most citedHow Quickly Do Development Teams Update Their Vulnerable Dependencies?

6 citations · 6 across the 2 of their papers we have counts for

collaborators

5 papers

cs.CR2026

The Software Supply Chain as a Market for Lemons: A Multivocal Review of Trust Signal Collapse

Ranindya Paramitha, Christian Kästner, Laurie Williams

Practitioners evaluating open-source dependencies rely on cheap trust signals, e.g., stars, download counts, and contributor activity, as substitutes for direct code inspection, as…

cs.CR2026

The Rising Cost of Trust: Practitioners' Trust Signals, Controls, and Responses in the Software Supply Chain

Ranindya Paramitha, Siri Paidipalli, Laurie Williams +1

The software supply chain is becoming more complex, and AI is reshaping its threat landscape, e.g., raising concerns about the quality of AI-generated dependencies. Seen through th…

cs.SE2026

CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages

Imranur Rahman, Jill Marley, Ranindya Paramitha +1

Dependency resolution at a specified point in time in the past can provide insight into software evolution in software ecosystems and facilitate the design of dynamic metrics (e.g.…

cs.SE20266 cited

How Quickly Do Development Teams Update Their Vulnerable Dependencies?

Imranur Rahman, Ranindya Paramitha, Nusrat Zahan +2

Industry practitioners are increasingly concerned with software that contains vulnerable versions of third-party dependencies that are included both directly and transitively. To a…

cs.CR2025

Today's Cat Is Tomorrow's Dog: Accounting for Time-Based Changes in the Labels of ML Vulnerability Detection Approaches

Ranindya Paramitha, Yuan Feng, Fabio Massacci

Vulnerability datasets used for ML testing implicitly contain retrospective information. When tested on the field, one can only use the labels available at the time of training and…