DEPTEX: Organization-First, Open Source Dependency Risk Monitoring

2026-05-04T08:51:48Zb5243179cdd024902cfc6dc89e40ac065c65c33e3da4dce403980c145ec0ad11
Agile security integrationCLOZEMASTERCPG slicingCode Property GraphExecution Path DominanceFMAFairness Monitor AgentLLM verificationLLM-generated codeRECRLRust compilerSCAalert fatigueclozeMaskcode-generationcompiler fuzzingcurriculum reinforcement learningdependency riskfairnessfraud detectiongovernance-as-codelog-based security analyticssocial biassoftware supply chainvulnerability discovery

What happened

This collection of recent software-engineering papers highlights several security-relevant advances and risks. Key work includes Deptex — an organization-first, graph-based dependency risk platform that combines Code Property Graph (CPG) slicing with LLM semantic verification via a new Execution Path Dominance (EPD) concept and programmable governance-as-code to reduce SCA alert fatigue and compute operational blast radius for OSS vulnerabilities. CLOZEMASTER presents a bracket-based clozeMask LLM-infilling fuzzer for the Rust compiler that generated 27 confirmed bugs (10 fixed), demonstrating

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arxiv_cs_se
Record identifier
b5243179cdd024902cfc6dc89e40ac065c65c33e3da4dce403980c145ec0ad11
Enrichment time
2026-05-04T08:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.