{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,27]],"date-time":"2026-05-27T13:25:16Z","timestamp":1779888316169,"version":"3.53.1"},"reference-count":109,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2023,5,24]],"date-time":"2023-05-24T00:00:00Z","timestamp":1684886400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,5,24]],"date-time":"2023-05-24T00:00:00Z","timestamp":1684886400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001711","name":"Schweizerischer Nationalfonds zur F\u00f6rderung der Wissenschaftlichen Forschung","doi-asserted-by":"publisher","award":["PZ00P2\u02d9186090"],"award-info":[{"award-number":["PZ00P2\u02d9186090"]}],"id":[{"id":"10.13039\/501100001711","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000038","name":"Natural Sciences and Engineering Research Council of Canada","doi-asserted-by":"publisher","award":["RGPIN-2021-04232"],"award-info":[{"award-number":["RGPIN-2021-04232"]}],"id":[{"id":"10.13039\/501100000038","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000038","name":"Natural Sciences and Engineering Research Council of Canada","doi-asserted-by":"publisher","award":["DGECR-2021-00283"],"award-info":[{"award-number":["DGECR-2021-00283"]}],"id":[{"id":"10.13039\/501100000038","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003407","name":"Ministero dell\u2019Istruzione, dell\u2019Universit\u00e0 e della Ricerca","doi-asserted-by":"publisher","award":["2020W3A5FY"],"award-info":[{"award-number":["2020W3A5FY"]}],"id":[{"id":"10.13039\/501100003407","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100007065","name":"Universit\u00e0 degli Studi di Salerno","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100007065","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2023,7]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Software refactoring is a behavior-preserving activity to improve the source code quality without changing its external behavior. Unfortunately, it is often a manual and error-prone task that may induce regressions in the source code. Researchers have provided initial compelling evidence of the relation between refactoring and defects, yet little is known about how much it may impact software security. This paper bridges this knowledge gap by presenting a large-scale empirical investigation into the effects of refactoring on the security profile of applications. We conduct a three-level mining software repository study to establish the impact of 14 refactoring types on (i) security-related metrics, (ii) security technical debt, and (iii) the introduction of known vulnerabilities. The study covers 39 projects and a total amount of 7,708 refactoring commits. The key results show that refactoring has a limited connection to security. However, <jats:italic>Inline Method<\/jats:italic> and <jats:italic>Extract Interface<\/jats:italic> statistically contribute to improving some security aspects connected to encapsulating security-critical code components. <jats:italic>Extract Superclass<\/jats:italic> and <jats:italic>Pull Up Attribute<\/jats:italic> refactoring are commonly found in commits violating specific security best practices for writing secure code. Finally, <jats:italic>Extract Superclass<\/jats:italic> and <jats:italic>Extract &amp; Move Method<\/jats:italic> refactoring tend to occur more often in commits contributing to the introduction of vulnerabilities. We conclude by distilling lessons learned and recommendations for researchers and practitioners.<\/jats:p>","DOI":"10.1007\/s10664-023-10287-x","type":"journal-article","created":{"date-parts":[[2023,5,24]],"date-time":"2023-05-24T06:02:06Z","timestamp":1684908126000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Rubbing salt in the wound? A large-scale investigation into the effects of refactoring on security"],"prefix":"10.1007","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7489-9969","authenticated-orcid":false,"given":"Emanuele","family":"Iannone","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zadia","family":"Codabux","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Valentina","family":"Lenarduzzi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andrea","family":"De Lucia","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fabio","family":"Palomba","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,5,24]]},"reference":[{"key":"10287_CR1","doi-asserted-by":"crossref","unstructured":"Abid C, Kessentini M, Alizadeh V, Dhouadi M, Kazman R (2020) How does refactoring impact security when improving quality? a security-aware refactoring approach. IEEE Transactions on Software Engineering","DOI":"10.1109\/TSE.2020.3005995"},{"key":"10287_CR2","unstructured":"Ad\u00e8r H. J (2008) Advising on research methods: A consultant\u2019s companion. Johannes van Kessel Publishing"},{"key":"10287_CR3","unstructured":"Agrawal A, Khan R (2014) Assessing impact of cohesion on security-an object oriented design perspective. Pensee 