A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features
Jessy Ayala, Yu-Jye Tung, Joshua Garcia
摘要
In open-source software (OSS), software vulnerabilities have significantly increased. Although researchers have investigated the perspectives of vulnerability reporters and OSS contributor security practices, understanding the perspectives of OSS maintainers on vulnerability management and platform security features is currently understudied. In this paper, we investigate the perspectives of OSS maintainers who maintain projects listed in the GitHub Advisory Database. We explore this area by conducting two studies: identifying aspects through a listing survey () and gathering insights from semi-structured interviews (). Of the 37 identified aspects, we find that supply chain mistrust and lack of automation for vulnerability management are the most challenging, and barriers to adopting platform security features include a lack of awareness and the perception that they are not necessary. Surprisingly, we find that despite being previously vulnerable, some maintainers still allow public vulnerability reporting, or ignore reports altogether. Based on our findings, we discuss implications for OSS platforms and how the research community can better support OSS vulnerability management efforts.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Action Required: A Mixed-Methods Study of Security Practices in GitHub ActionsYusuke Kubo, Fumihiro Kanei, Mitsuaki Akiyama, Takuro Wakai 等NDSS 2026 · 被引用 3 次
- Credible Threat Detection? Measuring Contribution Dynamics and Quality Control in a Crowdsourced Threat Detection EcosystemApurva Virkud, Gang Wang, Adam BatesUSENIX Security 2026 · 被引用 1 次
它引用的顶会 Paper20
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- Large Language Models Meet NL2Code: A SurveyDaoguang Zan, Bei Chen, Fengji Zhang, Dianjie Lu 等ACL 2023 · 被引用 104 次
- An Empirical Study on Software Bill of Materials: Where We Stand and the Road AheadBoming Xia, Tingting Bi, Zhenchang Xing, Qinghua Lu 等ICSE 2023 · 被引用 82 次
- "Did You Miss My Comment or What?" Understanding Toxicity in Open Source DiscussionsCourtney Miller, Sophie Cohen, Daniel Klug, Bogdan Vasilescu 等ICSE 2022 · 被引用 54 次
- Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software ProjectsDominik Wermke, Noah Wöhler, Jan H. Klemmer, Marcel Fourné 等S&P 2022 · 被引用 54 次
相关 Paper
- A Deep Dive into How Open-Source Project Maintainers Review and Resolve Bug Bounty ReportsJessy Ayala, Steven Ngo, Joshua GarciaS&P 2025
- Between Risk, Recognition, and Necessity: How Open-Source Project Maintainers Perceive and Navigate CVEs Through Reporting and Resolving VulnerabilitiesJessy Ayala, Steven Ngo, Joshua GarciaCCS 2026
- "Threat modeling is very formal, it's very technical, and also very hard to do correctly": Investigating Threat Modeling Practices in Open-Source Software ProjectsHarjot Kaur, Carson Powers, Ronald E. Thompson III, Sascha Fahl 等USENIX Security 2025
- Vision: Identifying Affected Library Versions for Open Source Software VulnerabilitiesSusheng Wu, Ruisi Wang, Kaifeng Huang, Yiheng Cao 等ASE 2024 · 被引用 1 次
- Death Is Not the End: a Longitudinal Study on the Impact of Automatic Updates on Container Vulnerability LifespansSimge Tekin, Octavian Suciu, Sungsu Kwag, Yonghwi Kwon 等S&P 2026 · 被引用 1 次
