EDBT 2026 Demo / reviewers in the wild / expert
Vitalis Salis
dblp:243/2569
· DBLP profile ↗
2ranked-venue papers
1as first author
1since 2021 · last 2021
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 100% | |
| Network and information security
1 paper |
Systems and software security · 100% |
Topics — the 4 heaviest of 4, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Program analysis › static analysis
call graph construction |
0.5 | 1 | 2021 | PyCG: Practical Call Graph Generation in Python · ICSE 2021 |
Program analysis › static analysis
interprocedural analysis |
0.5 | 1 | 2021 | PyCG: Practical Call Graph Generation in Python · ICSE 2021 |
Program analysis
static analysis |
0.5 | 1 | 2021 | PyCG: Practical Call Graph Generation in Python · ICSE 2021 |
Systems and software security
vulnerability discovery |
0.1 | 1 | 2021 | PyCG: Practical Call Graph Generation in Python · ICSE 2021 |
Methods — techniques the papers use, named apart from their topics
static analysis · 1.0interprocedural analysis · 0.5inter-procedural analysis · 0.5
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | PyCG: Practical Call Graph Generation in PythonabstractCall graphs play an important role in different contexts, such as profiling and vulnerability propagation analysis. Generating call graphs in an efficient manner can be a challenging task when it comes to high-level languages that are modular and incorporate dynamic features and higher-order functions. Despite the language's popularity, there have been very few tools aiming to generate call graphs for Python programs. Worse, these tools suffer from several effectiveness issues that limit their practicality in realistic programs. We propose a pragmatic, static approach for call graph generation in Python. We compute all assignment relations between program identifiers of functions, variables, classes, and modules through an inter-procedural analysis. Based on these assignment relations, we produce the resulting call graph by resolving all calls to potentially invoked functions. Notably, the underlying analysis is designed to be efficient and scalable, handling several Python features, such as modules, generators, function closures, and multiple inheritance. We have evaluated our prototype implementation, which we call PyCG, using two benchmarks: a micro-benchmark suite containing small Python programs and a set of macro-benchmarks with several popular real-world Python packages. Our results indicate that PyCG can efficiently handle thousands of lines of code in less than a second (0.38 seconds for 1k LoC on average). Further, it outperforms the state-of-the-art for Python in both precision and recall: PyCG achieves high rates of precision ~99.2% and adequate recall ~69.9%. Finally, we demonstrate how PyCG can aid dependency impact analysis by showcasing a potential enhancement to GitHub's "security advisory" notification service using a real-world example. Vitalis Salis, Thodoris Sotiropoulos, Panagiotis Louridas, Diomidis Spinellis, Dimitris Mitropoulos |
ICSE | 1 |
| 2019 | Time present and time past: analyzing the evolution of JavaScript code in the wildabstractJavaScript is one of the web's key building blocks. It is used by the majority of web sites and it is supported by all modern browsers. We present the first large-scale study of client-side JavaScript code over time. Specifically, we have collected and analyzed a dataset containing daily snapshots of JavaScript code coming from Alexa's Top 10000 web sites (~7.5 GB per day) for nine consecutive months, to study different temporal aspects of web client code. We found that scripts change often; typically every few days, indicating a rapid pace in web applications development. We also found that the lifetime of web sites themselves, measured as the time between JavaScript changes, is also short, in the same time scale. We then performed a qualitative analysis to investigate the nature of the changes that take place. We found that apart from standard changes such as the introduction of new functions, many changes are related to online configuration management. In addition, we examined JavaScript code reuse over time and especially the widespread reliance on third-party libraries. Furthermore, we observed how quality issues evolve by employing established static analysis tools to identify potential software bugs, whose evolution we tracked over time. Our results show that quality issues seem to persist over time, while vulnerable libraries tend to decrease. Dimitris Mitropoulos, Panagiotis Louridas, Vitalis Salis, Diomidis Spinellis |
MSR | 3 |