76(2)"},{"issue":"1","key":"10287_CR4","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1109\/TSE.2017.2658573","volume":"44","author":"J Al Dallal","year":"2017","unstructured":"Al Dallal J, Abdin A (2017) Empirical evaluation of the impact of object-oriented code refactoring on quality attributes: a systematic literature review. IEEE Trans Softw Eng 44(1):44\u201369","journal-title":"IEEE Trans Softw Eng"},{"issue":"3","key":"10287_CR5","doi-asserted-by":"publisher","first-page":"219","DOI":"10.1016\/j.cose.2006.10.002","volume":"26","author":"O Alhazmi","year":"2007","unstructured":"Alhazmi O, Malaiya Y, Ray I (2007) Measuring, analyzing and predicting security vulnerabilities in software systems. Comput Secur 26(3):219\u2013228","journal-title":"Comput Secur"},{"issue":"9","key":"10287_CR6","doi-asserted-by":"publisher","first-page":"932","DOI":"10.1109\/TSE.2018.2872711","volume":"46","author":"V Alizadeh","year":"2018","unstructured":"Alizadeh V, Kessentini M, Mkaouer MW, Ocinneide M, Ouni A, Cai Y (2018) An interactive and dynamic search-based approach to software refactoring recommendations. IEEE Trans Softw Eng 46(9):932\u2013961","journal-title":"IEEE Trans Softw Eng"},{"key":"10287_CR7","doi-asserted-by":"crossref","unstructured":"Alizadeh V, Ouali MA, Kessentini M, Chater M (2019) RefBot: Intelligent software refactoring bot. In: 2019 34th IEEE\/ACM international conference on automated software engineering (ASE). IEEE, pp 823\u2013834","DOI":"10.1109\/ASE.2019.00081"},{"key":"10287_CR8","doi-asserted-by":"crossref","unstructured":"Alshammari B, Fidge C, Corney D (2009) Security metrics for object-oriented class designs. In: International conference on quality software. IEEE, pp 11\u201320","DOI":"10.1109\/QSIC.2009.11"},{"key":"10287_CR9","doi-asserted-by":"crossref","unstructured":"Alshammari B, Fidge C, Corney D (2010) Assessing the impact of refactoring on security-critical object-oriented designs. In: Asia pacific software engineering conference. IEEE, pp 186\u2013195","DOI":"10.1109\/APSEC.2010.30"},{"key":"10287_CR10","doi-asserted-by":"crossref","unstructured":"Alshammari B, Fidge C, Corney D (2010) Security metrics for object-oriented designs. In: Australian software engineering conference. IEEE, pp 55\u201364","DOI":"10.1109\/ASWEC.2010.34"},{"key":"10287_CR11","unstructured":"Alshammari B, Fidge C, Corney D (2012) Security assessment of code refactoring rules. In: National workshop on information assurance research, VDE, pp 1\u201310"},{"issue":"2","key":"10287_CR12","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1214\/aoms\/1177729437","volume":"23","author":"TW Anderson","year":"1952","unstructured":"Anderson TW, Darling DA (1952) Asymptotic theory of certain \u201cGoodness of Fit\u201d criteria based on stochastic processes. Ann Math Stat 23(2):193\u2013212. https:\/\/doi.org\/10.1214\/aoms\/1177729437","journal-title":"Ann Math Stat"},{"key":"10287_CR13","doi-asserted-by":"crossref","unstructured":"Avgeriou P, Taibi D, Ampatzoglou A, Arcelli Fontana F, Besker T, Chatzigeorgiou A, Lenarduzzi V, Martini A, Moschou N, Pigazzini I, Saarim\u00e4ki N, Sas D, Soares de Toledo S, Tsintzira A (2021) An overview and comparison of technical debt measurement tools. IEEE Software","DOI":"10.1109\/MS.2020.3024958"},{"key":"10287_CR14","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1016\/j.infsof.2018.12.009","volume":"108","author":"MI Azeem","year":"2019","unstructured":"Azeem MI, Palomba F, Shi L, Wang Q (2019) Machine learning techniques for code smell detection: a systematic literature review and meta-analysis. Inf Softw Technol 108:115\u2013138","journal-title":"Inf Softw Technol"},{"key":"10287_CR15","doi-asserted-by":"crossref","unstructured":"Bavota G, De Carluccio B, De Lucia A, Di Penta M, Oliveto R, Strollo O (2012) When does a refactoring induce bugs? an empirical study. In: 12th international working conference on source code analysis and manipulation. IEEE, pp 104\u2013113","DOI":"10.1109\/SCAM.2012.20"},{"key":"10287_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.jss.2015.05.024","volume":"107","author":"G Bavota","year":"2015","unstructured":"Bavota G, De Lucia A, Di Penta M, Oliveto R, Palomba F (2015) An experimental investigation on the innate relationship between quality and refactoring. J Syst Softw 107:1\u201314","journal-title":"J Syst Softw"},{"issue":"6","key":"10287_CR17","doi-asserted-by":"publisher","first-page":"1617","DOI":"10.1007\/s10664-013-9256-x","volume":"19","author":"G Bavota","year":"2014","unstructured":"Bavota G, De Lucia A, Marcus A, Oliveto R (2014) Automating extract class refactoring: an improved method and its evaluation. Empir Softw Eng 19 (6):1617\u20131664","journal-title":"Empir Softw Eng"},{"key":"10287_CR18","doi-asserted-by":"crossref","unstructured":"Beschastnikh I, Lungu MF, Zhuang Y (2017) Accelerating software engineering research adoption with analysis bots. In: 2017 IEEE\/ACM 39th international