Abstract
Developers are known to keep third-party dependencies of their projects outdated even if some of them are affected by known vulnerabilities. In this study we aim to understand why they do so. For this, we conducted 25 semi-structured interviews with developers of both large and small-medium enterprises located in nine countries. All interviews were transcribed, coded, and analyzed according to applied thematic analysis. The results of the study reveal important aspects of developers' practices that should be considered by security researchers and dependency tool developers to improve the security of the dependency management process.
Author supplied keywords
Cite
CITATION STYLE
Pashchenko, I., Vu, D. L., & Massacci, F. (2020). Preliminary Findings on FOSS Dependencies and Security : A Qualitative Study on Developers’ Attitudes and Experience. In Proceedings - 2020 ACM/IEEE 42nd International Conference on Software Engineering: Companion, ICSE-Companion 2020 (pp. 284–285). Institute of Electrical and Electronics Engineers Inc. https://doi.org/10.1145/3377812.3390903
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.