{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T16:41:07Z","timestamp":1783701667219,"version":"3.55.0"},"reference-count":71,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2024,7,30]],"date-time":"2024-07-30T00:00:00Z","timestamp":1722297600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,7,30]],"date-time":"2024-07-30T00:00:00Z","timestamp":1722297600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2024,9]]},"DOI":"10.1007\/s10664-024-10523-y","type":"journal-article","created":{"date-parts":[[2024,7,30]],"date-time":"2024-07-30T18:03:44Z","timestamp":1722362624000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Dependabot and security pull requests: large empirical study"],"prefix":"10.1007","volume":"29","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-3657-8510","authenticated-orcid":false,"given":"Hocine","family":"Rebatchi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"T\u00e9gawend\u00e9 F.","family":"Bissyand\u00e9","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Naouel","family":"Moha","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,7,30]]},"reference":[{"key":"10523_CR1","doi-asserted-by":"publisher","unstructured":"Akoglu H (2018) User\u2019s guide to correlation coefficients. Turk J Emerg Med 18(3):91\u201393. https:\/\/doi.org\/10.1016\/j.tjem.2018.08.001, https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2452247318302164","DOI":"10.1016\/j.tjem.2018.08.001"},{"key":"10523_CR2","doi-asserted-by":"publisher","unstructured":"Alfadel M, Costa DE, Shihab E, Mkhallalati M (2021) On the use of dependabot security pull requests. In: 2021 IEEE\/ACM 18th International conference on mining software repositories (MSR), pp 254\u2013265. https:\/\/doi.org\/10.1109\/MSR52588.2021.00037","DOI":"10.1109\/MSR52588.2021.00037"},{"key":"10523_CR3","first-page":"301508","volume":"44","author":"A Andreoli","year":"2023","unstructured":"Andreoli A, Lounis A, Debbabi M, Hanna A (2023) On the prevalence of software supply chain attacks: empirical study and investigative framework. Forensic Sci Int: Digital Investigation 44:301508","journal-title":"Forensic Sci Int: Digital Investigation"},{"key":"10523_CR4","doi-asserted-by":"crossref","unstructured":"Angermeir F, Voggenreiter M, Moy\u00f3n F, Mendez D (2021) Enterprise-driven open source software: a case study on security automation. In: 2021 IEEE\/ACM 43rd International conference on software engineering: software engineering in practice (ICSE-SEIP). IEEE, pp 278\u2013287","DOI":"10.1109\/ICSE-SEIP52600.2021.00037"},{"key":"10523_CR5","doi-asserted-by":"crossref","unstructured":"ben Othmane L, Chehrazi G, Bodden E, Tsalovski P, Brucker AD, Miseldine P (2015) Factors impacting the effort required to fix security vulnerabilities. In: Lopez J, Mitchell CJ (eds) Information security. Springer International Publishing, Cham, pp 102\u2013119","DOI":"10.1007\/978-3-319-23318-5_6"},{"issue":"2","key":"10523_CR6","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1007\/s41019-016-0019-8","volume":"2","author":"L Ben Othmane","year":"2017","unstructured":"Ben Othmane L, Chehrazi G, Bodden E, Tsalovski P, Brucker AD (2017) Time for addressing software security issues: prediction models and impacting factors. Data Sci Eng 2(2):107\u2013124","journal-title":"Data Sci Eng"},{"key":"10523_CR7","doi-asserted-by":"publisher","unstructured":"Bird C, Gourley A, Devanbu P, Swaminathan A, Hsu G (2007) Open borders? immigration in open source projects. In: Proceedings of the fourth international workshop on mining software repositories. IEEE Computer Society, USA, MSR \u201907, p\u00a06. https:\/\/doi.org\/10.1109\/MSR.2007.23","DOI":"10.1109\/MSR.2007.23"},{"key":"10523_CR8","unstructured":"Birsan