conference on software engineering: New ideas and emerging technologies results track (ICSE-NIER). IEEE, pp 35\u201338","DOI":"10.1109\/ICSE-NIER.2017.17"},{"key":"10287_CR19","doi-asserted-by":"crossref","unstructured":"Bladel BV, Demeyer S (2018) Test behaviour detection as a test refactoring safety. In: International workshop on refactoring, pp 22\u201325","DOI":"10.1145\/3242163.3242168"},{"issue":"7247","key":"10287_CR20","doi-asserted-by":"publisher","first-page":"1468","DOI":"10.1136\/bmj.320.7247.1468","volume":"320","author":"JM Bland","year":"2000","unstructured":"Bland JM, Altman DG (2000) The odds ratio. BMJ 320(7247):1468","journal-title":"BMJ"},{"key":"10287_CR21","unstructured":"The MITRE Corporation (2023a) Common vulnerabilities and exposures. Accessed 16 February 2023, https:\/\/cve.mitre.org\/"},{"key":"10287_CR22","unstructured":"The MITRE Corporation (2023b) Cve search tool. Accessed 16 February 2023, https:\/\/github.com\/cve-search\/cve-search"},{"key":"10287_CR23","doi-asserted-by":"crossref","unstructured":"Camilo F, Meneely A, Nagappan M (2015) Do bugs foreshadow vulnerabilities? a study of the chromium project. In: 12th working conference on mining software repositories. IEEE, pp 269\u2013279","DOI":"10.1109\/MSR.2015.32"},{"key":"10287_CR24","doi-asserted-by":"publisher","first-page":"102067","DOI":"10.1016\/j.cose.2020.102067","volume":"99","author":"G Canfora","year":"2020","unstructured":"Canfora G, Di Sorbo A, Forootani S, Pirozzi A, Visaggio CA (2020) Investigating the vulnerability fixing process in OSS projects: Peculiarities and challenges. Comp Sec 99:102067","journal-title":"Comp Sec"},{"key":"10287_CR25","doi-asserted-by":"crossref","unstructured":"Cedrim D, Garcia A, Mongiovi M, Gheyi R, Sousa L, de Mello R, Fonseca B, Ribeiro M, Ch\u00e1vez A (2017) Understanding the impact of refactoring on smells: A longitudinal study of 23 software projects. In: Joint meeting on foundations of software engineering, pp 465\u2013475","DOI":"10.1145\/3106237.3106259"},{"issue":"6","key":"10287_CR26","doi-asserted-by":"publisher","first-page":"476","DOI":"10.1109\/32.295895","volume":"20","author":"SR Chidamber","year":"1994","unstructured":"Chidamber SR, Kemerer CF (1994) A metrics suite for object oriented design. IEEE Trans Softw Eng 20(6):476\u2013493","journal-title":"IEEE Trans Softw Eng"},{"issue":"3","key":"10287_CR27","doi-asserted-by":"publisher","first-page":"294","DOI":"10.1016\/j.sysarc.2010.06.003","volume":"57","author":"I Chowdhury","year":"2011","unstructured":"Chowdhury I, Zulkernine M (2011) Using complexity, coupling, and cohesion metrics as early indicators of vulnerabilities. J Syst Archit 57(3):294\u2013313","journal-title":"J Syst Archit"},{"key":"10287_CR28","doi-asserted-by":"crossref","unstructured":"Codabux Z, Williams B (2013) Managing technical debt: An industrial case study. In: International workshop on managing technical debt (MTD). IEEE, pp 8\u201315","DOI":"10.1109\/MTD.2013.6608672"},{"key":"10287_CR29","unstructured":"Codabux Z, Williams BJ, Niu N (2014) A quality assurance approach to technical debt. In: International conference on software engineering research and practice (SERP)"},{"key":"10287_CR30","doi-asserted-by":"publisher","DOI":"10.4324\/9780203771587","volume-title":"Statistical power analysis for the behavioral sciences","author":"J Cohen","year":"2013","unstructured":"Cohen J (2013) Statistical power analysis for the behavioral sciences. Taylor & Francis, New York"},{"key":"10287_CR31","doi-asserted-by":"crossref","unstructured":"Curtis B, Sappidi J, Szynkarski A (2012) Estimating the size, cost, and types of technical debt. In: 2012 3rd international workshop on managing technical debt (MTD). IEEE, pp 49\u201353","DOI":"10.1109\/MTD.2012.6226000"},{"key":"10287_CR32","doi-asserted-by":"crossref","unstructured":"Di Penta M, Bavota G, Zampetti F (2020) On the relationship between refactoring actions and bugs: a differentiated replication. In: Joint meeting on european software engineering conference and symposium on the foundations of software engineering, pp 556\u2013567","DOI":"10.1145\/3368089.3409695"},{"key":"10287_CR33","unstructured":"de Paulo Sobrinho EV, DeLucia A, de Almeida Maia M (2018) A systematic literature review on bad smells\u20145 w\u2019s: which, when, what, who, where. IEEE Transactions on Software Engineering"},{"issue":"7","key":"10287_CR34","doi-asserted-by":"publisher","first-page":"630","DOI":"10.1109\/32.935855","volume":"27","author":"K El Emam","year":"2001","unstructured":"El Emam K, Benlarbi S, Goel N, Rai SN (2001) The confounding effect of class size on the validity of object-oriented metrics. IEEE Trans Softw Eng 27(7):630\u2013650","journal-title":"IEEE Trans Softw Eng"},{"key":"10287_CR35","doi-asserted-by":"crossref","unstructured":"Elazhary O, Storey M-A, Ernst N, Zaidman A (2019) Do as i do, not as i say: Do contribution guidelines match the github contribution process?. In: International conference