3 papers
cs.SE2025
A Deep Dive Into How Open-Source Project Maintainers Review and Resolve Bug Bounty Reports
Jessy Ayala, Steven Ngo, Joshua Garcia
Researchers have investigated the bug bounty ecosystem from the lens of platforms, programs, and bug hunters. Understanding the perspectives of bug bounty report reviewers, especia…
cs.SE2025
A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features
Jessy Ayala, Yu-Jye Tung, Joshua Garcia
In open-source software (OSS), software vulnerabilities have significantly increased. Although researchers have investigated the perspectives of vulnerability reporters and OSS con…
cs.CR2025
Investigating Vulnerability Disclosures in Open-Source Software Using Bug Bounty Reports and Security Advisories
Jessy Ayala, Yu-Jye Tung, Joshua Garcia
In the world of open-source software (OSS), the number of known vulnerabilities has tremendously increased. The GitHub Advisory Database contains advisories for security risks in G…