{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T22:29:01Z","timestamp":1784759341846,"version":"3.55.0"},"reference-count":95,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2025,1,20]],"date-time":"2025-01-20T00:00:00Z","timestamp":1737331200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,1,20]],"date-time":"2025-01-20T00:00:00Z","timestamp":1737331200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2247141"],"award-info":[{"award-number":["2247141"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2312321"],"award-info":[{"award-number":["2312321"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2310179"],"award-info":[{"award-number":["2310179"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100009226","name":"National Security Agency","doi-asserted-by":"publisher","award":["H98230-21-1-0175"],"award-info":[{"award-number":["H98230-21-1-0175"]}],"id":[{"id":"10.13039\/100009226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2025,3]]},"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:sec>\n            <jats:title>Context<\/jats:title>\n            <jats:p>Practitioners prefer to achieve performance without sacrificing productivity when developing scientific software. The Julia programming language is designed to develop performant computer programs without sacrificing productivity by providing a syntax that is scripting in nature. According to the Julia programming language website, the common projects are data science, machine learning, scientific domains, and parallel computing. While Julia has yielded benefits with respect to productivity, programs written in Julia can include security weaknesses, which can hamper the security of Julia-based scientific software. A systematic derivation of security weaknesses can facilitate secure development of Julia programs\u2014an area that remains under-explored.<\/jats:p>\n          <\/jats:sec>\n          <jats:sec>\n            <jats:title>Objective<\/jats:title>\n            <jats:p>The goal of this paper is to help practitioners securely develop Julia programs by conducting an empirical study of security weaknesses found in Julia programs.<\/jats:p>\n          <\/jats:sec>\n          <jats:sec>\n            <jats:title>Method<\/jats:title>\n            <jats:p>We apply qualitative analysis on 4,592 Julia programs used in 126 open-source Julia projects to identify security weakness categories. Next, we construct a static analysis tool called <jats:underline>J<\/jats:underline>ulia <jats:underline>S<\/jats:underline>tatic <jats:underline>A<\/jats:underline>nalysis <jats:underline>T<\/jats:underline>ool (JSAT) that automatically identifies security weaknesses in Julia programs. We apply JSAT to automatically identify security weaknesses in 558 open-source Julia projects consisting of 25,008 Julia programs.<\/jats:p>\n          <\/jats:sec>\n          <jats:sec>\n            <jats:title>Results<\/jats:title>\n            <jats:p>We identify 7 security weakness categories, which include the usage of hard-coded password and unsafe invocation. From our empirical study we identify 23,839 security weaknesses. On average, we observe 24.9% Julia source code files to include at least one of the 7 security weakness categories.<\/jats:p>\n          <\/jats:sec>\n          <jats:sec>\n            <jats:title>Conclusion<\/jats:title>\n            <jats:p>Based on our research findings, we recommend rigorous inspection efforts during code reviews. We also recommend further development and application of security static analysis tools so that security weaknesses in Julia programs can be detected before execution.