A (2021) Dependency confusion: how I hacked into apple, microsoft and dozens of other companies. https:\/\/medium.com\/@alex.birsan\/dependency-confusion-4a5d60fec610"},{"key":"10523_CR9","unstructured":"Boehm C (2023) Supply chain attacks: how to protect against attack and sabotage. https:\/\/assets.sentinelone.com\/supply-chain-attacks\/how-to-protect-against-attack-and-sabotage-en"},{"key":"10523_CR10","unstructured":"Calkins KG (2005) Correlation coefficients. https:\/\/www.andrews.edu\/~calkins\/math\/edrm611\/edrm05.htm, publisher: Andrews University"},{"key":"10523_CR11","doi-asserted-by":"publisher","first-page":"102067","DOI":"10.1016\/j.cose.2020.102067","volume":"99","author":"G Canfora","year":"2020","unstructured":"Canfora G, Di Sorbo A, Forootani S, Pirozzi A, Visaggio CA (2020) Investigating the vulnerability fixing process in oss projects: peculiarities and challenges. Comput Secur 99:102067","journal-title":"Comput Secur"},{"key":"10523_CR12","doi-asserted-by":"crossref","unstructured":"Coufal\u00edkov\u00e1 A, Klaban I, \u0160lajs T (2021) Complex strategy against supply chain attacks. In: 2021 International conference on military technologies (ICMT). IEEE, pp 1\u20135","DOI":"10.1109\/ICMT52455.2021.9502768"},{"key":"10523_CR13","unstructured":"DeBill E (2019) Module counts. http:\/\/www.modulecounts.com\/"},{"key":"10523_CR14","doi-asserted-by":"crossref","unstructured":"Decan A, Mens T, Constantinou E (2018) On the impact of security vulnerabilities in the npm package dependency network. In: Proceedings of the 15th international conference on mining software repositories, pp 181\u2013191","DOI":"10.1145\/3196398.3196401"},{"key":"10523_CR15","doi-asserted-by":"crossref","unstructured":"Dey T, Mousavi S, Ponce E, Fry T, Vasilescu B, Filippova A, Mockus A (2020) Detecting and characterizing bots that commit code. In: Proceedings of the 17th international conference on mining software repositories, pp 209\u2013219","DOI":"10.1145\/3379597.3387478"},{"key":"10523_CR16","doi-asserted-by":"crossref","unstructured":"Duan R, Alrawi O, Kasturi RP, Elder R, Saltaformaggio B, Lee W (2020) Towards measuring supply chain attacks on package managers for interpreted languages. arXiv:2002.01139","DOI":"10.14722\/ndss.2021.23055"},{"key":"10523_CR17","doi-asserted-by":"crossref","unstructured":"Erlenhov L, de\u00a0Oliveira\u00a0Neto FG, Scandariato R, Leitner P (2019b) Current and future bots in software development. In: 2019 IEEE\/ACM 1st International workshop on bots in software engineering (BotSE). IEEE, pp 7\u201311","DOI":"10.1109\/BotSE.2019.00009"},{"key":"10523_CR18","doi-asserted-by":"publisher","unstructured":"Erlenhov L, Gomes\u00a0de Oliveira\u00a0Neto F, Scandariato R, Leitner P (2019a) Current and future bots in software development. In: 2019 IEEE\/ACM 1st International workshop on bots in software engineering (BotSE), pp 7\u201311. https:\/\/doi.org\/10.1109\/BotSE.2019.00009","DOI":"10.1109\/BotSE.2019.00009"},{"key":"10523_CR19","doi-asserted-by":"publisher","unstructured":"Garrett K, Ferreira G, Jia L, Sunshine J, K\u00e4stner C (2019) Detecting suspicious package updates. In: Proceedings of the 41st International conference on software engineering: new ideas and emerging results. IEEE Press, ICSE-NIER \u201919, p 13\u201316. https:\/\/doi.org\/10.1109\/ICSE-NIER.2019.00012","DOI":"10.1109\/ICSE-NIER.2019.00012"},{"key":"10523_CR20","unstructured":"GitHub (2021) Github rest api. https:\/\/docs.github.com\/en\/rest\/reference\/search"},{"key":"10523_CR21","doi-asserted-by":"publisher","unstructured":"Gousios G, Pinzger M, Deursen Av (2014a) An exploratory study of the pull-based software