IP Library Granted Patent US 12,373,583
Granted Patent B2
US 12,373,583 · App. 18/746,458 · Granted Jul 29, 2025

Open source library security rating

Inventors: Xun Sun (Shanghai, CN); Huaiyu Yan (Nanjing, CN); Chuyunxiao Zhong (Shanghai, CN)
Assignee: SAP SE
G06F21/604G06F8/65G06F8/77G06F21/51G06F2221/033G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,373,583
App. No.
18/746,458
Granted
Jul 29, 2025
Kind
B2
Abstract

An open source library rating is generated for an open source library based on dependencies of the library, vulnerabilities of the library, an age of the library, a popularity of the library, a history of the library, or any suitable combination thereof. The rating of a specific version of a library may be generated based on a base score for all versions of the library and a version score for the specific version of the library. An authorization system receives a request from a developer to add a library to a software application. In response, the authorization system accesses a rating for the library. Based on the rating, the authorization system approves the request, denies the request, or recommends an alternative library.

Claims (58)

1. A system comprising:

a memory that stores instructions; and

one or more processors configured by the instructions to perform operations comprising:

receiving, via a network, a request for a version of a first library;

accessing a database to obtain first data comprising a first score that applies to all of a plurality of versions of the first library, the requested version being one of the plurality of versions;

accessing second data comprising a second score that is based on a dependency of the requested version of the first library on a second library;

generating a rating for the requested version of the first library based on the first score and the second score; and

based on the rating, communicating, via the network, an approval of the request.

2. The system of claim 1 , wherein the operations further comprise:

requesting, via the network, fourth data representing a published time and severity of each known vulnerability of the requested version of the first library;

receiving, in response to the request, the fourth data;

determining, based on the published time of each known vulnerability of the requested version of the first library and a release time of the requested version of the first library, a duration of time for each known vulnerability of the requested version of the first library;

generating the second score based on the durations of time for the known vulnerabilities of the requested version of the first library; and

storing the second score in the database.

3. The system of claim 2 , wherein:

the generating of the second score comprises applying weights to the severity of each known vulnerability of the requested version of the first library, such that vulnerabilities with shorter durations affect the second score more than vulnerabilities with longer durations.

4. The system of claim 2 , wherein:

the generating of the second score comprises applying weights to the severity of each known vulnerability of the requested version of the first library, such that vulnerabilities with higher severities affect the second score more than vulnerabilities with lower severities.

5. The system of claim 2 , wherein the first score is further based on a popularity of the first library.

6. The system of claim 5 , wherein a lower number of libraries that depend on the requested version of the first library has a greater effect on the rating than a higher number of libraries that depend on the requested version of the first library.

7. A non-transitory computer-readable medium that stores instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving, via a network, a request for a version of a first library;

accessing a database to obtain first data comprising a first score that applies to all of a plurality of versions of the first library, the requested version being one of the plurality of versions;

accessing second data comprising a second score that is based on a dependency of the requested version of the first library on a second library;

generating a rating for the requested version of the first library based on the first score and the second score; and

based on the rating, communicating, via the network, an approval of the request.

8. The non-transitory computer-readable medium of claim 7 , wherein the operations further comprise:

requesting, via the network, fourth data representing a published time and severity of each known vulnerability of the requested version of the first library;

receiving, in response to the request, the fourth data;

determining, based on the published time of each known vulnerability of the requested version of the first library and a release time of the requested version of the first library, a duration of time for each known vulnerability of the requested version of the first library;

generating the second score based on the durations of time for the known vulnerabilities of the requested version of the first library; and

storing the second score in the database.

9. The non-transitory computer-readable medium of claim 8 , wherein:

the generating of the second score comprises applying weights to the severity of each known vulnerability of the requested version of the first library, such that vulnerabilities with shorter durations affect the second score more than vulnerabilities with longer durations.

10. The non-transitory computer-readable medium of claim 8 , wherein:

the generating of the second score comprises applying weights to the severity of each known vulnerability of the requested version of the first library, such that vulnerabilities with higher severities affect the second score more than vulnerabilities with lower severities.

11. The non-transitory computer-readable medium of claim 7 , wherein the first score is further based on a popularity of the first library.

12. The non-transitory computer-readable medium of claim 11 , wherein a lower number of libraries that depend on the requested version of the first library has a greater effect on the rating than a higher number of libraries that depend on the requested version of the first library.

