Preliminary Findings on FOSS Dependencies and Security : A Qualitative Study on Developers' Attitudes and Experience

1Citations
Citations of this article
15Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Developers are known to keep third-party dependencies of their projects outdated even if some of them are affected by known vulnerabilities. In this study we aim to understand why they do so. For this, we conducted 25 semi-structured interviews with developers of both large and small-medium enterprises located in nine countries. All interviews were transcribed, coded, and analyzed according to applied thematic analysis. The results of the study reveal important aspects of developers' practices that should be considered by security researchers and dependency tool developers to improve the security of the dependency management process.

Cite

CITATION STYLE

APA

Pashchenko, I., Vu, D. L., & Massacci, F. (2020). Preliminary Findings on FOSS Dependencies and Security : A Qualitative Study on Developers’ Attitudes and Experience. In Proceedings - 2020 ACM/IEEE 42nd International Conference on Software Engineering: Companion, ICSE-Companion 2020 (pp. 284–285). Institute of Electrical and Electronics Engineers Inc. https://doi.org/10.1145/3377812.3390903

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free