Publications (4)
Secure Software Development in the Era of Fluid Multi-party Open Software and Services
Ivan Pashchenko, Riccardo Scandariato, Antonino Sabetta +1
Pushed by market forces, software development has become fast-paced. As a consequence, modern development projects are assembled from 3rd-party components. Security & privacy assur…
Technical Leverage in a Software Ecosystem: Development Opportunities and Security Risks
Fabio Massacci, Ivan Pashchenko
In finance, leverage is the ratio between assets borrowed from others and one's own assets. A matching situation is present in software: by using free open-source software (FOSS) l…
A Fine-grained Data Set and Analysis of Tangling in Bug Fixing Commits
Steffen Herbold, Alexander Trautsch, Benjamin Ledel +45
Context: Tangled commits are changes to software that address multiple concerns at once. For researchers interested in bugs, tangled commits mean that they actually study not only…
Vulnerable Open Source Dependencies: Counting Those That Matter
Ivan Pashchenko, Henrik Plate, Serena Elisa Ponta +2
BACKGROUND: Vulnerable dependencies are a known problem in today's open-source software ecosystems because OSS libraries are highly interconnected and developers do not always upda…