Python package security is largely source-centric, yet Python runtimes can execute bytecode directly through .pyc files, compiled-only modules, and marshalled code objects, creating an inspection-execution gap. We present an empirical study of Python bytecode as a security artifact. We measure bytecode exposure in PyPI...
The results show that explicit dependency, event, and property semantics expose consequential runtime failures across API boundaries and execution modes at release scale.
Static analysis of Python packages must recover both program structure and object flow across first-class functions, dynamic dispatch, implicit protocol calls, exceptions, closures, and module execution. Native CPython bytecode provides the executable lowering of these behaviors, but its instruction, call, stack, and e...
A study of import-related bugs and security vulnerabilities in Python software, which combines security advisories with PyPI project histories and uses source and patch evidence to confirm how import activates cases, why the problem occurs, how developers fix it, and what program information is needed to explain the be...
Bai-Hong Chen, Wen Li· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.