Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

Qualitative Analysis of Security-Related Code Reviews in NPM Packages: An Empirical Study

View through CrossRef
Security issues are a major concern in software packages, and their impact can be detrimental if exploited. Prior work has shown that code review is a widely-used practice that project maintainers adopt to improve software quality. However, in-depth analyses on code review concerning security issues are limited. This paper explores the role of code review in finding and mitigating security issues. We investigate 10 active and popular npm packages to understand what types of security issues are raised during code review, and what kind of mitigation strategies are employed by package maintainers to address them. We analyze 171 pull-requests with raised security issues. We find that such issues are discussed at length by package maintainers. Moreover, we find that code review is effective at identifying certain types of issues, e.g., Race Condition and ReDOS, as dealing with such concerns requires in-depth knowledge of the project domain. When analysing how maintainers respond to the raised security issues, we find that most of the issues (55%) are addressed and mitigated. Still, some security concerns ended up not being fixed or are ignored by maintainers. Finally, we offer some implications to support the role of reviewing code in finding and fixing security concerns.
Title: Qualitative Analysis of Security-Related Code Reviews in NPM Packages: An Empirical Study
Description:
Security issues are a major concern in software packages, and their impact can be detrimental if exploited.
Prior work has shown that code review is a widely-used practice that project maintainers adopt to improve software quality.
However, in-depth analyses on code review concerning security issues are limited.
This paper explores the role of code review in finding and mitigating security issues.
We investigate 10 active and popular npm packages to understand what types of security issues are raised during code review, and what kind of mitigation strategies are employed by package maintainers to address them.
We analyze 171 pull-requests with raised security issues.
We find that such issues are discussed at length by package maintainers.
Moreover, we find that code review is effective at identifying certain types of issues, e.
g.
, Race Condition and ReDOS, as dealing with such concerns requires in-depth knowledge of the project domain.
When analysing how maintainers respond to the raised security issues, we find that most of the issues (55%) are addressed and mitigated.
Still, some security concerns ended up not being fixed or are ignored by maintainers.
Finally, we offer some implications to support the role of reviewing code in finding and fixing security concerns.

Related Results

[RETRACTED] Keanu Reeves CBD Gummies v1
[RETRACTED] Keanu Reeves CBD Gummies v1
[RETRACTED]Keanu Reeves CBD Gummies ==❱❱ Huge Discounts:[HURRY UP ] Absolute Keanu Reeves CBD Gummies (Available)Order Online Only!! ❰❰= https://www.facebook.com/Keanu-Reeves-CBD-G...
The New Public Management and Public Management Studies
The New Public Management and Public Management Studies
The New Public Management (NPM) is a major and sustained development in the management of public services that is evident in some major countries. Its rise is often linked to broad...
Abstract 1714: A novel NPM-BAX pathway regulates death evasion and drug sensitivity in human hepatoma cells.
Abstract 1714: A novel NPM-BAX pathway regulates death evasion and drug sensitivity in human hepatoma cells.
Abstract Death evasion is crucial for both carcinogenesis and resistance to anticancer therapies. Recently we identified nucleophosmin (NPM) as a key factor countera...
Prolactin And Non-Puerperal Mastitis: A Cohort Study Using Real-World Data
Prolactin And Non-Puerperal Mastitis: A Cohort Study Using Real-World Data
Abstract Objective Non-puerperal mastitis (NPM) is an umbrella term for non-specific inflammatory mastitis inflammation with unclear etiology. The objective of the current...
Information Security in Artificial Intelligence: A Study of the possible intersection
Information Security in Artificial Intelligence: A Study of the possible intersection
1. IntroductionArtificial Intelligence or A.I attempts to understand intelligent entities, and strives to build ones. And it is obvious that computers with human-level intelligence...
The role of the nuclear protein matrix during development of rabbit gr anulocytes
The role of the nuclear protein matrix during development of rabbit gr anulocytes
A proteinaceous nuclear substructure (nuclear protein matrix or nuclear pore complex-lamina) has been described in a number of cells and may be a universal feature of cell nuclei. ...
The role of the nuclear protein matrix during development of rabbit gr anulocytes
The role of the nuclear protein matrix during development of rabbit gr anulocytes
Abstract A proteinaceous nuclear substructure (nuclear protein matrix or nuclear pore complex-lamina) has been described in a number of cells and may be a universal ...
New public management and quality of service delivery in the agricultural sector
New public management and quality of service delivery in the agricultural sector
The agricultural sector in Uganda has undergone a number of reforms in order to improve service delivery since 1980s. While the country took promising steps to create an effective ...

Back to Top