On the use of github actions in software development repositories

A Decan, T Mens, PR Mazrae… - 2022 IEEE International …, 2022 - ieeexplore.ieee.org
GitHub Actions was introduced in 2019 and constitutes an integrated alternative to CI/CD
services for GitHub repositories. The deep integration with GitHub allows repositories to …

On the impact of security vulnerabilities in the npm and RubyGems dependency networks

A Zerouali, T Mens, A Decan, C De Roover - Empirical Software …, 2022 - Springer
The increasing interest in open source software has led to the emergence of large language-
specific package distributions of reusable software libraries, such as npm and RubyGems …

On the outdatedness of workflows in the GitHub Actions ecosystem

A Decan, T Mens, HO Delicheh - Journal of Systems and Software, 2023 - Elsevier
GitHub Actions was introduced as a way to automate CI/CD workflows in GitHub, the largest
social coding platform. Thanks to its deep integration into GitHub, GitHub Actions can be …

An Overview and Catalogue of Dependency Challenges in Open Source Software Package Registries

T Mens, A Decan - arxiv preprint arxiv:2409.18884, 2024 - arxiv.org
While open-source software has enabled significant levels of reuse to speed up software
development, it has also given rise to the dreadful dependency hell that all software …

Chronos: Time-aware zero-shot identification of libraries from vulnerability reports

Y Lyu, T Le-Cong, HJ Kang, R Widyasari… - 2023 IEEE/ACM 45th …, 2023 - ieeexplore.ieee.org
Tools that alert developers about library vulnerabilities depend on accurate, up-to-date
vulnerability databases which are maintained by security researchers. These databases …

Plumber: Boosting the Propagation of Vulnerability Fixes in the npm Ecosystem

Y Wang, P Sun, L Pei, Y Yu, C Xu… - IEEE Transactions …, 2023 - ieeexplore.ieee.org
Vulnerabilities are known reported security threats that affect a large amount of packages in
the npm ecosystem. To mitigate these security threats, the open-source community strongly …

Latency-aware container scheduling in edge cluster upgrades: a deep reinforcement learning approach

H Cui, Z Tang, J Lou, W Jia… - IEEE Transactions on …, 2024 - ieeexplore.ieee.org
In Mobile Edge Computing (MEC), Internet of Things (IoT) devices offload computationally-
intensive tasks to edge nodes, where they are executed within containers, reducing the …

Modeling interconnected social and technical risks in open source software ecosystems

W Schueller, J Wachs - Collective intelligence, 2024 - journals.sagepub.com
Open source software ecosystems consist of thousands of interdependent libraries, which
users can combine to great effect. Recent work has pointed out two kinds of risks in these …

Where to go now? Finding alternatives for declining packages in the npm ecosystem

S Mujahid, DE Costa, R Abdalkareem… - 2023 38th IEEE/ACM …, 2023 - ieeexplore.ieee.org
Software ecosystems (eg, npm, PyPI) are the backbone of modern software developments.
Developers add new packages to ecosystems every day to solve new problems or provide …

Software Security Analysis in 2030 and Beyond: A Research Roadmap

M Böhme, E Bodden, T Bultan, C Cadar, Y Liu… - ACM Transactions on …, 2024 - dl.acm.org
As our lives, our businesses, and indeed our world economy become increasingly reliant on
the secure operation of many interconnected software systems, the software engineering …