Skip to search boxSkip to navigationSkip to main content

An Empirical Study of Security Issues Posted in Open Source Projects

  • Mansooreh Zahedi
    ,
  • Muhammad Ali Babar
    ,
  • Christoph Treude
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-review

Open access

Publication Information

Output type

Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-review

Original language

English

Pages from-to (Number of pages)

Pages 5504-5513 (10 pages)

Publication milestones

  • Published - 2018

Publication status

Published - 2018

Place of publication

Hawaii, Manoa
978-0-9981331-1-9

Publication IDs

  • Scopus: 85073501038

Host publication title

Hawaii International Conference on System Sciences (HICSS)

Abstract

When developers gain thorough understanding and knowledge of software security, they can produce more secure software. This study aims at empirically identifying and understanding the security issues posted on a random sample of GitHub repositories. We tried to understand the presence of security issues and their key themes and topics. We applied a mixed-methods approach, combining topic modeling techniques and qualitative analysis. Our findings have revealed that a) the rate of security-related issues was rather small (approx. 3% of all issues), b) the majority of the security issues were related to identity management and cryptography topics. We present 7 high-level themes of problems that developers face in implementing security features.

Publication metrics

PlumX

Citations
19