most citedHow Quickly Do Development Teams Update Their Vulnerable Dependencies?

6 citations · 7 across the 3 of their papers we have counts for

collaborators

7 papers

cs.SE2026

CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages

Imranur Rahman, Jill Marley, Ranindya Paramitha +1

Dependency resolution at a specified point in time in the past can provide insight into software evolution in software ecosystems and facilitate the design of dynamic metrics (e.g.…

cs.SE20266 cited

How Quickly Do Development Teams Update Their Vulnerable Dependencies?

Imranur Rahman, Ranindya Paramitha, Nusrat Zahan +2

Industry practitioners are increasingly concerned with software that contains vulnerable versions of third-party dependencies that are included both directly and transitively. To a…

cs.SE20261 cited

Which Is Better For Reducing Outdated and Vulnerable Dependencies: Pinning or Floating?

Imranur Rahman, Jill Marley, William Enck +1

Developers consistently use version constraints to specify acceptable versions of the dependencies for their project. Pinning dependencies can reduce the likelihood of breaking cha…

cs.SE2025

Relative Positioning Based Code Chunking Method For Rich Context Retrieval In Repository Level Code Completion Task With Code Language Model

Imranur Rahman, Md Rayhanur Rahman

Code completion can help developers improve efficiency and ease the development lifecycle. Although code completion is available in modern integrated development environments (IDEs…

cs.SE2025

Assumptions to Evidence: Evaluating Security Practices Adoption and Their Impact on Outcomes in the npm Ecosystem

Nusrat Zahan, Imranur Rahman, Laurie Williams

Practitioners often struggle with the overwhelming number of security practices outlined in cybersecurity frameworks for risk mitigation. Given the limited budget, time, and resour…

cs.CR2025

S3C2 Summit 2024-09: Industry Secure Software Supply Chain Summit

Imranur Rahman, Yasemin Acar, Michel Cukier +5

While providing economic and software development value, software supply chains are only as strong as their weakest link. Over the past several years, there has been an exponential…