on software maintenance and evolution (ICSME), pp 286\u2013290","DOI":"10.1109\/ICSME.2019.00043"},{"key":"10287_CR36","doi-asserted-by":"crossref","unstructured":"Erlenhov L, de Oliveira Neto FG, Scandariato R, Leitner P (2019) Current and future bots in software development. In: 2019 IEEE\/ACM 1st international workshop on bots in software engineering (BotSE). IEEE, pp 7\u201311","DOI":"10.1109\/BotSE.2019.00009"},{"key":"10287_CR37","doi-asserted-by":"crossref","unstructured":"Ghafari M, Gadient P, Nierstrasz O (2017) Security smells in android. In: The 17th international working conference on source code analysis and manipulation (SCAM), pp 121\u2013130","DOI":"10.1109\/SCAM.2017.24"},{"key":"10287_CR38","doi-asserted-by":"crossref","unstructured":"Ghaith S, Cinn\u00e9ide M\u00d3 (2012) Improving software security using search-based refactoring. In: International symposium on search based software engineering. Springer, pp 121\u2013135","DOI":"10.1007\/978-3-642-33119-0_10"},{"key":"10287_CR39","doi-asserted-by":"crossref","unstructured":"Goyal PK, Joshi G (2014) QMOOD metric sets to assess quality of java program. In: International conference on issues and challenges in intelligent computing techniques (ICICT). IEEE, pp 520\u2013533","DOI":"10.1109\/ICICICT.2014.6781337"},{"key":"10287_CR40","doi-asserted-by":"crossref","unstructured":"Huang S, Tang H, Zhang M, Tian J (2010) Text clustering on national vulnerability database. In: International conference on computer engineering and applications, vol 2, pp 295\u2013299","DOI":"10.1109\/ICCEA.2010.209"},{"key":"10287_CR41","doi-asserted-by":"crossref","unstructured":"Iannone E, Codabux Z, Lenarduzzi V, De Lucia A, Palomba F (2022) Rubbing salt in the wound? a large-scale investigation into the effects of refactoring on security. [Online]. Accessed 16 February 2023. Available: https:\/\/figshare.com\/articles\/online_resource\/Rubbing_Salt_in_the_Wound_A_Large-Scale_Investigation_into_the_Effects_of_Refactoring_on_Vulnerabilities\/14483787\/1","DOI":"10.1007\/s10664-023-10287-x"},{"key":"10287_CR42","doi-asserted-by":"crossref","unstructured":"Iannone E, Guadagni R, Ferrucci F, De Lucia A, Palomba F (2022) The secret life of software vulnerabilities: a large-scale empirical study. IEEE Trans Softw Eng :1\u20131","DOI":"10.1109\/TSE.2022.3140868"},{"key":"10287_CR43","first-page":"5","volume":"1","author":"C Joshi","year":"2015","unstructured":"Joshi C, Singh UK, Tarey K (2015) A review on taxonomies of attacks and vulnerability in computer and network system. Int J 1:5","journal-title":"Int J"},{"key":"10287_CR44","doi-asserted-by":"crossref","unstructured":"Kim M, Zimmermann T, Nagappan N (2012) A field study of refactoring challenges and benefits. In: 20th international symposium on the foundations of software engineering, pp 1\u201311","DOI":"10.1145\/2393596.2393655"},{"issue":"7","key":"10287_CR45","doi-asserted-by":"publisher","first-page":"633","DOI":"10.1109\/TSE.2014.2318734","volume":"40","author":"M Kim","year":"2014","unstructured":"Kim M, Zimmermann T, Nagappan N (2014) An empirical study of refactoringchallenges and benefits at microsoft. IEEE Trans Softw Eng 40 (7):633\u2013649","journal-title":"IEEE Trans Softw Eng"},{"key":"10287_CR46","doi-asserted-by":"crossref","unstructured":"Koru AG, Liu H (2005) An investigation of the effect of module size on defect prediction using static measures. In: Workshop on Predictor models in software engineering, pp 1\u20135","DOI":"10.1145\/1082983.1083172"},{"key":"10287_CR47","volume-title":"Applied linear statistical models, vol 5","author":"MH Kutner","year":"2005","unstructured":"Kutner MH, Nachtsheim CJ, Neter J, Li W, et al. (2005) Applied linear statistical models, vol 5. McGraw-Hill, Irwin Boston"},{"issue":"3","key":"10287_CR48","doi-asserted-by":"publisher","first-page":"307","DOI":"10.1109\/TSE.2011.29","volume":"37","author":"I Kwan","year":"2011","unstructured":"Kwan I, Schroter A, Damian D (2011) Does socio-technical congruence have an effect on software build success? a study of coordination in a software project. IEEE Trans Softw Eng 37(3):307\u2013324","journal-title":"IEEE Trans Softw Eng"},{"issue":"1","key":"10287_CR49","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1109\/MS.2017.4541027","volume":"35","author":"C Lebeuf","year":"2017","unstructured":"Lebeuf C, Storey M-A, Zagalsky A (2017) Software bots. IEEE Softw 35(1):18\u201323","journal-title":"IEEE Softw"},{"key":"10287_CR50","doi-asserted-by":"crossref","unstructured":"Lenarduzzi V, Saarim\u00e4ki N, Taibi D (2019) The technical debt dataset. In: 15th conference on PREdictive Models and data analycs In Software Engineering, ser. PROMISE \u201919, pp 2\u201311","DOI":"10.1145\/3345629.3345630"},{"key":"10287_CR51","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1214\/aoms\/1177730491","volume":"18","author":"HB Mann","year":"1947","unstructured":"Mann HB, Whitney DR (1947) On a test of whether one of two