Paper-Conference

On Categorizing Open Source Software Security Vulnerability Reporting Mechanisms on GitHub
Open-source projects are essential to software development, but publicly disclosing vulnerabilities without fixes increases the risk of …
An Empirical Study of Security-Policy Related Issues in Open Source Projects
Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem
On the Use of Agentic Coding Manifests: An Empirical Study of Claude Code