Improving Accuracy of OWASP Dependency-Check Through Optimized CPE Matching to Reduce False Positives and False Negatives
This study focuses on improving the accuracy of one widely used SCA tool, OWASP Dependency-Check, by highlighting one of its main sources of error: the Common Platform Enumeration (CPE) matching process between project dependencies and vulnerability entries in the Common Vulnerabilities and Exposures (CVE) database.