random variables is stochastically larger than the other. Ann Math Stat 18:50\u201360","journal-title":"Ann Math Stat"},{"key":"10287_CR52","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1016\/j.infsof.2016.11.009","volume":"83","author":"T Mariani","year":"2017","unstructured":"Mariani T, Vergilio SR (2017) A systematic review on search-based refactoring. Inf Softw Technol 83:14\u201334","journal-title":"Inf Softw Technol"},{"key":"10287_CR53","volume-title":"Refactoring: Improving the design of existing code","author":"F Martin","year":"1999","unstructured":"Martin F, Kent B (1999) Refactoring: Improving the design of existing code. Addison-Wesley Longman Publishing Co. Inc., Saddle River"},{"key":"10287_CR54","doi-asserted-by":"crossref","unstructured":"Maruyama K, Omori T (2011) A security-aware refactoring tool for java programs. In: Workshop on Refactoring Tools, pp 22\u201328","DOI":"10.1145\/1984732.1984737"},{"key":"10287_CR55","doi-asserted-by":"publisher","first-page":"308","DOI":"10.1109\/TSE.1976.233837","volume":"4","author":"TJ McCabe","year":"1976","unstructured":"McCabe TJ (1976) A complexity measure. IEEE Trans Softw Eng 4:308\u2013320","journal-title":"IEEE Trans Softw Eng"},{"issue":"2","key":"10287_CR56","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1109\/MSECP.2004.1281254","volume":"2","author":"G McGraw","year":"2004","unstructured":"McGraw G (2004) Software security. IEEE Secur Priv 2(2):80\u201383","journal-title":"IEEE Secur Priv"},{"key":"10287_CR57","doi-asserted-by":"crossref","unstructured":"Meneely A, Srinivasan H, Musa A, Tejeda A, M Mokary, Spates B (2013) When a patch goes bad: Exploring the properties of vulnerability-contributing commits. In: International symposium on empirical software engineering and measurement, pp 65\u201374","DOI":"10.1109\/ESEM.2013.19"},{"issue":"2","key":"10287_CR58","doi-asserted-by":"publisher","first-page":"126","DOI":"10.1109\/TSE.2004.1265817","volume":"30","author":"T Mens","year":"2004","unstructured":"Mens T, Tourw\u00e9 T (2004) A survey of software refactoring. IEEE Trans Softw Eng 30(2):126\u2013139","journal-title":"IEEE Trans Softw Eng"},{"issue":"11","key":"10287_CR59","doi-asserted-by":"publisher","first-page":"e1978","DOI":"10.1002\/smr.1978","volume":"30","author":"F Mercaldo","year":"2018","unstructured":"Mercaldo F, Di Sorbo A, Visaggio CA, Cimitile A, Martinelli F (2018) An exploratory study on the evolution of android malware quality. J Softw Evol Proc 30(11):e1978","journal-title":"J Softw Evol Proc"},{"key":"10287_CR60","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1016\/j.jss.2016.05.019","volume":"120","author":"M Mohan","year":"2016","unstructured":"Mohan M, Greer D, McMullan P (2016) Technical debt reduction using search based automated refactoring. J Syst Softw 120:183\u2013194","journal-title":"J Syst Softw"},{"issue":"3","key":"10287_CR61","doi-asserted-by":"publisher","first-page":"1383","DOI":"10.1007\/s10664-017-9541-1","volume":"23","author":"PJ Morrison","year":"2018","unstructured":"Morrison PJ, Pandita R, Xiao X, Chillarege R, Williams L (2018) Are vulnerabilities discovered and resolved like other defects? Empir Softw Eng 23(3):1383\u20131421","journal-title":"Empir Softw Eng"},{"key":"10287_CR62","doi-asserted-by":"publisher","first-page":"112","DOI":"10.1016\/j.infsof.2017.11.010","volume":"96","author":"H Mumtaz","year":"2018","unstructured":"Mumtaz H, Alshayeb M, Mahmood S, Niazi M (2018) An empirical study to improve software security through the application of code refactoring. Inf Softw Technol 96:112\u2013125","journal-title":"Inf Softw Technol"},{"key":"10287_CR63","doi-asserted-by":"crossref","unstructured":"Murphy-Hill E, Black AP (2008) Breaking the barriers to successful refactoring: observations and tools for extract method. In: International conference on Software engineering, pp 421\u2013430","DOI":"10.1145\/1368088.1368146"},{"key":"10287_CR64","unstructured":"National Institute for Standards (2023) U.S. NIST computer security division. Accessed 16 February 2023, https:\/\/www.nist.gov"},{"key":"10287_CR65","unstructured":"National Institute for Standards (2023) National vulnerability database. Accessed 16 February 2023, https:\/\/nvd.nist.gov\/"},{"key":"10287_CR66","doi-asserted-by":"crossref","unstructured":"Nagappan N, Ball T (2005) Use of relative code churn measures to predict system defect density. In: International conference on Software engineering, pp 284\u2013292","DOI":"10.1145\/1062455.1062514"},{"key":"10287_CR67","doi-asserted-by":"crossref","unstructured":"Nagappan M, Zimmermann T, Bird C (2013) Diversity in software engineering research. In: 2013 9th joint meeting on foundations of software engineering, pp 466\u2013476","DOI":"10.1145\/2491411.2491415"},{"issue":"4","key":"10287_CR68","doi-asserted-by":"publisher","first-page":"502","DOI":"10.1016\/j.jss.2007.06.003","volume":"81","author":"M O\u2019Keeffe","year":"2008","unstructured":"O\u2019Keeffe