π Call for Papers
First-ever #FSE #AIware Joint Competition Track
To participate:
Choose a task π» β conquer it βοΈ β submit by Feb 26, 2026 πβ present at #AIware2026 during #FSE in Montreal!
Details: 2026.aiwareconf.org
π Call for Papers
First-ever #FSE #AIware Joint Competition Track
To participate:
Choose a task π» β conquer it βοΈ β submit by Feb 26, 2026 πβ present at #AIware2026 during #FSE in Montreal!
Details: 2026.aiwareconf.org
"Software is no longer seen as an asset, as something to care for, to maybe even take pride in. Itβs a throw-away product. Like a napkin. Just get one quick, wipe your mouth and throw it away. Like a novelty t-shirt."
tante.cc/2026/01/15/s...
And of course amazing food
Some semi recent photos from my visit to Salerno, Napoli and Pompeii for PROFES 2025
Attention software engineering researchers. Submissions for the FSE-AIWare Joint Competition 2026 are open!
'This competition aims to address challenges arising from software ecosystem dependencies by introducing a novel approach: On-Demand Library Generation (ODAI-LIB).'
odai-lib.github.io
"Using a ... dataset of 100 real and 100 fake CVE-IDs, we manually analyzed the credibility ... of [ChatGPT's] outputs. ChatGPT generated plausible security advisories for 96% of given real CVE-IDs and 97% of fake CVE-IDs, demonstrating a limitation in differentiating between real and fake IDs."
Congratulations to intern student Bayu Fedra Abdullah for Student Best Paper award at the 2025 International Conference on Smart Computing, IoT, and Machine Learning (SIML) for our paper "Using LLMs for Security Advisory Investigations: How Far Are We?" ieeexplore.ieee.org/document/110...
The GitHub logo centered among various geometric shapes.
You can't secure what you don't know about. π
GitHub's dependency graph can help. β
Use it to get a project's entire software supply chain, including both direct and indirect dependencies.
Enable this feature and improve your project's security.π
github.blog/security/sup...
"For our initial analysis, we look at a sample of heavily-depended upon NPM packages, and identify that such end-of-chain packages make up a significant portion of these critical dependency chain (over 50%)."
"For a long time, the dominant philosophy [within package networks like NPM] has been to βreuse as much as possible [...]'. In this vision paper, we investigate packages that challenge the typical concepts of reuseβthat is, packages with no dependencies [...]...."
This month I will attend FSE 2025 in Norway to present our vision paper "Rethinking Reuse in Dependency Supply Chains: Initial Analysis of NPM packages at the End of the Chain" at the 2030 SE Workshop. arxiv.org/abs/2503.02804
All @acm.org publications will be 100% Open Access as of January 2026. When we announced this at POPL and CHI this year, conference participants spontaneously erupted in applause. The CS community is excited about ACM's move to OA!
@plago.bsky.social defines software sustainability as follows: βthe preservation of the long term and beneficial use of software, and its appropriate evolution, in a context that continuously changes.β
#ICSE2025
@icseconf.bsky.social
'Analyzing a dataset of 2,763 NPM libraries, we found that 39.49% are self-contained. Of these ... 40.42% previously had dependencies that were later removed. This analysis revealed a significant trend of dependency reduction within the NPM ecosystem.'
PhD student Pongchai Jaisri's paper 'A Preliminary Study on Self-contained Libraries in the NPM Ecosystem', presented at SERA 2024, has now been published as a chapter in Springer's Studies in Computational Intelligence (SCI). doi.org/10.1007/978-...
Uncle Sam abruptly turns off funding for CVE program. Yes, that CVE program
Today I start my new position as Assistant Professor at the Nara Institute of Science and Technology Software Design Lab. π₯³
We found some instances of vulnerabilities being discussed in GitHub issues instead of being disclosed through secure channels. Primarily, these issues were made by users external to the project.
Presented undergrad intern @ NAIST Sushawapak's ERA paper 'On Categorizing Open Source Software Security Vulnerability Reporting Mechanisms on GitHub' at SANER 2025, Montreal, Canada this month. Paper Link: arxiv.org/abs/2502.07395 Slides: brittany-reid.github.io/talks/saner-...