determine whether the file is an atomic file or a container file and metadata is generated or extracted. Each file stored in a container file is recursively extracted and analyzed, where metadata is generated for each extracted file and each container file. The KDFMR periodically analyzes the files stored on the SDP for differences to maintain the currency of the KDFMR data with respect to files stored on the SDP. Storage or modification of files on the SDP triggers analysis of the associated file. KDFMR data is updated with metadata determined based on sandbox detonation of files and / or identified artifacts of known-deployed files.
Owner:BANK OF AMERICA CORP

Software development control method

The invention relates to the technical field of software engineering management, in particular to a software development control method. The method comprises the following steps of: decomposing a software application into a plurality of independent software modules according to software development requirements, and acquiring characteristic measurement of each software module; based on the feature measurement of each software module, determining a reconstruction probability score of the software module; determining the risk level of the software module according to the reconstruction probability score; selecting a matched control strategy for the software module from a plurality of predefined control strategies based on the risk level; and applying the control strategy corresponding to the selected software module to the subsequent development process of the software module. Through the data-driven and differentiated control method, the quality assurance resources can be accurately projected to the most required links, so that the software delivery speed is increased, and the stability and maintainability of the system are remarkably enhanced.
Owner:WUHAN COMPUTING ECOLOGY TECH CO LTD

A secondary development processing method and device for closed-source delivered software and a medium

The application provides a secondary development processing method and device for closed-source software delivery and a medium, the method comprising the following steps: adopting a meta-model engine in combination with a mode of a standard APP to provide a standard software product in a closed source on a software delivery platform; the standard APP is an APP delivered to a customer enterprise in a closed source through the software delivery platform, and the APP refers to an application function module or an application capability module; obtaining individualized needs of an enterprise customer; newly creating a plurality of new APPs on the software delivery platform, and extending functions of the standard software product by using the plurality of new APPs according to the individualized needs to obtain individualized secondary development content customized by the standard software product. The application can realize the effects of upgrading a version of a software product and retaining individualized secondary development content customized by a customer in the software product.
Owner:GUANGZHOU SIE CONSULTING CO LTD +1

Methods and systems for secure software delivery

Methods, systems, and apparatuses for securely delivering software artifacts. A first computing device may be configured to encrypt one or more software artifacts into an encrypted data file and encrypt a key and a policy file associated with the encrypted data file and send the encrypted data file, key, and policy file to a second computing device. The policy file may comprise policy information for authenticating access to the encrypted data file. The second computing device may use the key and the policy information to access and authenticate a software application of the second computing device. The software application may be used to decrypt the data file and access the one or more software artifacts.
Owner:GUARDANT HEALTH INC

Software automatic distribution and deployment method oriented to cloud edge collaboration

PendingCN122018938AVersion controlTransmissionSoftware distributionEdge node
The invention discloses an automatic software distribution and deployment method and system oriented to cloud edge collaboration, and belongs to the technical field of distributed computing and continuous software delivery. The method comprises the following steps: a cloud creates a task based on a declarative deployment description unit and a release strategy; the intelligent scheduler constructs a hybrid distribution network according to the dynamic context of the node to carry out differential scheduling; the edge agent instantiates a description unit through environment injection, executes deployment through atomized transactions after pre-verification, and decides traffic switching or fast rollback according to a multi-stage health probe verification result; and the cloud side converges the global state through a bidirectional channel to realize strategy-based closed-loop management and control. According to the method, the problems of low software distribution efficiency, tedious deployment adaptation, poor reliability and difficulty in collaborative management and control of massive heterogeneous edge nodes in a weak network environment are solved, and efficient, intelligent and high-reliability cloud edge collaborative software delivery is realized.
Owner:CHINESE PEOPLES LIBERATION ARMY UNIT 63729

Method for improving software delivery training quality based on large model and digital human

