2 papers
cs.SE2026
How Humans, Bots, and Agents Communicate About Vulnerabilities in Pull Requests
Pien Rooijendijk, Christoph Treude, Mairieli Wessel
Developers may reference vulnerabilities in pull request discussions through both explicit identifiers, such as CVEs or GHSAs, and implicit security-related language (e.g., "unauth…
cs.SE2026
Who Said CVE? How Vulnerability Identifiers Are Mentioned by Humans, Bots, and Agents in Pull Requests
Pien Rooijendijk, Christoph Treude, Mairieli Wessel
Vulnerability identifiers such as CVE, CWE, and GHSA are standardised references to known software security issues, yet their use in practice is not well understood. This paper com…