{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T05:18:36Z","timestamp":1755926316927,"version":"3.40.3"},"publisher-location":"Cham","reference-count":29,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030208820"},{"type":"electronic","value":"9783030208837"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-20883-7_2","type":"book-chapter","created":{"date-parts":[[2019,5,23]],"date-time":"2019-05-23T04:58:16Z","timestamp":1558587496000},"page":"12-23","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Open Source Vulnerability Notification"],"prefix":"10.1007","author":[{"given":"Brandon","family":"Carlson","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kevin","family":"Leach","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Darko","family":"Marinov","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Meiyappan","family":"Nagappan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Atul","family":"Prakash","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,5,23]]},"reference":[{"key":"2_CR1","unstructured":"BugCrowd: Bugcrowd. https:\/\/www.bugcrowd.com"},{"key":"2_CR2","first-page":"171","volume":"33","author":"H Cavusoglu","year":"2007","unstructured":"Cavusoglu, H., Cavusoglu, H., Raghunathan, S.: Efficiency of vulnerability disclosure mechanisms to disseminate vulnerability knowledge. IEEE TSE 33, 171\u2013185 (2007)","journal-title":"IEEE TSE"},{"key":"2_CR3","doi-asserted-by":"crossref","unstructured":"Crocker, D.: Mailbox Names for Common Services, Roles and Functions. RFC 2142, Internet Engineering Task Force (1997). http:\/\/www.rfc-editor.org\/rfc\/rfc2142.txt","DOI":"10.17487\/rfc2142"},{"key":"2_CR4","doi-asserted-by":"crossref","unstructured":"Decan, A., Mens, T., Constantinou, E.: On the impact of security vulnerabilities in the npm package dependency network. In: MSR (2018)","DOI":"10.1145\/3196398.3196401"},{"key":"2_CR5","unstructured":"Foudil, E., Shafranovich, Y.: securitytxt.org. https:\/\/securitytxt.org"},{"key":"2_CR6","unstructured":"Foudil, E., Shafranovich, Y.: A method for web security policies. Technical report, Internet Engineering Task Force (2018). https:\/\/datatracker.ietf.org\/doc\/html\/draft-foudil-securitytxt-03"},{"key":"2_CR7","unstructured":"GitHub: About security alerts for vulnerable dependencies. https:\/\/help.github.com\/en\/articles\/about-security-alerts-for-vulnerable-dependencies"},{"key":"2_CR8","unstructured":"GitHub: GitHub and government civic hackers projects. https:\/\/government.github.com\/community\/#civic_hackers"},{"key":"2_CR9","unstructured":"GitHub: GitHub and government open source projects. https:\/\/government.github.com\/community\/"},{"key":"2_CR10","unstructured":"GitHub: GitHub and government research projects. https:\/\/government.github.com\/community\/#research"},{"key":"2_CR11","unstructured":"GitHub: GitHub trending Java open source projects. https:\/\/github.com\/trending\/java"},{"key":"2_CR12","unstructured":"GitHub: Octoverse. https:\/\/octoverse.github.com\/projects#languages"},{"key":"2_CR13","unstructured":"GitHub: Open source survey. https:\/\/opensourcesurvey.org\/2017"},{"key":"2_CR14","unstructured":"HackerOne: HackerOne. https:\/\/hackerone.com"},{"key":"2_CR15","unstructured":"HackerOne: Vulnerability disclosure policy basics: 5 critical components. https:\/\/www.hackerone.com\/blog\/Vulnerability-Disclosure-Policy-Basics-5-Critical-Components"},{"key":"2_CR16","first-page":"384","volume":"23","author":"RG Kula","year":"2018","unstructured":"Kula, R.G., German, D.M., Ouni, A., Ishio, T., Inoue, K.: Do developers update their library dependencies? ESE 23, 384\u2013417 (2018)","journal-title":"ESE"},{"key":"2_CR17","doi-asserted-by":"crossref","unstructured":"Legunsen, O., Hassan, W.U., Xu, X., Ro\u015fu, G., Marinov, D.: How good are the specs? A study of the bug-finding effectiveness of existing Java API specifications. In: ASE (2016)","DOI":"10.1145\/2970276.2970356"},{"key":"2_CR18","doi-asserted-by":"crossref","unstructured":"Liu, C., White, R.W., Dumais, S.: Understanding web browsing behaviors through Weibull analysis of dwell time. In: SIGIR (2010)","DOI":"10.1145\/1835449.1835513"},{"key":"2_CR19","doi-asserted-by":"crossref","unstructured":"Mirhosseini, S., Parnin, C.: Can automated pull requests encourage software developers to upgrade out-of-date dependencies? In: ASE (2017)","DOI":"10.1109\/ASE.2017.8115621"},{"key":"2_CR20","first-page":"3219","volume":"22","author":"N Munaiah","year":"2017","unstructured":"Munaiah, N., Kroh, S., Cabrey, C., Nagappan, M.: Curating GitHub for engineered software projects. ESE 22, 3219\u20133253 (2017)","journal-title":"ESE"},{"key":"2_CR21","unstructured":"Nesbitt, A., Nickolls, B.: Libraries.io open source repository and dependency metadata (2017)"},{"key":"2_CR22","unstructured":"NIST: National vulnerability database (2018). https:\/\/nvd.nist.gov"},{"key":"2_CR23","unstructured":"OWASP Foundation: Top ten security risks. https:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_2017_Project"},{"key":"2_CR24","unstructured":"Podjarny, G.: Open source vulnerabilities tripped Equifax, how can you defend yourself? https:\/\/snyk.io\/blog\/equifax-breach-vulnerable-open-source-libraries"},{"key":"2_CR25","unstructured":"Rapid7: NIST cyber framework updated with coordinated vuln disclosure processes. https:\/\/blog.rapid7.com\/2017\/12\/19\/nist-cyber-framework-revised-to-include-coordinated-vuln-disclosure-processes"},{"key":"2_CR26","unstructured":"Snyk: Snyk. https:\/\/snyk.io"},{"key":"2_CR27","unstructured":"Snyk: The state of open source (2017). https:\/\/snyk.io\/stateofossecurity"},{"key":"2_CR28","unstructured":"Tetelman, A.: bounty-targets-data (2018). https:\/\/github.com\/arkadiyt\/bounty-targets-data"},{"key":"2_CR29","unstructured":"Williams, J., Dabirsiaghi, A.: The unfortunate reality of insecure libraries. https:\/\/www.contrastsecurity.com\/the-unfortunate-reality-of-insecure-libraries"}],"container-title":["IFIP Advances in Information and Communication Technology","Open Source Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-20883-7_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,5,22]],"date-time":"2023-05-22T00:06:11Z","timestamp":1684713971000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-20883-7_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030208820","9783030208837"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-20883-7_2","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1868-422X"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"23 May 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"OSS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP International Conference on Open Source Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Montreal, QC","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Canada","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 May 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 May 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"oss2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/2019.icse-conferences.org\/series\/oss","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}