6 citations · 7 across the 3 of their papers we have counts for
7 papers
CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages
Imranur Rahman, Jill Marley, Ranindya Paramitha +1
Dependency resolution at a specified point in time in the past can provide insight into software evolution in software ecosystems and facilitate the design of dynamic metrics (e.g.…
How Quickly Do Development Teams Update Their Vulnerable Dependencies?
Imranur Rahman, Ranindya Paramitha, Nusrat Zahan +2
Industry practitioners are increasingly concerned with software that contains vulnerable versions of third-party dependencies that are included both directly and transitively. To a…
Which Is Better For Reducing Outdated and Vulnerable Dependencies: Pinning or Floating?
Imranur Rahman, Jill Marley, William Enck +1
Developers consistently use version constraints to specify acceptable versions of the dependencies for their project. Pinning dependencies can reduce the likelihood of breaking cha…
Relative Positioning Based Code Chunking Method For Rich Context Retrieval In Repository Level Code Completion Task With Code Language Model
Imranur Rahman, Md Rayhanur Rahman
Code completion can help developers improve efficiency and ease the development lifecycle. Although code completion is available in modern integrated development environments (IDEs…
Assumptions to Evidence: Evaluating Security Practices Adoption and Their Impact on Outcomes in the npm Ecosystem
Nusrat Zahan, Imranur Rahman, Laurie Williams
Practitioners often struggle with the overwhelming number of security practices outlined in cybersecurity frameworks for risk mitigation. Given the limited budget, time, and resour…
S3C2 Summit 2024-09: Industry Secure Software Supply Chain Summit
Imranur Rahman, Yasemin Acar, Michel Cukier +5
While providing economic and software development value, software supply chains are only as strong as their weakest link. Over the past several years, there has been an exponential…