Towards automatic vulnerability management in open-source software