Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

26 results about "Software repository" patented technology

A software repository, colloquially known as a "repo" for short, is a storage location from which software packages may be retrieved and installed on a computer. These repositories often house metadata about the packages stored in the repository. One can often install or update local software using a given package manager installed on the local machine by accessing the packages stored on the repository through it.

Advanced Cybersecurity System for Real-Time Phishing Detection, Account Takeover Fraud Prevention, and Software Repository Optimization Using Machine Learning Techniques

Systems and processes are disclosed for enhancing cybersecurity and optimizing software repositories through integration of web crawling, web scraping, feature engineering, and advanced machine learning algorithms to detect phishing attempts, prevent account takeover fraud, and identify unused code in repositories. The system collects and refines data from various sources, including transaction logs, customer databases, device details, external data sources, and historical fraud data, to build comprehensive datasets. Feature engineering creates new, meaningful features from the refined data, which are used to train and evaluate machine learning models. The best-performing models are deployed in production to monitor incoming communications and transactions in real-time, flagging suspicious activities and optimizing codebases. This processing ensures timely detection and prevention of security threats while maintaining efficient software development processes. Robust protection is provided against evolving cyber threats and enhances software performance and security through continuous learning and adaptation.
Owner:BANK OF AMERICA CORP

A dependency-aware software repository compilation scheduling method, system, and medium

This invention discloses a dependency-aware software repository compilation scheduling method, system, and medium. The method includes obtaining a list of software source code from a specified software repository; constructing a compilation relationship graph G of the software source code packages based on the compilation dependency attribute fields of each package in the list; splitting the compilation relationship graph G into multiple subgraphs; determining the compilation order of the software source code packages for each subgraph and constructing an independent compilation chain; and controlling the compilation chains of each subgraph to perform concurrent compilation according to the corresponding compilation order of the software source code packages. This invention aims to eliminate or mitigate software package compilation pauses caused by dependencies and conflicts between packages and improve the compilation efficiency of the software repository by perceiving software dependencies and providing a determined compilation order as guidance.
Owner:NAT UNIV OF DEFENSE TECH

Computer-implemented method, computer program product, and computer system for identifying the use of deprecated software source code in software repositories (machine learning-based deprecated software identification)

To provide a computer implementation method, a computer programming product and a computer system that identify use of a non-recommended software source code in a software repository.SOLUTION: An approach that identifies and recommends use of a non-recommended source code in a software repository comprises steps of: analyzing one or more software repositories for a software source code identified as non-recommendation by a machine learning model 502: alerting, in response to identifying the non-recommended software source code, one or more first software developers responsible for maintaining a software source code module using the non-recommended software source code 504; and recommending, to the one or more first software developers, an alternative software source code to be used in the software source code module to replace the non-recommended software source code 506.SELECTED DRAWING: Figure 5
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

System for signing software article

A system for signing a software article is presented. The system comprises a software repository for storing one or more software products, a monitoring unit for monitoring the software repository, a software product creation unit designed to store new software products in the software repository, and a signature unit for signing the software products, wherein the monitoring unit is designed to monitor the software product creation unit (10) and, after a new software product is stored in the software store, to send an activation signal for signing the stored new software product to the signature unit, and wherein the signature unit is designed to sign the new software product in the software store. And signing the stored new software product based on the starting signal. As a result, it is possible to sign the software article after it is created and stored. This has the advantage that the signature can be integrated in a different, also already existing structure for creating a software article, since the signature is not executed during the creation process as in an existing system and thus does not need to be integrated in the creation process itself.
Owner:SIEMENS AG

Managing a federated software repository across multiple devices

The present disclosure provides systems, methods, and computer readable storage devices for managing a federated software repository. A method includes storing, at a first member of a multi-device software repository, at least one file and metadata corresponding to the at least one file. The method includes adding an entry to an event log queue. The entry indicates addition of the at least one file. The method includes sending the metadata corresponding to the at least one file to other members of the multi-device software repository for storage at the other devices. The method includes performing, at a later time from sending the metadata, one or more repository update operations that include sending the at least one file to at least a second member of the multi-device software repository.
Owner:JFROG LTD

Methods, systems, and computer program products for automatically selecting tests for regression testing of software systems using machine learning.