13. A method comprising:

receiving, via a network, a request for a version of a first library;

accessing a database to obtain first data comprising a first score that applies to all of a plurality of versions of the first library, the requested version being one of the plurality of versions;

accessing second data comprising a second score that is based on a dependency of the requested version of the first library on a second library;

generating, by one or more processors, a rating for the requested version of the first library based on the first score and the second score; and

based on the rating, communicating, via the network, an approval of the request.

14. The method of claim 13 , further comprising:

requesting, via the network, fourth data representing a published time and severity of each known vulnerability of the requested version of the first library;

receiving, in response to the request, the fourth data;

determining, based on the published time of each known vulnerability of the requested version of the first library and a release time of the requested version of the first library, a duration of time for each known vulnerability of the requested version of the first library;

generating the second score based on the durations of time for the known vulnerabilities of the requested version of the first library; and

storing the second score in the database.

15. The method of claim 14 , wherein:

the generating of the second score comprises applying weights to the severity of each known vulnerability of the requested version of the first library, such that vulnerabilities with shorter durations affect the second score more than vulnerabilities with longer durations.

16. The method of claim 14 , wherein:

the generating of the second score comprises applying weights to the severity of each known vulnerability of the requested version of the first library, such that vulnerabilities with higher severities affect the second score more than vulnerabilities with lower severities.

17. The method of claim 13 , wherein the first score is further based on a popularity of the first library.

18. The method of claim 17 , wherein a lower number of libraries that depend on the requested version of the first library has a greater effect on the rating than a higher number of libraries that depend on the requested version of the first library.

19. The method of claim 13 , wherein the generating of the rating for the requested version of the first library is further based on an age of the requested version of the first library.

20. The method of claim 19 , wherein a greater age has a greater effect on the rating than a lesser age.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 19, 2024
From: SUN, XUN; YAN, HUAIYU; ZHONG, CHUYUNXIAO
To: SAP SE
Reel/Frame 067769/0878 →
Continuity (4)
Continuation 18205911 · Jun 5, 2023
Continuation 17364112 · Jun 30, 2021
Continuation 16403803 · May 6, 2019
Related Publication 20240338463A1 · Oct 10, 2024
References Cited (23)
US 9135591B1 · Nicol · 2015 [cited by examiner]
US 10235527B1 · Dalessio et al. · 2019 [cited by applicant]
US 10579803B1 · Mueller et al. · 2020 [cited by applicant]
US 11100239B2 · Sun et al. · 2021 [cited by applicant]
US 11709949B2 · Sun et al. · 2023 [cited by applicant]
US 11749494B2 · Miwa et al. · 2023 [cited by applicant]
US 20040221176A1 · Cole · 2004 [cited by applicant]
US 20140165034A1 · Balasubramanian · 2014 [cited by examiner]
US 20190079734A1 · Kadam et al. · 2019 [cited by applicant]
US 20190205542A1 · Kao · 2019 [cited by examiner]
US 20200202007A1 · Nagaraja · 2020 [cited by examiner]
US 20200218533A1 · Sharma et al. · 2020 [cited by applicant]
US 20200242254A1 · Velur · 2020 [cited by examiner]
US 20200356681A1 · Sun et al. · 2020 [cited by applicant]
US 20210326462A1 · Sun et al. · 2021 [cited by applicant]
US 20230325518A1 · Sun et al. · 2023 [cited by applicant]
“U.S. Appl. No. 16/403,803, Notice of Allowance mailed Apr. 28, 2021”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 17/364,112, Non Final Office Action mailed Mar. 3, 2023”, 6 pgs. [cited by applicant]
“U.S. Appl. No. 17/364,112, Notice of Allowance mailed May 12, 2023”, 8 pgs. [cited by applicant]
“U.S. Appl. No. 17/364,112, Response filed Apr. 25, 2023 to Non Final Office Action mailed Mar. 3, 2023”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 18/205,911, Non-Final Office Action mailed Feb. 22, 2024”, 7 pgs. [cited by applicant]
“U.S. Appl. No. 18/205,911, Notice of Allowance mailed Apr. 19, 2024”, 7 pgs. [cited by applicant]
“U.S. Appl. No. 18/205,911, Response filed Apr. 3, 2024 to Non Final Office Action mailed Feb. 22, 2024”, 8 pgs. [cited by applicant]