development model. In: Proceedings of the 36th international conference on software engineering. Association for computing machinery, New York, NY, USA, ICSE 2014, pp 345\u2013355. https:\/\/doi.org\/10.1145\/2568225.2568260","DOI":"10.1145\/2568225.2568260"},{"key":"10523_CR22","doi-asserted-by":"crossref","unstructured":"Gousios G, Pinzger M, Deursen Av (2014b) An exploratory study of the pull-based software development model. In: Proceedings of the 36th international conference on software engineering, pp 345\u2013355","DOI":"10.1145\/2568225.2568260"},{"key":"10523_CR23","doi-asserted-by":"publisher","unstructured":"Gousios G, Zaidman A (2014) A dataset for pull-based development research. In: Proceedings of the 11th working conference on mining software repositories. Association for computing machinery, New York, NY, USA, MSR 2014, pp 368\u2013371. https:\/\/doi.org\/10.1145\/2597073.2597122","DOI":"10.1145\/2597073.2597122"},{"key":"10523_CR24","volume-title":"Survey methodology,","author":"RM Groves","year":"2011","unstructured":"Groves RM, Fowler FJ Jr, Couper MP, Lepkowski JM, Singer E, Tourangeau R (2011) Survey methodology, vol 561. John Wiley & Sons"},{"issue":"1","key":"10523_CR25","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1007\/s10664-022-10238-y","volume":"28","author":"F Hou","year":"2023","unstructured":"Hou F, Jansen S (2023) A systematic literature review on trust in the software ecosystem. Empir Softw Eng 28(1):8","journal-title":"Empir Softw Eng"},{"key":"10523_CR26","doi-asserted-by":"crossref","unstructured":"Imtiaz N, Khanom A, Williams L (2022) Open or sneaky? fast or slow? light or heavy?: Investigating security releases of open source packages. IEEE Trans Softw Eng","DOI":"10.1109\/TSE.2022.3181010"},{"key":"10523_CR27","unstructured":"Jeong G, Kim S, Zimmermann T, Yi K (2009) Improving code review by predicting reviewers and acceptance of patches. Research on software analysis for error-free computing center Tech-Memo (ROSAEC MEMO 2009-006), pp 1\u201318"},{"key":"10523_CR28","unstructured":"Kaczorowski M (2020) Secure at every step: what is software supply chain security and why does it matter? https:\/\/github.blog\/2020-09-02-secure-your-software-supply-chain-and-protect-against-supply-chain-threats-github-blog\/"},{"key":"10523_CR29","doi-asserted-by":"crossref","unstructured":"Kalliamvakou E, Gousios G, Blincoe K, Singer L, German DM, Damian D (2014) The promises and perils of mining github. In: Proceedings of the 11th working conference on mining software repositories, pp 92\u2013101","DOI":"10.1145\/2597073.2597074"},{"key":"10523_CR30","doi-asserted-by":"crossref","unstructured":"Kononenko O, Rose T, Baysal O, Godfrey M, Theisen D, De\u00a0Water B (2018a) Studying pull request merges: a case study of shopify\u2019s active merchant. In: Proceedings of the 40th international conference on software engineering: software engineering in practice, pp 124\u2013133","DOI":"10.1145\/3183519.3183542"},{"key":"10523_CR31","doi-asserted-by":"crossref","unstructured":"Kononenko O, Rose T, Baysal O, Godfrey M, Theisen D, de\u00a0Water B (2018b) Studying pull request merges: a case study of shopify\u2019s active merchant. In: 2018 IEEE\/ACM 40th International conference on software engineering: software engineering in practice track (ICSE-SEIP), pp 124\u2013133","DOI":"10.1145\/3183519.3183542"},{"key":"10523_CR32","doi-asserted-by":"crossref","unstructured":"Ladisa P, Plate H, Martinez M, Barais O (2022) Taxonomy of attacks on open-source software supply chains. arXiv preprint arXiv:2204.04008","DOI":"10.1145\/3560835.3564546"},{"key":"10523_CR33","unstructured":"Lawall J, Muller G (2018) Coccinelle: 10 years