What is provided is a computer-implemented method, system, and computer program product for automatically selecting tests for regression testing of a software system using machine learning. This includes generating a test map that includes at least one of a plurality of tests corresponding to source files. The plurality of tests and at least one source file are associated with a software repository. Furthermore, the method involves determining a defect score for the at least one test based on historical test data; receiving a component criticality score and defect definition corresponding to the source file; generating a key value corresponding to the at least one test based on the defect score, component criticality score, and defect definition; determining a subset of the plurality of tests based on the key value corresponding to the at least one test; and executing the test subset in conjunction with the software repository.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Detecting advanced typosquatting techniques in software repositories using semantic analysis

An untrusted package is detected from a system. A name of the untrusted package is input to a machine learning model, and an embedding vector generated as an output. A pool of candidate neighbors of the name of the untrusted package is determined by inputting the embedding vector into a plurality of models, the plurality of models outputting an identification of the conceptual similarity, and a metric associated with the amount of conceptual similarity. A subset of the pool of candidate neighbors based on the respective metrics is selected. Names of each package of the subset is input to a large language model along with respective metadata associated with each respective package of the subset. It is identified whether one or more packages of the subset are sensitive based on the output of the large language model, and an alert is output for each sensitive package.
Owner:SOCKET INC

Automated software build capacity incorporating code generated in software development environments with varying levels of security

Systems and methods are provided for automatically building software in a secure environment. A system includes a software development environment, having an associated security level. The software development environment generates an encrypted software module containing a software module and a cryptographic hash representing a content of the software module and provides it to a software repository. The software repository, in response to receipt of a build plan, decrypts the encrypted software module to recover the software module and the cryptographic hash representing the content of the software module, generates a new cryptographic hash for the software module, and verifies that the new cryptographic hash matches the cryptographic hash representing the content of the software module. A build environment receives the plurality of software modules from the software repository and generates a software build from the plurality of software modules based upon the build plan.
Owner:NORTHROP GRUMMAN SYSTEMS CORP

Method and system for installing Linux operating system based on PXE adaptive hard drive

This invention provides an installation method and system for a Linux operating system based on a PXE-adaptive hard disk driver. The method includes: creating a hard disk driver RPM package software repository; creating a mapping file between hard disk information and its driver RPM packages; updating the path of the hard disk driver RPM package repository on the PXE server via the PXE protocol; automatically detecting and obtaining the hard disk's device type, device ID, and alias in the Live memory system environment; determining whether the target hard disk is supported in the Live memory system environment; configuring the hard disk driver RPM package repository in the Live memory system environment; downloading the mapping file between hard disk information and its driver RPM packages; matching and downloading the hard disk driver RPM package from the PXE server; installing and loading the hard disk driver RPM package in the Live memory system environment; installing the operating system software package according to normal logic in the Linux operating system installer in the Live memory system environment; installing the hard disk driver RPM package on the hard disk file system and updating the kernel module configuration file.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Incubation Hub for Validation and Deployment of Software on a Cloud Platform

A system performs incubation of software platform. The system software components for a software platform configured to run on a target cloud platform. The system selects a cloud platform account from an account pool. The system identifies a cloud provisioning template for running the software platform and extracts information describing deployment of the software platform based on the cloud provisioning template. The system configures the cloud platform account to run the software platform. The system bundles a set of software components including software artifacts, custom tools, and automated custom scripts used for running the software platform in a software repository. The system creates a software platform package based on the set of software components. The system provides the software platform package to a target cloud platform account for deployment and execution of the software platform for the tenant.
Owner:GOLDMAN SACHS & CO LLC

Systems and methods for managing a software repository

A system method of managing a software repository. The method including receiving a dataset comprising a set of computer instructions, retrieving feature-related data from the dataset, determining, by a machine learning model executing on the computing device, a function of the computer instructions based on the feature-related data, and generating a synopsis of the function of the computer instructions. The method can include transmitting the synopsis to a user interface and receiving feedback from a user indicative of whether the synopsis accurately describes the function of the computer instructions. If the feedback indicates that the synopsis accurately describes the function of the computer instructions, the method can include storing the synopsis in a memory of the computing device. If the feedback indicates that the synopsis inaccurately describes the function of the computer instructions, the method can include generating a revised synopsis of the function of the computer instructions.
Owner:CAPITAL ONE SERVICES LLC

Enabling lifecycle management services for heterogeneous cloud resources using blueprints

Techniques described herein relate to a method for provisioning and managing resources on resource providers. The method may include obtaining, by a blueprint orchestrator, a blueprint generation request associated with resource providers (RPs) from a user; in response to obtaining the blueprint generation request: making a determination that the blueprint generation request is associated with lifecycle management (LCM) services; in response to the determination: obtaining resource information associated with the LCM services and the RPs; generating a blueprint based on the resource information and a software repository associated with the RPs; composing RP resources and LCM resources on the RPs based on a generic composition request using the blueprint; and performing LCM operations on the RP resources using the LCM resources and the blueprint.
Owner:DELL PROD LP

