Thomas Durieux
Program-analysis engineer. I build static analysis at scale — from compiler-grade tooling to production AI SAST — at Endor Labs. Below: a catalogue of the software and research I've built.
Anonymous GitHub
A web service that anonymizes GitHub repositories so they can be shared in double-blind paper submissions.
Open ScienceWeb ServiceGitHub
12.5M requests / month view →
docker-parfum
A static analyzer and autofix tool for Dockerfiles, built on Tree-sitter.
Program AnalysisDockerTree-sitter
32 rules · autofix view →
EnergiBridge
A cross-platform tool to measure software energy consumption (CPU, GPU, RAM).
SustainabilityMeasurementRust
Linux · macOS · Windows view →
index of works 19 projects
№ProjectYear
01 Spoon An open-source library for parsing, analyzing, and transforming Java source code as an AST. 2014— 02 Anonymous GitHub A web service that anonymizes GitHub repositories so they can be shared in double-blind paper submissions. 2017— 03 docker-parfum A static analyzer and autofix tool for Dockerfiles, built on Tree-sitter. 2023 04 Dinghy A versatile AST parser for shell scripts and Dockerfiles. 2023 05 EnergiBridge A cross-platform tool to measure software energy consumption (CPU, GPU, RAM). 2023 06 BibTeX2Wiki Converts BibTeX entries into Wikipedia-style references. 2014 07 BikiniProxy A research prototype HTTP proxy that rewrites buggy client-side HTML and JavaScript to keep web pages working. 2018 08 BlueLaTeX A toolchain for collaborative, real-time LaTeX editing. 2014 09 c2Spoon Maps the XML representation of a C program onto the Java AST used by Spoon. 2019 10 Defects4J Dissection Data and analysis describing the patches in the Defects4J bug dataset. 2018 11 IntroClassJava A Java port of the IntroClass benchmark of small buggy programs. 2016 12 Itzal A research prototype for generating patches directly in a production environment. 2017 13 LeBonCoin JS API A JavaScript client for the leboncoin.fr listings API. 2016 14 Maven-repair A Maven plugin to run automated program repair on a project. 2017 15 Nopol An automatic repair tool for Java bugs in conditional statements. 2016 16 NPEFix A research tool that explores runtime strategies to recover from null-pointer exceptions in Java. 2017 17 SmartBugs A framework for running static-analysis tools over Solidity smart contracts, with a curated vulnerability dataset. 2019 18 SyncTeX-js A SyncTeX parser written in JavaScript. 2015 19 Travis Listener A small library that streams new builds from the Travis CI API in real time. 2019