The invention relates to a method for improving software delivery training quality based on a large model and a digital person, and solves the problem of poor traditional training effect through cooperation of the AI digital person and the large model. According to the technical scheme, a virtual studio generates 3D digital human explanation training content; and the large model analyzes the user questions and generates personalized answers. A real environment is simulated, and immersive practical operation training is provided in a sandbox mode. And performing intelligent evaluation and optimization based on the data of the user behaviors.
Owner:SHANGHAI CAIJIANG INTELLIGENT TECH CO LTD

Automatic operation and maintenance method and device, equipment, storage medium and program product

The invention discloses an automatic operation and maintenance method and device, equipment, a storage medium and a program product, and relates to the technical field of data processing.The automatic operation and maintenance method comprises the steps that when an operation and maintenance trigger event is detected, data is obtained from multiple data sources, and multi-dimensional data is obtained; generating a strategy decision context object according to the multi-dimensional data; determining a resource condition rule matched with the current resource state according to the current resource state and a current resource condition rule set in a rule base; determining a test condition rule matched with the first test information of the current code according to the first test information of the current code and a current test condition rule set in a rule base; determining a target operation and maintenance strategy according to a resource condition rule matched with the current resource state and a test condition rule matched with the first test information of the current code; and executing the target operation and maintenance strategy. According to the method, the accuracy of the target operation and maintenance strategy is improved, and then the software delivery efficiency and the stability of a service system are improved.
Owner:CHINA CONSTRUCTION BANK +1

A cabin driving fusion software collaborative delivery and safe operation management and control system and method

The application discloses a cabin-driving integrated software collaborative delivery and safe operation management and control system and method, and belongs to the technical field of vehicle-mounted software. The method comprises the following steps: collecting and inputting version information of cabin domain and intelligent driving domain software; performing automatic checking on full-dimension compatibility based on a bidirectional compatibility matrix; if the checking fails, triggering a release lock; if the checking passes, entering a gray release queue; filtering terminals according to multiple scenes; performing pushing by the OTA cloud according to a hierarchical proportion; if an exception occurs, suspending the pushing; collecting states in real time and determining fault levels; performing cross-domain linkage self-healing operation according to the fault levels; returning monitoring data, self-healing results and user feedback to a general control management module, generating a delivery report and completing an iterative closed loop. The application can realize collaborative and reliable delivery of cabin domain and intelligent driving domain software, rapid self-healing of operation exceptions, and improvement of cabin-driving integrated software delivery efficiency, vehicle-mounted end operation safety and stability.
Owner:CHINA FAW CO LTD +1

Gray release method and device, computer equipment, storage medium and program product

The invention relates to a gray release method and device, computer equipment, a storage medium and a computer program product. The method comprises the steps that in response to gray release strategy type selection operation for a software deliverable object, the gray release strategy type of the software deliverable object is selected, and different gray release strategy types correspond to different gray release processes; in response to a gray release strategy configuration operation for the selected gray release strategy type, configuring a gray release strategy for the software deliverable, the gray release strategy comprising a plurality of step nodes having an execution sequence for realizing a gray release process corresponding to the selected gray release strategy type; and in response to a gray release triggering operation, sequentially executing each step node according to the execution sequence, and when each step node is executed, obtaining a gray release parameter indicated by the executed step node, and performing gray release on the software deliverable according to the gray release parameter. By adopting the method, the gray release efficiency can be improved.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Software development test system

The invention relates to a software development test system, which belongs to the technical field of software development, and comprises a user layer and a support layer, the output end of the user layer is in signal connection with a function module layer, and the function module layer is in bidirectional signal connection with the support layer. The function module layer comprises a test case management module, an automatic test module, a defect management module, a test environment management module, a CI / CD integration module, a test data management module, a report analysis module, a safety test module and an AI enhancement module. According to the software development test system, through deep integration and cooperation of all the modules, the problems that all links are scattered and unsmooth in connection in a traditional development test mode are effectively solved, automation and intelligentization of the whole process from test case design to software delivery are achieved, the development period is greatly shortened, meanwhile, the software quality is ensured, and the development efficiency is improved. And enterprises can quickly respond to market changes and deliver high-quality software products, so that the advantage of improving the development efficiency and quality is achieved.
Owner:WUHAN FENGYONG TECHNOLOGY CO LTD

