2 papers
cs.SE2025
Dealing with SonarQube Cloud: Initial Results from a Mining Software Repository Study
Sabato Nocera, Davide Fucci, Giuseppe Scanniello
Background: Static Code Analysis (SCA) tools are widely adopted to enforce code quality standards. However, little is known about how open-source projects use and customize these t…
cs.SE2025
Augmenting Software Bills of Materials with Software Vulnerability Description: A Preliminary Study on GitHub
Davide Fucci, Massimiliano Di Penta, Simone Romano +1
Software Bills of Material (SBOMs) are becoming a consolidated, often enforced by governmental regulations, way to describe software composition. However, based on recent studies,…