Mining Pull Requests to Detect Process Anomalies in Open Source Software Development
Bohan Liu, He Zhang, Weigang Ma, Hongyu Kuang, Yi Yang, Jinwei Xu, Shan Gao, Jian Gao
Abstract
Trustworthy Open Source Software (OSS) development processes are the basis that secures the long-term trustworthiness of software projects and products. With the aim to investigate the trustworthiness of the Pull Request (PR) process, the common model of collaborative development in OSS community, we exploit process mining to identify and analyze the normal and anomalous patterns of PR processes, and propose our approach to identifying anomalies from both control-flow and semantic aspects, and then to analyze and synthesize the root causes of the identified anomalies. We analyze 17531 PRs of 18 OSS projects on GitHub, extracting 26 root causes of control-flow anomalies and 19 root causes of semantic anomalies. We find that most PRs can hardly contain both semantic anomalies and control-flow anomalies, and the internal custom rules in projects may be the key causes for the identified anomalous PRs. We further discover and analyze the patterns of normal PR processes. We find that PRs in the non-fork model (42%) are far more likely than the fork model (5%) to bypass the review process, indicating a higher potential risk. Besides, we analyzed nine poisoned projects whose PR practices were indeed worse. Given the complex and diverse PR processes in OSS community, the proposed approach can help identify and understand not only anomalous PRs but also normal PRs, which offers early risk indications of suspicious incidents (such as poisoning) to OSS supply chain.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get d5fbd180-8194-429e-b839-73dc4c3e5b62Cited by top-tier papers1
Ask how each one uses itRelated papers
- Opportunities and Challenges in Repeated Revisions to Pull-Requests: An Empirical StudyZhixing Li, Yue Yu, Tao Wang, Shanshan Li et al.CSCW 2022 · 11 citations
- Who's Pushing the Code? An Exploration of GitHub ImpersonationYueke Zhang, Anda Liang, Xiaohan Wang, Pamela J. Wisniewski et al.ICSE 2025 · 2 citations
- Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software ProjectsDominik Wermke, Noah Wöhler, Jan H. Klemmer, Marcel Fourné et al.S&P 2022 · 54 citations
- Fork Entropy: Assessing the Diversity of Open Source Software Projects' ForksLiang Wang, Zhiwen Zheng, Xiangchen Wu, Baihui Sang et al.ASE 2023 · 8 citations
- Modeling Review History for Reviewer Recommendation: A Hypergraph ApproachGuoping Rong, Yifan Zhang, Lanxin Yang, Fuli Zhang et al.ICSE 2022 · 20 citations