Sorting-based open source software security vulnerability patch location method

The present invention provides a method for locating open source software security vulnerability patches based on sorting, specifically comprising: collecting vulnerability and code submission data from a website; extracting vulnerability and code submission similarity features in four dimensions, namely, code line, vulnerability identity, vulnerability repair location, and bag-of-words, using data mining and statistical analysis methods; training a vulnerability domain text semantic encoding module based on a Bert model, and using the semantic encoding module to extract vulnerability semantic features and code submission semantic features; concatenating the vulnerability semantic features and code submission semantic features to form a complete feature set of the vulnerability and code submission; model training; and model fusion using the concept of majority voting. The present invention can extract features from vulnerabilities and code submissions, establish a vulnerability patch submission sorting model, sort code submissions in an open source software repository according to their matching degree with the vulnerability, and effectively reduce the number of code submissions that patch annotators need to review.
Owner:ZHEJIANG UNIV CITY COLLEGE

Testing automation for open standard cloud services applications

A method performed by a processing system including at least one processor includes monitoring a software repository for code changes, detecting a code change in a software instance that is stored in the software repository, generating a container image of the software instance in response to the detecting, creating a container for the container image, wherein the container encapsulates software needed to run a test suite on the software instance, configuring a testing platform for a development environment used to create the software instance, executing the test suite for the software instance by running the software encapsulated in the container on the testing platform, and publishing a test output of the test suite as a human-readable scorecard for the software instance.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Automatic virtual machine pressure testing method and device, medium and electronic equipment

The invention discloses an automatic virtual machine pressure test method. The method comprises the following steps: acquiring a target configuration file required by a virtual machine pressure test; the target configuration file comprises software warehouse information, a pressure test tool list, cloud environment information, virtual machine configuration information, network environment information and pressure test information; uploading a pressure test tool specified by the pressure test tool list to the software repository based on the software repository information; creating at least two groups of test virtual machines in the cloud platform based on the cloud environment information, the virtual machine configuration information and the network environment information, and establishing a pressure test environment for the test virtual machines based on the pressure test information; and under the condition that the pressure test environment is successfully established, calling a pressure test tool based on the pressure test information, performing pressure test on the at least two groups of test virtual machines, and summarizing obtained pressure test results. According to the technical scheme, automation of the pressure test of the virtual machine is achieved, and the reliability and efficiency of the pressure test are improved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Detecting advanced typosquatting techniques in software repositories using semantic analysis

An untrusted package is detected from a system. A name of the untrusted package is input to a machine learning model, and an embedding vector generated as an output. A pool of candidate neighbors of the name of the untrusted package is determined by inputting the embedding vector into a plurality of models, the plurality of models outputting an identification of the conceptual similarity, and a metric associated with the amount of conceptual similarity. A subset of the pool of candidate neighbors based on the respective metrics is selected. Names of each package of the subset is input to a large language model along with respective metadata associated with each respective package of the subset. It is identified whether one or more packages of the subset are sensitive based on the output of the large language model, and an alert is output for each sensitive package.
Owner:SOCKET INC

Software repository file path coverage conflict detection method and device, equipment and medium

The embodiment of the invention discloses a software repository file path coverage conflict detection method and device, equipment and a medium. The method comprises the steps that software package installation file lists of all to-be-detected software repository are extracted and integrated to form a total installation file list; searching software packages with the same installation file path in the total installation file list and grouping the software packages to form a plurality of path conflict package groups; pairing the software packages contained in each path conflict package group in pairs to form conflict package pairs to be verified; and performing installation verification on the to-be-verified conflict packet pair, and determining whether the to-be-verified conflict packet pair has a file path coverage conflict according to whether the installation is successful. According to the method, the test range is narrowed by combining the files into the total installation file list and searching the same installation file path, and then the software packages are paired, so that the software packages with conflicts can be accurately positioned, the detection precision is improved, the positioning difficulty is reduced, and the file path conflict points can be quickly positioned.
Owner:KYLIN CORP

Systems for and methods of using a secure dataloader

Disclosed are systems, methods, and media for using a secure dataloading system for updating an aerospace system. The secure dataloading system includes a communications module that is configured to communicatively couple the secure dataloading system to the aerospace system. The secure dataloading system also includes a processor that is configured a to access a software repository storing a secure software update having a unique hash ID to provide a copy of the secure software update to the aerospace system via the communications module. The processor can be configured to use a blockchain to validate the unique hash ID of the software update and, upon validation of the unique hash ID, install the secure software update on the aerospace system.
Owner:ASTRONAUTICS CORPORATION OF AMERICA

Advanced cybersecurity system for real-time phishing detection, account takeover fraud prevention, and software repository optimization using machine learning techniques

Systems and processes are disclosed for enhancing cybersecurity and optimizing software repositories through integration of web crawling, web scraping, feature engineering, and advanced machine learning algorithms to detect phishing attempts, prevent account takeover fraud, and identify unused code in repositories. The system collects and refines data from various sources, including transaction logs, customer databases, device details, external data sources, and historical fraud data, to build comprehensive datasets. Feature engineering creates new, meaningful features from the refined data, which are used to train and evaluate machine learning models. The best-performing models are deployed in production to monitor incoming communications and transactions in real-time, flagging suspicious activities and optimizing codebases. This processing ensures timely detection and prevention of security threats while maintaining efficient software development processes. Robust protection is provided against evolving cyber threats and enhances software performance and security through continuous learning and adaptation.
Owner:BANK OF AMERICA CORP