Known deployed file metadata repository and analysis engine

A known-deployed file metadata repository (KDFMR) and analysis engine enumerates reference lists of files stored on a software delivery point (SDP) and compares the enumerated list of files and associated metadata to previously stored values in the KDFMR. If newly stored or modified files are identified, the analysis engine acquires the files from the SDP. Each file is analyzed to determine whether the file is an atomic file or a container file and metadata is generated or extracted. Each file stored in a container file is recursively extracted and analyzed, where metadata is generated for each extracted file and each container file. The KDFMR periodically analyzes the files stored on the SDP for differences to maintain the currency of the KDFMR data with respect to files stored on the SDP. Storage or modification of files on the SDP triggers analysis of the associated file. KDFMR data is updated with metadata determined based on sandbox detonation of files and / or identified artifacts of known-deployed files.
Owner:BANK OF AMERICA CORP

Intelligent continuous integration / continuous delivery implementation method and system based on Jenkins

The invention discloses an intelligent continuous integration / continuous delivery implementation method and system based on Jenkins, and belongs to the technical field of industrial application software, the implementation of the method comprises the following steps: an administrator configures Jenkins server connection information, a basic construction template and mirror image warehouse authentication information; creating a product and configuring basic information as a basic unit of subsequent management; product access and operation authorities are distributed to team members, and safety control is achieved; adding each component under the product, and configuring a code warehouse, branches and component types; multiple sets of environments are configured for the product, and mirror image warehouses and architecture requirements of all the environments are specified; selecting a component and environment creation construction task, and automatically generating initial configuration by the system; and after the user confirms or modifies the construction parameters, the construction is triggered. According to the method, standardization and automation of the construction and deployment process can be realized, the DevOps threshold is greatly reduced, and the software delivery efficiency and quality are improved.
Owner:SHANDONG INSPUR DIGITAL BUSINESS TECHNOLOGY CO LTD

Fault positioning method and device based on vehicle machine screenshot and electronic equipment

This application discloses a fault location method, apparatus, and electronic device based on vehicle infotainment system screenshots, relating to the field of vehicle testing technology. The method includes: acquiring an atomic interface test command for testing the vehicle infotainment system; the atomic interface test command includes operation flag information; based on the atomic interface test command, acquiring user interface screenshot data, system log data, and CAN bus signal data of the vehicle infotainment system; based on the operation flag information, associating the user interface screenshot data, system log data, and CAN bus signal data to determine the test data corresponding to the operation flag information; and storing the test data in a structured manner according to a preset time series, and generating a display interface containing user interface screenshot thumbnails to support fault location of the vehicle infotainment system. This application achieves rapid fault location and reproduction of the vehicle infotainment system, shortening the fault location cycle and reducing the fault location cost, thereby improving the efficiency of vehicle infotainment system software delivery.
Owner:VOYAH AUTOMOBILE TECH CO LTD

Civil aircraft airborne software delivery-to-host process design method

The invention provides a method for designing a penetration and modification process after civil aircraft airborne software is delivered to a host. According to the method, a set of rigorous work flow is provided for loading after airborne equipment software is delivered according to loading drive, preparation and inspection before loading implementation, loading implementation, loading verification, loading recording and management and control flow requirements and activity requirements in the loading completion process after civil aircraft airborne software is delivered to a host; activity and rules which should be followed in the loading process are completely planned, wrong software configuration items are prevented from being loaded, and the loading process is prevented from being out of control. A set of perfect and executable control program is provided for loading after the civil aircraft airborne software is delivered, it is guaranteed that software loading is correct, complete and controlled, and powerful guarantee is provided for flight safety of civil aircrafts.
Owner:AVIC GENERAL HUANAN AIRCRAFT IND CO LTD