of automated evolution in the Linux kernel. In: Proceedings of the 2018 USENIX conference on usenix annual technical conference. USENIX Association, USA, USENIX ATC \u201918, pp 601\u2013613"},{"key":"10523_CR34","doi-asserted-by":"crossref","unstructured":"Lin G, Xiao W, Zhang J, Xiang Y (2019) Deep learning-based vulnerable function detection: a benchmark. In: International conference on information and communications security. Springer, pp 219\u2013232","DOI":"10.1007\/978-3-030-41579-2_13"},{"key":"10523_CR35","doi-asserted-by":"publisher","unstructured":"Lin G, Zhang J, Luo W, Pan L, Xiang Y (2017a) Poster: vulnerability discovery with function representation learning from unlabeled projects. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security. Association for computing machinery, New York, NY, USA, CCS \u201917, pp 2539\u20132541. https:\/\/doi.org\/10.1145\/3133956.3138840","DOI":"10.1145\/3133956.3138840"},{"key":"10523_CR36","doi-asserted-by":"crossref","unstructured":"Lin G, Zhang J, Luo W, Pan L, Xiang Y (2017b) Poster: vulnerability discovery with function representation learning from unlabeled projects. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security, pp 2539\u20132541","DOI":"10.1145\/3133956.3138840"},{"key":"10523_CR37","doi-asserted-by":"crossref","unstructured":"Mirhosseini S, Parnin C (2017) Can automated pull requests encourage software developers to upgrade out-of-date dependencies? In: 2017 32nd IEEE\/ACM international conference on automated software engineering (ASE). IEEE, pp 84\u201394","DOI":"10.1109\/ASE.2017.8115621"},{"key":"10523_CR38","doi-asserted-by":"crossref","unstructured":"Moguel-S\u00e1nchez R, Mart\u00ednez-Palacios CS, Ochar\u00e1n-Hern\u00e1ndez JO, Lim\u00f3n X, S\u00e1nchez-Garc\u00eda \u00c1J (2022) Bots and their uses in software development: a systematic mapping study. In: 2022 10th International conference in software engineering research and innovation (CONISOFT). IEEE, pp 140\u2013149","DOI":"10.1109\/CONISOFT55708.2022.00027"},{"key":"10523_CR39","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2022.111588","volume":"198","author":"S Mujahid","year":"2023","unstructured":"Mujahid S, Abdalkareem R, Shihab E (2023) What are the characteristics of highly-selected packages? a case study on the npm ecosystem. J Syst Softw 198:111588","journal-title":"J Syst Softw"},{"key":"10523_CR40","doi-asserted-by":"publisher","first-page":"3219","DOI":"10.1007\/s10664-017-9512-6","volume":"22","author":"N Munaiah","year":"2017","unstructured":"Munaiah N, Kroh S, Cabrey C, Nagappan M (2017) Curating github for engineered software projects. Empir Softw Eng 22:3219\u20133253","journal-title":"Empir Softw Eng"},{"key":"10523_CR41","unstructured":"NIST (2021) Vulnerability metrics. https:\/\/nvd.nist.gov\/vuln-metrics\/cvss"},{"key":"10523_CR42","doi-asserted-by":"crossref","unstructured":"Ohm M, Kempf L, Boes F, Meier M (2020a) Supporting the detection of software supply chain attacks through unsupervised signature generation. arXiv preprint arXiv:2011.02235","DOI":"10.1145\/3407023.3409183"},{"key":"10523_CR43","doi-asserted-by":"crossref","unstructured":"Ohm M, Kempf L, Boes F, Meier M (2021) Supporting the detection of software supply chain attacks through unsupervised signature generation. arXiv:2011.02235","DOI":"10.1145\/3407023.3409183"},{"key":"10523_CR44","doi-asserted-by":"crossref","unstructured":"Ohm M, Plate H, Sykosch A, Meier M (2020b) Backstabber\u2019s knife collection: a review of open source software supply chain attacks. In: International conference on detection of intrusions and malware, and vulnerability assessment. Springer, pp 