Skip to content

Are you using Tai-e? #66

Description

@silverbullettt

The Purpose of This Issue

We are consistently eager to learn more about Tai-e users, understand what led you to choose our framework, attentively address your requirements, and help promote your work on program analysis.

  • We often receive inquiries from those wondering about Tai-e's utilization.
  • We highly value your input on desired Tai-e features and usage scenarios, and we are keen to hear your suggestions.
  • We would like to help promote your work or open-source tools on program analysis (if you have used Tai-e to develop a tool that solves a specific problem, we also want to help promote it, making it accessible to other users who may find it useful).

What We Would Like To Hear From You

We kindly ask that you submit a comment in this issue to provide the following information:

  • Your organization/company
  • Your organization's website (optional)
  • Your country/region
  • Your contact info: blog/personal website, email or Twitter (at least one)
  • Your usage scenario for Tai-e, e.g., conducting research or developing program analysis tools based on Tai-e, referring to Tai-e for implementing my own program analysis tools, etc.

For example:

Organization/Company: Nanjing University
Website: https://www.nju.edu.cn/
Country/Region: China
Contact: https://cs.nju.edu.cn/tiantan, tiantan@nju.edu.cn
Usage scenario: Using Tai-e to
(1) conducting research in program analysis for addressing XXX problem,
(2) developing XXX program analysis tools,
(3) referring to Tai-e for implementing our own XXX program analysis frameworks and tools,
etc.

We will pay attention to this issue.
Whether you are from a company or a university, we encourage you to leave your usage information of Tai-e.
We will prioritize addressing the problems and needs of users who leave usage information in this issue.

Activity

  1. pinned this issue on Oct 22, 2023
  2. deleted a comment from ningninger on Oct 22, 2023
  3. LFYSec commented on Oct 28, 2023

    @LFYSec

    Organization/Company: Fudan University
    Country/Region: China
    Contact: 23110240120@m.fudan.edu.cn
    Usage scenario: Using Tai-e to develop static analysis tools

  4. YaphetsH commented on Oct 31, 2023

    @YaphetsH
    Contributor

    Organization/Company: Meituan Mobile Security Team
    Country/Region: China
    Contact: Yaphetsh@outlook.com
    Usage scenario: Using Tai-e to Mobile Security Research and Development

  5. Peteling commented on Oct 31, 2023

    @Peteling

    Organization/Company: Personal
    Country/Region: Singapore
    Contact: voidness1023@gmail.com
    Usage scenario: Using Tai-e to develop static analysis tools

  6. Liyw979 commented on Nov 2, 2023

    @Liyw979

    Organization/Company: Huawei
    Country/Region: China
    Contact: liyiwei14@huawei.com
    Usage scenario: referring to Tai-e for implementing my own program analysis tools

  7. jiecse commented on Nov 3, 2023

    @jiecse

    Organization/Company: ByteDance
    Country/Region: China
    Contact: liujie.jl@bytedance.com
    Usage scenario: referring to the design from tai-e to develop our own static analysis framework

  8. DeReWu commented on Nov 3, 2023

    @DeReWu

    Organization/Company: AntGroup
    Country/Region: China
    Contact: wudiyu.wdy@antgroup.com
    Usage scenario: referring to Tai-e for our own program analysis platform

  9. w22cao commented on Mar 25, 2024

    @w22cao

    Organization/Company: University of Chinese Academy of Sciences
    Country/Region: China
    Contact: owhvayifuqq@gmail.com
    Usage scenario: Using Tai-e to extract useful information, such as call graphs and so on

  10. littlematch59 commented on Apr 22, 2024

    @littlematch59

    Organization/Company: ZheJiang University
    Country/Region: China
    Contact: wuzhiyao@zju.edu.cn
    Usage scenario: Using Tai-e for taint analysis and generating call graph.

  11. YunFy26 commented on Oct 14, 2024

    @YunFy26

    Organization/Company: Southeast University
    Country/Region: China
    Contact: 220235339@seu.edu.cn
    Usage scenario: Using Tai-e to develop a tool for analyzing Spring projects.

  12. anabioticsoul commented on Dec 15, 2024

    @anabioticsoul

    Organization/Company: Nankai University
    Country/Region: China
    Contact: yuhao.liu@mail.nankai.edu.cn
    Usage scenario: Using Tai-e for
    (1) learning and implementing custom static analysis,
    (2) conducting research in software misconfigurations for addressing detecting/diagnosing/validation problem.

  13. FoggyDawn commented on May 23, 2025

    @FoggyDawn
    Contributor

    Organization/Company: Zhejiang University
    Country/Region: China
    Contact: yixuanbu@zju.edu.cn
    Usage scenario: Using Tai-e to conducting research in program analysis for addressing Influence of call site reachability

  14. GabrielBBaldez commented on Jun 16, 2026

    @GabrielBBaldez

    Organization/Company: Independent (personal open-source project)
    Country/Region: Brazil
    Contact: https://github.com/GabrielBBaldez

    Usage scenario: I built spring-taint, an interprocedural taint analyzer for Spring Boot, on top of Tai-e. A thin Spring layer registers controller/listener entry points and emits param/call sources for Spring annotations (@RequestParam, @RequestBody, @KafkaListener, @RabbitListener, @FeignClient, JAX-RS/Micronaut, ...), and Tai-e's call graph, pointer analysis and IFDS taint analysis do the heavy lifting -- flagging source->sink flows that cross controller/service/repository layers, which same-method scanners miss. It detects SQL/JPQL injection, XSS, SSRF, SpEL/JNDI/template injection, path traversal, command injection and open redirect, and ships as a CLI, a Docker image and a GitHub Action (SARIF 2.1, now on the Marketplace).

    The TaintConfigProvider / Plugin extension points and call-site-mode sink matching made the Spring modeling clean to layer on. Thanks for the framework!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions