Preliminary Findings on FOSS Dependencies and Security: A Qualitative Study on Developers' Attitudes and Experience

I. Pashchenko, D.-L. Vu, Fabio Massacci

Research output: Chapter in Book / Report / Conference proceedingConference contributionAcademicpeer-review

17 Downloads (Pure)

Abstract

Developers are known to keep third-party dependencies of their projects outdated even if some of them are affected by known vulnerabilities. In this study we aim to understand why they do so. For this, we conducted 25 semi-structured interviews with developers of both large and small-medium enterprises located in nine countries. All interviews were transcribed, coded, and analyzed according to applied thematic analysis. The results of the study reveal important aspects of developers' practices that should be considered by security researchers and dependency tool developers to improve the security of the dependency management process.
Original languageEnglish
Title of host publicationICSE '20: Proceedings of the ACM/IEEE 42nd International Conference on Software Engineering
Subtitle of host publicationCompanion Proceedings
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages284-285
Number of pages2
ISBN (Electronic)9781450371223
DOIs
Publication statusPublished - Jun 2020
Event42nd ACM/IEEE International Conference on Software Engineering: Companion, ICSE-Companion 2020 - Seoul, Korea, Republic of
Duration: 27 Jun 202019 Jul 2020

Conference

Conference42nd ACM/IEEE International Conference on Software Engineering: Companion, ICSE-Companion 2020
Country/TerritoryKorea, Republic of
CitySeoul
Period27/06/2019/07/20

Funding

This research has been partly funded by the EU under the H2020 Programs H2020-EU.2.1.1-CyberSec4Europe (Grant No. 830929) and the NeCS: European Network for Cyber Security (Grant No. 675320).

FundersFunder number
European Network for Cyber Security675320
Horizon 2020 Framework Programme830929
European Commission

    Fingerprint

    Dive into the research topics of 'Preliminary Findings on FOSS Dependencies and Security: A Qualitative Study on Developers' Attitudes and Experience'. Together they form a unique fingerprint.

    Cite this