M, Cinn\u00e9ide MO (2008) Search-based refactoring for software maintenance. J Syst Softw 81(4):502\u2013516","journal-title":"J Syst Softw"},{"key":"10287_CR69","doi-asserted-by":"crossref","unstructured":"Palomba F, Tamburri DA, Arcelli Fontana F, Oliveto R, Zaidman A, Serebrenik A (2018) Beyond technical aspects: How do community smells influence the intensity of code smells? IEEE Trans Softw Eng :1\u20131","DOI":"10.1145\/3183440.3194950"},{"key":"10287_CR70","doi-asserted-by":"crossref","unstructured":"Palomba F, Zaidman A, Oliveto R, De Lucia A (2017) An exploratory study on the relationship between changes and refactoring. In: 25th international conference on program comprehension (ICPC). IEEE, pp 176\u2013185","DOI":"10.1109\/ICPC.2017.38"},{"key":"10287_CR71","doi-asserted-by":"crossref","unstructured":"Pascarella L, Spadini D, Palomba F, Bruntink M, Bacchelli A (2018) Information needs in contemporary code review. In: Proceedings of the ACM on human-computer interaction, vol. 12, no. CSCW, pp. 1\u201327","DOI":"10.1145\/3274404"},{"key":"10287_CR72","volume-title":"Qualitative evaluation and research methods","author":"M Patton","year":"2002","unstructured":"Patton M (2002) Qualitative evaluation and research methods. Sage, Newbury Park"},{"issue":"2","key":"10287_CR73","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1007\/s10664-008-9102-8","volume":"14","author":"R Per","year":"2009","unstructured":"Per R, Martin H (2009) Guidelines for conducting and reporting case study research in software engineering. Empirical Softw Engg 14(2):131\u2013164","journal-title":"Empirical Softw Engg"},{"key":"10287_CR74","doi-asserted-by":"crossref","unstructured":"P\u00e9rez B, Castellanos C, Correal D, Rios N, Freire S, Sp\u00ednola R, Seaman C (2020) What are the practices used by software practitioners on technical debt payment: results from an international family of surveys. In: International conference on technical debt, pp 103\u2013112","DOI":"10.1145\/3387906.3388632"},{"key":"10287_CR75","doi-asserted-by":"publisher","unstructured":"Perl H, Dechand S, Smith M, Arp D, Yamaguchi F, Rieck K, Fahl S, Acar Y (2015) Vccfinder: Finding potential vulnerabilities in open-source projects to assist code audits. In: Proceedings of the 22nd ACM SIGSAC conference on computer and communications security, ser. CCS \u201915. Association for Computing Machinery, New York, pp 426\u2013437. https:\/\/doi.org\/10.1145\/2810103.2813604","DOI":"10.1145\/2810103.2813604"},{"key":"10287_CR76","doi-asserted-by":"crossref","unstructured":"Rahman A, Parnin C, Williams L (2019) The seven sins: Security smells in infrastructure as code scripts. In: International conference on software engineering (ICSE). IEEE, pp 164\u2013175","DOI":"10.1109\/ICSE.2019.00033"},{"key":"10287_CR77","unstructured":"Ralph P, bin Ali N, Baltes S, Bianculli D, Diaz J, Dittrich Y, Ernst N, Felderer M, Feldt R, Filieri A, de Fran\u00e7a BBN, Furia CA, Gay G, Gold N, Graziotin D, He P, Hoda R, Juristo N, Kitchenham B, Lenarduzzi V, Mart\u00ednez J, Melegati J, Mendez D, Menzies T, Molleri J, Pfahl D, Robbes R, Russo D, Saarim\u00e4ki N, Sarro F, Taibi D, Siegmund J, Spinellis D, Staron M, Stol K, Storey M-A, Taibi D, Tamburri D, Torchiano M, Treude C, Turhan B, Wang X, Vegas S (2021) Empirical standards for software engineering research"},{"key":"10287_CR78","doi-asserted-by":"publisher","first-page":"164","DOI":"10.1016\/j.infsof.2018.03.009","volume":"99","author":"G Rodr\u00edguez-P\u00e9rez","year":"2018","unstructured":"Rodr\u00edguez-P\u00e9rez G, Robles G, Gonz\u00e1lez-Barahona J (2018) Reproducibility and credibility in empirical software engineering: a case study based on a systematic literature review of the use of the SZZ algorithm. Inf Softw Technol 99:164\u2013176","journal-title":"Inf Softw Technol"},{"issue":"C","key":"10287_CR79","doi-asserted-by":"publisher","first-page":"164","DOI":"10.1016\/j.infsof.2018.03.009","volume":"99","author":"G Rodr\u00edguez-P\u00e9rez","year":"2018","unstructured":"Rodr\u00edguez-P\u00e9rez G, Robles G, Gonz\u00e1lez-Barahona JM (2018) Reproducibility and credibility in empirical software engineering: A case study based on a systematic literature review of the use of the SZZ algorithm. Inf Softw Technol 99(C):164\u2013176. https:\/\/doi.org\/10.1016\/j.infsof.2018.03.009","journal-title":"Inf Softw Technol"},{"key":"10287_CR80","doi-asserted-by":"crossref","unstructured":"Rosa G, Pascarella L, Scalabrino S, Tufano R, Bavota G, Lanza M, Oliveto R (2021) Evaluating SZZ implementations through a developer-informed oracle. In: International conference on software engineering (ICSE). p. to appear. IEEE","DOI":"10.1109\/ICSE43902.2021.00049"},{"key":"10287_CR81","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1016\/j.jss.2019.06.001","volume":"156","author":"ER Russo","year":"2019","unstructured":"Russo ER, Di Sorbo A, Visaggio CA, Canfora G (2019) Summarizing vulnerabilities\u2019 descriptions to