Publication in conference proceedings Q4
To kill a mocking bug: Open source repo mining of security patches for programming education
Iosif Andrei-Cristian (Iosif, A.); Tiago Espinha Gasiba (Gasiba, T.); Ulrike Lechner (Lechner, U.); Maria Pinto-Albuquerque (Pinto-Albuquerque, M.);
5th International Computer Programming Education Conference (ICPEC 2024)
Year (definitive publication)
2024
Language
English
Country
Germany
More Information
Web of Science®

Times Cited: 0

(Last checked: 2026-08-23 07:21)

View record in Web of Science®

Scopus

Times Cited: 0

(Last checked: 2026-08-12 00:42)

View record in Scopus

Google Scholar

Times Cited: 0

(Last checked: 2026-08-18 12:06)

View record in Google Scholar

This publication is not indexed in Overton

Abstract
The use of third-party components (TPCs) and open-source software (OSS) has become increasingly popular in software development, and this trend has also increased the chance of detecting security vulnerabilities. Understanding practical recurring vulnerabilities that occur in real-world applications (TPCs and OSS) is a very important step to educate not only aspiring software developers, but also seasoned ones. To achieve this goal, we analyze publicly available OSS software on GitHub to identify the most common security vulnerabilities and their frequency of occurrence between 2009 and 2022. Our work looks at programming language and type of vulnerability and also analyses the number of code lines needed to be changed to fix different vulnerabilities. Furthermore, our work contributes to the understanding of real-world and human-made data quality required for training machine learning algorithms by highlighting the importance of homogeneous and complete data. We provide insights for both developers and researchers seeking to improve cybersecurity in software education and mitigate risks associated with OSS and TPCs. Finally, our analysis contributes to software education by shedding light on common sources of poor code quality and the effort required to fix different vulnerabilities.
Acknowledgements
--
Keywords
Cybersecurity,Open-source software,Repository mining,Software quality
  • Mathematics - Natural Sciences
  • Social and Economic Geography - Social Sciences
Funding Records
Funding Reference Funding Entity
UIDB/04466/2020 Fundação para a Ciência e a Tecnologia
UIDP/04466/2020 Fundação para a Ciência e a Tecnologia
Related Projects