23\u201343","DOI":"10.1007\/978-3-030-52683-2_2"},{"key":"10523_CR45","doi-asserted-by":"crossref","unstructured":"Pashchenko I, Vu DL, Massacci F (2020) A qualitative study of dependency management and its security implications. In: Proceedings of the 2020 ACM SIGSAC conference on computer and communications security, pp 1513\u20131531","DOI":"10.1145\/3372297.3417232"},{"key":"10523_CR46","unstructured":"Peterson K (2013) The github open source development process. http:\/\/kevinp.me\/github-process-research\/github-processresearch.pdf (visited on 05\/11\/2017)"},{"key":"10523_CR47","doi-asserted-by":"crossref","unstructured":"Pham R, Singer L, Liskin O, Figueira\u00a0Filho F, Schneider K (2013) Creating a shared understanding of testing culture on a social coding site. In: 2013 35th International conference on software engineering (ICSE). IEEE, pp 112\u2013121","DOI":"10.1109\/ICSE.2013.6606557"},{"key":"10523_CR48","unstructured":"Plumb T (2022) GitHub\u2019s Octoverse report finds 97% of apps use open source software. https:\/\/venturebeat.com\/programming-development\/github-releases-open-source-report-octoverse-2022-says-97-of-apps-use-oss\/"},{"issue":"4","key":"10523_CR49","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10664-021-09959-3","volume":"26","author":"GAA Prana","year":"2021","unstructured":"Prana GAA, Sharma A, Shar LK, Foo D, Santosa AE, Sharma A, Lo D (2021) Out of sight, out of mind? how vulnerable dependencies affect open-source projects. Empir Softw Eng 26(4):1\u201334","journal-title":"Empir Softw Eng"},{"key":"10523_CR50","unstructured":"Preston-Werner T (2021) Semantic versioning 2.0.0. https:\/\/semver.org\/"},{"key":"10523_CR51","doi-asserted-by":"publisher","unstructured":"Rigby PC, Bird C (2013) Convergent contemporary software peer review practices. In: Proceedings of the 2013 9th joint meeting on foundations of software engineering. Association for Computing Machinery, New York, NY, USA, ESEC\/FSE 2013, pp 202\u2013212. https:\/\/doi.org\/10.1145\/2491411.2491444","DOI":"10.1145\/2491411.2491444"},{"key":"10523_CR52","doi-asserted-by":"crossref","unstructured":"Russell R, Kim L, Hamilton L, Lazovich T, Harer J, Ozdemir O, Ellingwood P, McConley M (2018) Automated vulnerability detection in source code using deep representation learning. In: 2018 17th IEEE international conference on machine learning and applications (ICMLA). IEEE, pp 757\u2013762","DOI":"10.1109\/ICMLA.2018.00120"},{"key":"10523_CR53","doi-asserted-by":"publisher","DOI":"10.7717\/peerj-cs.866","volume":"8","author":"S Santhanam","year":"2022","unstructured":"Santhanam S, Hecking T, Schreiber A, Wagner S (2022) Bots in software engineering: a systematic mapping study. PeerJ Computer Science 8:e866","journal-title":"PeerJ Computer Science"},{"key":"10523_CR54","doi-asserted-by":"publisher","unstructured":"Soares DM, de\u00a0Lima\u00a0J\u00fanior ML, Murta L, Plastino A (2015a) Acceptance factors of pull requests in open-source projects. In: Proceedings of the 30th annual ACM symposium on applied computing. Association for Computing Machinery, New York, USA, SAC \u201915, pp 1541\u20131546. https:\/\/doi.org\/10.1145\/2695664.2695856","DOI":"10.1145\/2695664.2695856"},{"key":"10523_CR55","doi-asserted-by":"crossref","unstructured":"Soares DM, de\u00a0Lima\u00a0J\u00fanior ML, Murta L, Plastino A (2015b) Acceptance factors of pull requests in open-source projects. In: Proceedings of the 30th annual ACM symposium on applied computing, pp 1541\u20131546","DOI":"10.1145\/2695664.2695856"},{"key":"10523_CR56","doi-asserted-by":"publisher","unstructured":"Soto-Valero C, Durieux T, Baudry B (2021) A longitudinal analysis of bloated java dependencies. In: Proceedings of the 29th ACM joint