support experts during vulnerability assessment activities. J Syst Softw 156:84\u201399","journal-title":"J Syst Softw"},{"key":"10287_CR82","doi-asserted-by":"crossref","unstructured":"Saarimaki N, Baldassarre MT, Lenarduzzi V, Romano S (2019) On the accuracy of SonarQube technical debt remediation time. In: Euromicro conference on software engineering and advanced applications (SEAA). IEEE, pp 317\u2013324","DOI":"10.1109\/SEAA.2019.00055"},{"key":"10287_CR83","doi-asserted-by":"crossref","unstructured":"Sellitto G, Iannone E, Codabux Z, Lenarduzzi V, De Lucia A, Palomba F, Ferrucci F (2022) Toward understanding the impact of refactoring on program comprehension. In: 2022 IEEE international conference on software analysis, evolution and reengineering (SANER), pp 731\u2013742","DOI":"10.1109\/SANER53432.2022.00090"},{"issue":"6","key":"10287_CR84","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1109\/MS.2015.105","volume":"32","author":"T Sharma","year":"2015","unstructured":"Sharma T, Suryanarayana G, Samarthyam G (2015) Challenges to and solutions for refactoring adoption: an industrial perspective. IEEE Softw 32(6):44\u201351","journal-title":"IEEE Softw"},{"issue":"6","key":"10287_CR85","doi-asserted-by":"publisher","first-page":"772","DOI":"10.1109\/TSE.2010.81","volume":"37","author":"Y Shin","year":"2010","unstructured":"Shin Y, Meneely A, Williams L, Osborne JA (2010) Evaluating complexity, code churn, and developer activity metrics as indicators of software vulnerabilities. IEEE Trans Softw Eng 37(6):772\u2013787","journal-title":"IEEE Trans Softw Eng"},{"key":"10287_CR86","doi-asserted-by":"crossref","unstructured":"Shin Y, Williams L (2008) An empirical model to predict security vulnerabilities using code complexity metrics. In: International symposium on Empirical software engineering and measurement, pp 315\u2013317","DOI":"10.1145\/1414004.1414065"},{"key":"10287_CR87","doi-asserted-by":"crossref","unstructured":"Silva D, Silva J, Santos GJDS, Terra R, Valente MTO (2020) Refdiff 2.0: A multi-language refactoring detection tool. IEEE Transactions on Software Engineering","DOI":"10.1109\/TSE.2020.2968072"},{"key":"10287_CR88","doi-asserted-by":"crossref","unstructured":"Silva D, Tsantalis N, Valente MT (2016) Why we refactor? Confessions of github contributors. In: 24th ACM sigsoft international symposium on foundations of software engineering, pp 858\u2013870","DOI":"10.1145\/2950290.2950305"},{"key":"10287_CR89","doi-asserted-by":"crossref","unstructured":"Sliwerski J, Zimmermann T, Zeller A (2005) When do changes induce fixes?. In: International workshop on mining software repositories, ser. MSR \u201905, pp 1\u20135","DOI":"10.1145\/1083142.1083147"},{"issue":"2","key":"10287_CR90","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1109\/TSE.2012.19","volume":"39","author":"G Soares","year":"2012","unstructured":"Soares G, Gheyi R, Massoni T (2012) Automated behavioral testing of refactoring engines. IEEE Trans Softw Eng 39(2):147\u2013162","journal-title":"IEEE Trans Softw Eng"},{"issue":"4","key":"10287_CR91","doi-asserted-by":"publisher","first-page":"52","DOI":"10.1109\/MS.2010.63","volume":"27","author":"G Soares","year":"2010","unstructured":"Soares G, Gheyi R, Serey D, Massoni T (2010) Making program refactoring safer. IEEE Softw 27(4):52\u201357","journal-title":"IEEE Softw"},{"key":"10287_CR92","doi-asserted-by":"crossref","unstructured":"Spadini D, Aniche M, Bacchelli A (2018) PyDriller: Python framework for mining software repositories. In: Proceedings of the 2018 26th ACM joint meeting on european software engineering conference and symposium on the foundations of software engineering - ESEC\/FSE 2018. ACM Press, New York, pp 908\u2013911. [Online]. Available: http:\/\/dl.acm.org\/citation.cfm?doid=3236024.3264598","DOI":"10.1145\/3236024.3264598"},{"key":"10287_CR93","doi-asserted-by":"crossref","unstructured":"Spearman C (1961) The proof and measurement of association between two things","DOI":"10.1037\/11491-005"},{"key":"10287_CR94","doi-asserted-by":"crossref","unstructured":"Stroggylos K, Spinellis D (2007) Refactoring\u2013does it improve software quality?. In: International workshop on software quality (WoSQ\u201907: ICSE Workshops 2007). IEEE, pp 10\u201310","DOI":"10.1109\/WOSQ.2007.11"},{"key":"10287_CR95","first-page":"2","volume":"1","author":"S Sukamolson","year":"2007","unstructured":"Sukamolson S (2007) Fundamentals of quantitative research. Lang Inst Chulalongkorn Univ 1:2\u20133","journal-title":"Lang Inst Chulalongkorn Univ"},{"key":"10287_CR96","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1016\/j.jss.2017.11.073","volume":"138","author":"R Terra","year":"2018","unstructured":"Terra R, Valente MT, Miranda S, Sales V (2018) JMove: a novel heuristic and tool to detect move method refactoring opportunities. J Syst Softw 138:19\u201336","journal-title":"J Syst Softw"},{"issue":"3","key":"10287_CR97","doi-asserted-by":"publisher","first-page":"251","DOI":"10.2307\/2525642","volume":"10","author":"H