One-stop intelligent software development system based on multi-agent

PendingCN122450429ATask analysisRequirements management
The application discloses a one-stop intelligent software development system based on multiple agents, which comprises a one-stop DevOps research and development cooperation platform and a multiple-agent scheduling and cooperation engine. The multiple-agent scheduling and cooperation engine is connected with each sub-module in the one-stop DevOps research and development cooperation platform, including a demand management module, a code library management module, a document management module, a pipeline module, a product library module, a code scanning module, a test management module and a measurement management module. The multiple-agent scheduling and cooperation engine comprises a task analysis and distributor, a multi-role virtual employee intelligent agent pool, a large model calling adapter, a delivery material archiving and integration controller and an artificial confirmation node manager, realizes end-to-end automation from demand description to software delivery, and only needs to fill in a natural language demand description or a prompt word in a task card, so that the system can automatically drive a whole-process task such as prototype generation, code writing, test case generation and construction deployment, and the software delivery cycle is greatly shortened.
Owner:BEIJING SIMPLE POINT TECH CO LTD

Software deliverable quality examination method and system

The invention relates to the technical field of software testing, and provides a software deliverable quality examination method and system. The method comprises the following steps: performing format analysis on the content of the software deliverable according to the organization structure of the software deliverable, and constructing the context of an examination tool; setting an examination rule configuration attribute; the review rule configuration attributes comprise a unique identifier of the review rule, a classification to which the review rule belongs, a Boolean flag bit for identifying starting and stopping of the review rule, a rule brief description of the review rule and an implementation class name of the specific review rule; and based on the context of the review tool and the interface for inputting the unified rule, according to the review rule configuration attribute, combining the configuration file of the report to be generated and the check failure item, and according to the report template, generating the review report. The inspection efficiency and the automation degree of the deliverable can be improved.
Owner:INSPUR GENERSOFT CO LTD

Embedded software development method and device, equipment and storage medium

The invention discloses an embedded software development method and device, equipment and a storage medium, and relates to the technical field of embedded software, and the embedded software development method comprises the steps that after a preset code warehouse obtains a project file about a target embedded software project and corresponding label information, a CI / CD assembly line is triggered; determining a containerized environment based on the label information through a CI / CD assembly line, in the containerized environment, determining a project identifier and a project variant identifier based on a configuration file in the project file through a preset cross-platform construction tool, and loading a target file from the project file based on the project identifier and the project variant identifier; and in a containerized environment, executing project construction and project packaging operation about the target embedded software project based on the target file through a preset cross-platform construction tool and a packaging tool to obtain an embedded software product so as to publish the embedded software product. According to the method, the high-efficiency and standardized requirements of software delivery in an embedded scene can be met.
Owner:HANGZHOU MAITANG TECH CO LTD

Software platform collaborative design method and device, equipment and storage medium

The invention discloses a software platform collaborative design method and device, equipment and a storage medium. Comprising the steps that a software design task is obtained, the design task is distributed to multiple software developers based on different functions, original design achievements of the software developers are received, and the original design achievements comprise a topological graph which is constructed based on the distributed design task and takes software element entities as nodes and the relation between the software element entities as edges; and merging the software element entities in the original design results of the software developers and the relationship between the software element entities to obtain a software collaborative design result. According to the method, the function service is taken as a software delivery boundary, collaborative design of multiple suppliers is supported, the function modules of the software platform are taken as nodes, calling relations among different function modules are taken as edges to construct the network topology of the software platform, and function decoupling of a complex software system is realized; and a single software element entity can be independently called, upgraded and replaced, so that the expandability and the flexibility of the system are improved.
Owner:BEIJING PALMGO INFOTECH CO LTD

