Abstract: The widespread use of importing open-source software (OSS) as third-party libraries (TPLs) in software development has introduced critical open-source security risks. These security risks ...