meeting on European software engineering conference and symposium on the foundations of software engineering. Association for Computing Machinery, New York, USA, ESEC\/FSE 2021, pp 1021\u20131031. https:\/\/doi.org\/10.1145\/3468264.3468589","DOI":"10.1145\/3468264.3468589"},{"key":"10523_CR57","unstructured":"Szulik K (2018) Dependency management and your software health. https:\/\/blog.tidelift.com\/dependency-management-and-your-software-health"},{"key":"10523_CR58","doi-asserted-by":"publisher","first-page":"1943","DOI":"10.1109\/TIFS.2020.3044773","volume":"16","author":"H Wang","year":"2020","unstructured":"Wang H, Ye G, Tang Z, Tan SH, Huang S, Fang D, Feng Y, Bian L, Wang Z (2020a) Combining graph-based learning with automated data collection for code vulnerability detection. IEEE Trans Inf Forensics Secur 16:1943\u20131958","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"10523_CR59","doi-asserted-by":"crossref","unstructured":"Wang Y, Chen B, Huang K, Shi B, Xu C, Peng X, Wu Y, Liu Y (2020b) An empirical study of usages, updates and risks of third-party libraries in java projects. In: 2020 IEEE International conference on software maintenance and evolution (ICSME). IEEE, pp 35\u201345","DOI":"10.1109\/ICSME46990.2020.00014"},{"key":"10523_CR60","doi-asserted-by":"publisher","unstructured":"Wei\u00dfgerber P, Neu D, Diehl S (2008) Small patches get in! In: Proceedings of the 2008 international working conference on mining software repositories. Association for Computing Machinery, New York, USA, MSR \u201908, pp 67\u201376. https:\/\/doi.org\/10.1145\/1370750.1370767","DOI":"10.1145\/1370750.1370767"},{"issue":"CSCW","key":"10523_CR61","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3274451","volume":"2","author":"M Wessel","year":"2018","unstructured":"Wessel M, De Souza BM, Steinmacher I, Wiese IS, Polato I, Chaves AP, Gerosa MA (2018) The power of bots: characterizing and understanding bots in oss projects. Proc ACM Hum-Comput Interaction 2(CSCW):1\u201319","journal-title":"Proc ACM Hum-Comput Interaction"},{"issue":"CSCW2","key":"10523_CR62","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3476042","volume":"5","author":"M Wessel","year":"2021","unstructured":"Wessel M, Wiese I, Steinmacher I, Gerosa MA (2021) Don\u2019t disturb me: challenges of interacting with software bots on open source software projects. Proc ACM Hum-Comput Interaction 5(CSCW2):1\u201321","journal-title":"Proc ACM Hum-Comput Interaction"},{"key":"10523_CR63","doi-asserted-by":"crossref","unstructured":"Wessel M, Gerosa MA, Shihab E (2022) Software bots in software engineering: benefits and challenges. In: Proceedings of the 19th International conference on mining software repositories, pp 724\u2013725","DOI":"10.1145\/3524842.3528533"},{"key":"10523_CR64","doi-asserted-by":"publisher","unstructured":"Wessel M, Steinmacher I (2020a) The inconvenient side of software bots on pull requests. In: Proceedings of the IEEE\/ACM 42nd international conference on software engineering workshops. Association for Computing Machinery, New York, USA, CSEW\u201920, pp 51\u201355. https:\/\/doi.org\/10.1145\/3387940.3391504","DOI":"10.1145\/3387940.3391504"},{"key":"10523_CR65","doi-asserted-by":"crossref","unstructured":"Wessel M, Steinmacher I (2020b) The inconvenient side of software bots on pull requests. In: Proceedings of the IEEE\/ACM 42nd international conference on software engineering workshops, pp 51\u201355","DOI":"10.1145\/3387940.3391504"},{"key":"10523_CR66","doi-asserted-by":"publisher","unstructured":"Yu Y, Wang H, Filkov V, Devanbu P, Vasilescu B (2015) Wait for it: determinants of pull request evaluation latency on github. In: 2015 IEEE\/ACM 