Test information intelligent decision-making system based on machine learning

The invention discloses a test information intelligent decision-making system based on machine learning, and relates to the technical field of software test management, and the system comprises a test management center which is used for calling data and sending the data to a global data sensing unit; the global data sensing unit is used for outputting a static asset dependency tree and a dynamic business value map; the map construction mapping unit is used for deducing a potential commercial risk propagation path set; the risk propagation calculation unit is used for calculating a quantified expected commercial risk value and sending the quantified expected commercial risk value to the decision execution unit; and the decision execution unit is used for generating a release blocking instruction or an intelligent test instruction. According to the method, the association graph of the code assets and the business value is constructed, the change risk is quantitatively calculated by using historical data and real-time traffic, and the test strategy and the release decision are dynamically adjusted according to the business risk value, so that test resources are inclined to high-risk business, and the test efficiency is improved. And the software delivery efficiency and security are improved while the service continuity is guaranteed.
Owner:FUJIAN HONGJINDA INTELLIGENT TECH CO LTD

Known-deployed file metadata repository and analysis engine

A known-deployed file metadata repository (KDFMR) and analysis engine enumerates reference lists of files stored on a software delivery point (SDP) and compares the enumerated list of files and associated metadata to previously stored values in the KDFMR. If newly stored or modified files are identified, the analysis engine acquires the files from the SDP. Each file is analyzed to determine whether the file is an atomic file or a container file and metadata is generated or extracted. Each file stored in a container file is recursively extracted and analyzed, where metadata is generated for each extracted file and each container file. The KDFMR periodically analyzes the files stored on the SDP for differences to maintain the currency of the KDFMR data with respect to files stored on the SDP. Storage or modification of files on the SDP triggers analysis of the associated file. KDFMR data is updated with metadata determined based on sandbox detonation of files and / or identified artifacts of known-deployed files.
Owner:BANK OF AMERICA CORP

Software delivery automatic evaluation method and system

The embodiment of the invention discloses a software delivery automatic evaluation method and device, electronic equipment and a computer readable medium. A specific embodiment of the method comprises the following steps: analyzing a contract or a demand document related to software delivery to extract function demand entries; performing structured processing to generate an evaluation case; performing static analysis on the source code to obtain code function feature information; executing a dynamic test based on the evaluation case to obtain behavior data during operation; performing joint comparison on the code function feature information and the runtime behavior data with the function requirement items, and calculating a function completion degree score; executing multi-dimensional quality evaluation on the software to obtain scores of all dimensions; configuring a weight based on a preset quality model and calculating a comprehensive quality score; and generating a structured evaluation report. According to the implementation mode, full-process automation and objective quantification of software delivery evaluation are realized, and the evaluation efficiency and the standardization level are improved.
Owner:BEIJING ALPHA RISK CONTROL TECH CO LTD

Software delivery team operation management system and method

The invention discloses a software delivery team operation management system and method, and belongs to the field of computers and data processing, and the system comprises a user interaction module which can receive a software development project arrangement request and software development project arrangement related data inputted by a user, and transmits the request and data to a data management module; a software development project arrangement plan obtained from the data management module is received and displayed; the data management module can store a software development project arrangement request and software development project arrangement related data, and receive and store a software development project arrangement plan fed back by the solution arrangement module; and the solving and arranging module can construct an optimization solving and arranging mathematical model meeting the software development and arranging requirements according to the software development project arranging request and the software development project arranging related data acquired from the data management module, solves the model through a solver to obtain a software development project arranging plan, and feeds back the software development project arranging plan to the data management module. The system can provide powerful data support for software delivery.
Owner:UNIV OF SCI & TECH OF CHINA +1

Software change processing method and device, computer equipment and storage medium

