Out of sight, out of mind? How vulnerable dependencies affect open-source projects

GAA Prana, A Sharma, LK Shar, D Foo… - Empirical Software …, 2021 - Springer
Context Software developers often use open-source libraries in their project to improve
development speed. However, such libraries may contain security vulnerabilities, and this …

On the outdatedness of workflows in the GitHub Actions ecosystem

A Decan, T Mens, HO Delicheh - Journal of Systems and Software, 2023 - Elsevier
GitHub Actions was introduced as a way to automate CI/CD workflows in GitHub, the largest
social coding platform. Thanks to its deep integration into GitHub, GitHub Actions can be …

Quantifying security issues in reusable JavaScript actions in GitHub workflows

H Onsori Delicheh, A Decan, T Mens - Proceedings of the 21st …, 2024 - dl.acm.org
GitHub's integrated automated workflow mechanism called GitHub Actions promotes the use
of Actions as reusable building blocks in workflows. The majority of those Actions are …

Mitigating security issues in github actions

HO Delicheh, T Mens - Proceedings of the 2024 ACM/IEEE 4th …, 2024 - dl.acm.org
Collaborative practices have revolutionised the software development process, enabling
distributed teams to seamlessly work together. Social coding platforms have integrated …

[PDF][PDF] A Preliminary Study of GitHub Actions Dependencies.

HO Delicheh, A Decan, T Mens - SATToSE, 2023 - ceur-ws.org
GitHub Actions was introduced in 2019 as a software development workflow automation
tool, allowing to automate a wide range of social and technical activities in GitHub …

Quantifying Security Issues in Reusable JavaScript Actions in GitHub Workflows

A Decan, T Mens - 21st International Conference on Mining …, 2024 - orbi.umons.ac.be
GitHub's integrated automated workflow mechanism called GitHub Actions promotes the use
of Actions as reusable building blocks in workflows. The majority of those Actions are …

[图书][B] Software Ecosystems: Tooling and Analytics

T Mens, C De Roover, A Cleve - 2023 - books.google.com
This book highlights recent research advances in various domains related to software
ecosystems such as library reuse, collaborative development, cloud computing, open …

An introduction to software ecosystems

T Mens, CD Roover - Software Ecosystems: Tooling and Analytics, 2023 - Springer
This chapter defines and presents the kinds of software ecosystems that are targeted in this
book. The focus is on the development, tooling, and analytics aspects of “software …

A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software

SHBI Kumar, LR Sampaio, A Martin… - 2024 IEEE 35th …, 2024 - ieeexplore.ieee.org
Open-source libraries are widely used by software developers to speed up the development
of products, however, they can introduce security vulnerabilities, leading to incidents like …

Mitigating Security Issues in GitHub Actions

T Mens - 2024 ACM/IEEE 4th International Workshop on …, 2024 - orbi.umons.ac.be
Collaborative practices have revolutionised the software development process, enabling
distributed teams to seamlessly work together. Social coding platforms have integrated …