We should evaluate atom+chen on a simple end-to-end flow: - [x] Install atom+chen - [x] Select a good CVE to use as a test. - https://github.com/aboutcode-org/vulnerablecode/issues/327 may be useful - [x] Collect the fix patch/commit - [x] Compute the graph on the vulnerable package with atom+chen - [x] Query that graph using fix patch/commit symbols (function, etc....) - [x] Report here about the experience