The invention discloses a software change processing method and device, computer equipment and a storage medium, belongs to the technical field of software engineering, and is applied to a software delivery scene. According to the method, the software change event is continuously monitored, fine analysis and structured processing on the change log are combined, and under the support of the unified software asset dependency relationship graph, accurate topology analysis on the change influence range is realized, so that upstream and downstream software assets involved in the change can be accurately identified, and the change accuracy is improved. And automatically matching a most suitable change processing strategy based on the influence range, and driving a corresponding change processing executor to carry out targeted processing on the change content. By means of the technical means, on-demand and granularity-based processing of software change is achieved, unnecessary construction and deployment operations are reduced, the overall execution time of software change processing is shortened, consumption of computing resources and network resources is reduced, and therefore the efficiency, stability and safety of the software delivery process are overall improved.
Owner:YGSOFT INC

Software product delivery method and device oriented to cloud computing scene and electronic equipment

The invention provides a cloud computing scene-oriented software product delivery method and device and electronic equipment, and relates to the technical field of computers, in particular to the technical fields of cloud computing, software delivery and the like. The specific implementation scheme comprises the steps of obtaining a product delivery list; wherein the product delivery list is used for indicating a target software product to be delivered; generating a function white list of the target software product; wherein the function white list is used for indicating to-be-delivered functions of the target software product; generating a product delivery instruction based on the product delivery list and the function white list; sending the product delivery indication to a product server; wherein the product server is used for delivering the target software product based on the product delivery instruction. By adopting the method, the delivery cost of software products can be reduced, and meanwhile, the flexibility, the automation level and the efficiency of the delivery process are improved.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD +1

End-to-end automatic whole package integration method and system of domain controller

The invention provides an end-to-end automatic whole package integration method and system for a domain controller, and relates to the technical field of domain controllers. According to the method, key links such as component retrieval, version verification, firmware combination, security packaging, integrity verification and audit log generation are comprehensively automated; and the problems of error proneness, low efficiency, version chaos and the like in the traditional manual integration process are effectively eliminated. According to the method, the compliance and consistency of software component versions are ensured, and the security and credibility of the whole OTA package are ensured through a dynamic security policy and a digital signature mechanism; meanwhile, redundant storage is avoided based on Hash verification and a differentiated uploading mechanism, and the product management efficiency is improved; more importantly, the structured integrated log which is automatically generated and stored in an associated mode completely records the whole operation process, the strict auditing and tracing requirements of the automotive electronic field for function safety and ASPICE standards are met, and therefore efficient, accurate, safe and compliant domain controller software delivery is achieved.
Owner:CHINA FAW CO LTD

Machine-learned model for duplicate crash dump detection

In an example embodiment, a machine learned model is utilized for identifying duplicate crash dumps. After a developer submits code, corresponding test cases are used to ensure the quality of the software delivery. Test failures can occur during this period, such as crashes, errors, and timeouts. Since it takes time for developers to resolve them, many duplicate failures can occur during this time period. In some embodiments, trash triggering is the most time-consuming task of development, and thus if duplicate crash failures can be automatically identified, the degree of automation will be significantly enhanced. To locate such duplicates, a training-based machine learned model uses component information of an in-memory database system to achieve better crash similarity comparison.
Owner:SAP SE

Software security assessment method, system and readable storage medium

ActiveCN115906094BPlatform integrity maintainanceThird partyProgram security
The present invention discloses a software security assessment method, system, and readable storage medium. The method includes the following steps: extracting fingerprint features of third-party libraries in software delivery files; obtaining vulnerability information disclosed by the third-party libraries and extracting vulnerability features; calculating a vulnerability matching degree based on correlation comparison between the fingerprint features of the third-party libraries and the vulnerability features, and calculating a third-party library security score based on the vulnerability matching degree; obtaining the control flow of the program source code; calculating a source program security score based on the program's input validation, API calls, exception handling, and / or security features in the control flow; and calculating a software security score based on the third-party library security score and the source program security score, and using this score to assess the security of the software. The present invention solves the problem in related technologies of being unable to comprehensively detect security threats to program source code and referenced third-party libraries.
Owner:HANGZHOU DBAPPSECURITY CO LTD