Theil","year":"1969","unstructured":"Theil H (1969) A multinomial extension of the linear logit model. Int Econ Rev 10(3):251\u2013259","journal-title":"Int Econ Rev"},{"key":"10287_CR98","doi-asserted-by":"crossref","unstructured":"Tourani P, Adams B, Serebrenik A (2017) Code of conduct in open source projects. In: 2017 IEEE 24th international conference on software analysis, evolution and reengineering (SANER). IEEE, pp 24\u201333","DOI":"10.1109\/SANER.2017.7884606"},{"issue":"3","key":"10287_CR99","doi-asserted-by":"publisher","first-page":"347","DOI":"10.1109\/TSE.2009.1","volume":"35","author":"N Tsantalis","year":"2009","unstructured":"Tsantalis N, Chatzigeorgiou A (2009) Identification of move method refactoring opportunities. IEEE Trans Softw Eng 35(3):347\u2013367","journal-title":"IEEE Trans Softw Eng"},{"key":"10287_CR100","doi-asserted-by":"crossref","unstructured":"Tsantalis N, Mansouri M, Eshkevari LM, Mazinanian D, Dig D (2018) Accurate and efficient refactoring detection in commit history. In: 40th international conferenc on software engineering, ser ICSE \u201918, pp 483\u2013494","DOI":"10.1145\/3180155.3180206"},{"issue":"11","key":"10287_CR101","doi-asserted-by":"publisher","first-page":"1063","DOI":"10.1109\/TSE.2017.2653105","volume":"43","author":"M Tufano","year":"2017","unstructured":"Tufano M, Palomba F, Bavota G, Oliveto R, Di Penta M, De Lucia A, Poshyvanyk D (2017) When and why your code starts to smell bad (and whether the smells go away). IEEE Trans Softw Eng 43(11):1063\u20131088","journal-title":"IEEE Trans Softw Eng"},{"key":"10287_CR102","doi-asserted-by":"crossref","unstructured":"Vassallo C, Palomba F, Gall HC (2018) Continuous refactoring in CI: A preliminary study on the perceived advantages and barriers. In: International conference on software maintenance and evolution (ICSME). IEEE, pp 564\u2013568","DOI":"10.1109\/ICSME.2018.00068"},{"key":"10287_CR103","doi-asserted-by":"crossref","unstructured":"Vassallo C, Panichella S, Palomba F, Proksc S, Gall HC, Zaidman A (2019) How developers engage with static analysis tools in different contexts. Empirical Software Engineering","DOI":"10.1007\/s10664-019-09750-5"},{"key":"10287_CR104","doi-asserted-by":"crossref","unstructured":"Wong WE, Horgan JR, London S, Agrawal H (1997) A study of effective regression testing in practice. In: International symposium on software reliability engineering. IEEE, pp 264\u2013274","DOI":"10.1109\/ISSRE.1997.630875"},{"key":"10287_CR105","doi-asserted-by":"crossref","unstructured":"Yang L, Li X, Yu Y (2017) Vuldigger: A just-in-time and cost-aware tool for digging vulnerability-contributing changes. In: GLOBECOM 2017 - 2017 IEEE global communications conference, pp 1\u20137","DOI":"10.1109\/GLOCOM.2017.8254428"},{"key":"10287_CR106","doi-asserted-by":"crossref","unstructured":"Yoshida N, Saika T, Choi E, Ouni A, Inoue K (2016) Revisiting the relationship between code smells and refactoring. In: International conference on program comprehension (ICPC). IEEE, pp 1\u20134","DOI":"10.1109\/ICPC.2016.7503738"},{"key":"10287_CR107","doi-asserted-by":"crossref","unstructured":"Zabardast E, Gonzalez-Huerta J, \u0160mite D (2020) Refactoring, bug fixing, and new development effect on technical debt: An industrial case study. In: Euromicro conference on software engineering and advanced applications (SEAA). IEEE, pp 376\u2013384","DOI":"10.1109\/SEAA51224.2020.00068"},{"key":"10287_CR108","doi-asserted-by":"crossref","unstructured":"Zhang H (2009) An investigation of the relationships between lines of code and defects. In: International conference on software maintenance. IEEE, pp 274\u2013283","DOI":"10.1109\/ICSM.2009.5306304"},{"key":"10287_CR109","doi-asserted-by":"crossref","unstructured":"Zhang S, Caragea D, Ou X (2011) An empirical study on using the national vulnerability database to predict software vulnerabilities. In: International conference on database and expert systems applications, pp 217\u2013231","DOI":"10.1007\/978-3-642-23088-2_15"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-023-10287-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-023-10287-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-023-10287-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,27]],"date-time":"2023-09-27T09:15:38Z","timestamp":1695806138000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-023-10287-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,24]]},"references-count":109,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,7]]}},"alternative-id":["10287"],"URL":"https:\/\/doi.org\/10.1007\/s10664-023-10287-x","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,5,24]]},"assertion":[{"value":"5 January 2023","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 May 2023","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"<!--Emphasis Type='Bold' removed-->Conflict of Interests"}}],"article-number":"89"}}