Service design coordination among developers

An example operation may include one or more of receiving a first code base and a second code base from a software repository, wherein each of the first and second code bases comprise source code of a plurality of different software programs, identifying a source code within the first code base that is interdependent with a source code within the second code base based on execution of a generative artificial intelligence (GenAI) model on the first and second code bases, determining a software component to connect the source code within the first code base to the source code within the second code base, and displaying an identifier of the software component via a user interface. The example operation may further include an AI agent that performs an action based on the identifier.
Owner:THE TORONTO DOMINION BANK

System

A system is provided.SOLUTION: A system, comprising: means for obtaining a software repository; means for analyzing source code in the obtained software repository; means for generating improvement suggestions for the source code using a generative AI model; means for updating the source code based on the generated improvement suggestions; means for testing the updated source code; and means for sharing improvement results and updates to users.SELECTED DRAWING: Figure 1
Owner:SOFTBANK GROUP CORP

Software repository security risk detection methods, devices, computer equipment, and storage media

This application relates to a method, apparatus, computer device, storage medium, and computer program product for security risk detection in a software repository. The method includes: establishing a dependency tree model of software packages based on version information of the packages in the software repository; the dependency tree model representing the dependencies between packages through a tree structure; matching vulnerability information in a vulnerability database with the version information of each package to obtain target packages that match the vulnerability information; performing vulnerability marking processing on the target packages in the dependency tree model, and performing risk marking processing on the nodes associated with the target packages; obtaining the security risk detection results of the software repository based on the packages with risk markings in the dependency tree model. This method can improve the timeliness, accuracy, and comprehensiveness of security risk monitoring in software repositories.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Methods for modifying configuration files, systems, devices, and storage media in migration scenarios.

This invention provides a method, system, device, and storage medium for modifying configuration files in a migration scenario, belonging to the field of data processing technology. The method includes: determining reference files for difference comparison from a pre-built configuration reference file library based on the configuration file of the software to be migrated; simultaneously displaying the configuration file and reference files on a display page and performing format unification processing; highlighting the differences between the files; receiving user input for modifications to the configuration file based on the differences; and obtaining a standardized configuration file that can successfully migrate the software based on the modification input. This invention pre-centralizes the standardized configuration files of multiple successfully migrated software in a configuration reference file library, eliminating the need to access individual online software repositories to quickly obtain reference files for the configuration files of the software to be migrated. Furthermore, by directly obtaining the configuration reference files from the configuration reference file library, it saves the time spent extracting configuration files after downloading software packages online, improving the speed and efficiency of batch software migration.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Dynamic review of software updates after pull requests

In some implementations, a system may receive, from a software repository, a difference file indicating changes, to software code, that was submitted to the software repository. The system may parse the difference file to determine files, associated with the software code, affected by the changes and to determine content associated with the changes. The system may apply rules, from a rule dictionary, based on comparing identifiers, associated with the files, with identifiers included in the rules and based on comparing the content, associated with the changes, with content included in the rules. The system may generate software review checklist items based on applying the rules and output the software review checklist items for display. The system may receive, based on input from a user, confirmation of the changes and commit the changes to the software repository based on the confirmation.
Owner:CAPITAL ONE SERVICES LLC

Private micro frontends with API access to code artifacts in a software repository

An apparatus is provided including storage encoded computer executable code for a consolidated enterprise application configured to provide, to a select set of users with credentialed private access to the consolidated enterprise application, web-based access in a form of a given user experience. In select embodiments, the given user experience involves providing access to user interface static content. The consolidated enterprise application comprises plural frontend web-based independent user interface (UI) unit applications. More specifically, the UI unit applications are individual uncontainerized micro frontends. One or more content publishing interfaces may be provided, that are configured to publish content including the code to a web service storage. The one or more content publishing interfaces are configured to use application programming interface requests to publish the content to the web service storage.
Owner:JPMORGAN CHASE BANK NA

Version management and releases of a software application

Techniques are described for deploying software applications associated with document management. The techniques may include retrieving, by a computing system and from a software repository, configuration information for a software application for managing an electronic document, the configuration information specifying a plurality of widgets for deploying the software application. The techniques may further include receiving, by the computing system and from a client device, a request to access the software application. The techniques may further include generating, by the computing system, a response to the request comprising an indication of the configuration information and instructions configured to cause the client device to request, from the software repository, the plurality of widgets specified by the configuration information. The techniques may further include outputting, by the computing system, the response to the client device to provide the software application at the client device.
Owner:DOCUSIGN INC