12th Working conference on mining software repositories, pp 367\u2013371. https:\/\/doi.org\/10.1109\/MSR.2015.42","DOI":"10.1109\/MSR.2015.42"},{"key":"10523_CR67","doi-asserted-by":"crossref","unstructured":"Zahan N, Zimmermann T, Godefroid P, Murphy B, Maddila C, Williams L (2022) What are weak links in the npm supply chain? In: 2022 IEEE\/ACM 44th International conference on software engineering: software engineering in practice (ICSE-SEIP). IEEE, pp 331\u2013340","DOI":"10.1109\/ICSE-SEIP55303.2022.9794068"},{"issue":"5","key":"10523_CR68","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10664-022-10154-1","volume":"27","author":"A Zerouali","year":"2022","unstructured":"Zerouali A, Mens T, Decan A, De Roover C (2022) On the impact of security vulnerabilities in the npm and rubygems dependency networks. Empir Softw Eng 27(5):1\u201345","journal-title":"Empir Softw Eng"},{"key":"10523_CR69","doi-asserted-by":"crossref","unstructured":"Zerouali A, Mens T, Decan A, Roover CD (2021) On the impact of security vulnerabilities in the npm and rubygems dependency networks. arXiv:2106.06747","DOI":"10.1007\/s10664-022-10154-1"},{"key":"10523_CR70","unstructured":"Zhou Y, Liu S, Siow J, Du X, Liu Y (2019) Devign: effective vulnerability identification by learning comprehensive program semantics via graph neural networks. Adv Neural Inf Process Syst 32"},{"key":"10523_CR71","doi-asserted-by":"publisher","unstructured":"Zhu J, Zhou M, Mockus A (2016) Effectiveness of code contribution: from patch-based to pull-request-based tools. In: Proceedings of the 2016 24th ACM SIGSOFT international symposium on foundations of software engineering. Association for Computing Machinery, New York, USA, FSE 2016, pp 871\u2013882. https:\/\/doi.org\/10.1145\/2950290.2950364","DOI":"10.1145\/2950290.2950364"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-024-10523-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-024-10523-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-024-10523-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,6]],"date-time":"2024-09-06T03:57:46Z","timestamp":1725595066000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-024-10523-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7,30]]},"references-count":71,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2024,9]]}},"alternative-id":["10523"],"URL":"https:\/\/doi.org\/10.1007\/s10664-024-10523-y","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,7,30]]},"assertion":[{"value":"2 July 2024","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 July 2024","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"All the authors give their consent to submit this work.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent"}},{"value":"Our datasets support our results and comply with the field standards.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Data"}},{"value":"Our manuscript is not submitted to another journal for simultaneous consideration, and our work is original. The authors also declare that this manuscript follows the best scientific standards, in particular, w-r-t to acknowledgment of prior works, honesty of the presentation of results, and focus on the demonstrability of the statements. This manuscript and the work that led to it do not carry any specific ethic issue. As such, it was considered unnecessary to seek formal approval from our institution Ethics Committee specifically for this work.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics Approval"}},{"value":"The authors declare that they have no known competing financial or non-financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing Interests"}}],"article-number":"128"}}