<\/jats:p>\n          <\/jats:sec>","DOI":"10.1007\/s10664-024-10606-w","type":"journal-article","created":{"date-parts":[[2025,1,20]],"date-time":"2025-01-20T11:22:59Z","timestamp":1737372179000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Come for syntax, stay for speed, write secure code: an empirical study of security weaknesses in Julia programs"],"prefix":"10.1007","volume":"30","author":[{"given":"Yue","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Justin","family":"Murphy","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Akond","family":"Rahman","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,1,20]]},"reference":[{"issue":"8","key":"10606_CR1","first-page":"9","volume":"7","author":"AV Aho","year":"1986","unstructured":"Aho AV, Sethi R, Ullman JD (1986) Compilers, principles, techniques. Addison Wesley 7(8):9","journal-title":"Addison Wesley"},{"key":"10606_CR2","doi-asserted-by":"crossref","unstructured":"Alnaeli SM, Sarnowski M, Aman MS, Yelamarthi K, Abdelgawad A, Jiang H (2023) On the evolution of mobile computing software systems and c\/c++ vulnerable code: Empirical investigation. In: 2016 IEEE 7th Annual Ubiqui- tous Computing, Electronics & Mobile Communication Conference (UEMCON). IEEE, pp 1\u20137","DOI":"10.1109\/UEMCON.2016.7777883"},{"key":"10606_CR3","unstructured":"aviatesk (2023) aviatesk\/jet.jl, 2023. https:\/\/juliapackages.com\/p\/jet. Accessed\u00a0 5 Aug 2024"},{"key":"10606_CR4","unstructured":"Axillus V (2020) Comparing Julia and Python: An investigation of the perfor- mance on image processing with deep neural networks and classification, 2020. https:\/\/www.diva-portal.org\/smash\/record.jsf?pid=diva2%3A1389123&dswid=5389.\u00a0Accessed 5 Aug 2024"},{"key":"10606_CR5","doi-asserted-by":"publisher","unstructured":"Baker E (2020) Guideline for Using Cryptographic Standards in the Federal Government: Cryptographic Mechanisms. 03. https:\/\/doi.org\/10.6028\/NIST.SP.800-175Br1","DOI":"10.6028\/NIST.SP.800-175Br1"},{"issue":"1","key":"10606_CR6","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1137\/141000671","volume":"59","author":"J Bezanson","year":"2017","unstructured":"Bezanson J, Edelman A, Karpinski S, Shah VB (2017) Julia: A fresh approach to numerical computing. SIAM Rev 59(1):65\u201398. https:\/\/doi.org\/10.1137\/141000671","journal-title":"SIAM Rev"},{"key":"10606_CR7","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3276490","volume":"2","author":"J Bezanson","year":"2018","unstructured":"Bezanson J, Chen J, Chung B, Karpinski S, Shah VB, Vitek J, Zoubritzky L (2018) Julia: Dynamism and performance reconciled by design. Proc ACM Program Lang 2:1\u201323. https:\/\/doi.org\/10.1145\/3276490","journal-title":"Proc ACM Program Lang"},{"key":"10606_CR8","doi-asserted-by":"publisher","unstructured":"Bezanson J, Chen J, Chung B, Karpinski S, Shah VB, Vitek J, Zoubritzky L (2018) Julia: Dynamism and performance reconciled by design. Proc. ACM Program. Lang., 2(OOPSLA). https:\/\/doi.org\/10.1145\/3276490","DOI":"10.1145\/3276490"},{"key":"10606_CR9","doi-asserted-by":"publisher","unstructured":"Bhuiyan FA, Prowell S, Shahriar H, Wu F, Rahman A (2022) Shifting left for machine learning: An empirical study of security weaknesses in supervised learning-based projects. In: 2022 IEEE 46th Annual Computers, Software, and Applications Conference (COMPSAC), pp 798\u2013808. https:\/\/doi.org\/10.1109\/COMPSAC54236.2022.00130","DOI":"10.1109\/COMPSAC54236.2022.00130"},{"key":"10606_CR10","unstructured":"Boxler D, Walcott KR (2018) Static taint analysis tools to detect information flows. In: Proceedings of the international conference on software engineering research and practice (SERP). The Steering Committee of The World Congress in Computer Science, Computer Engineering and Applied Computing (WorldComp), pp 46\u201352"},{"issue":"9","key":"10606_CR11","doi-asserted-by":"publisher","first-page":"3280","DOI":"10.1109\/TSE.2021.3087402","volume":"48","author":"S Chakraborty","year":"2022","unstructured":"Chakraborty S, Krishna R, Ding Y, Ray B (2022) Deep learning based vulnera- bility detection: Are we there yet? IEEE Trans Software Eng 48(9):3280\u20133296. https:\/\/doi.org\/10.1109\/TSE.2021.3087402","journal-title":"IEEE Trans Software Eng"},{"key":"10606_CR12","unstructured":"Churavy VVR (2019) Transparent distributed programming in Julia. PhD thesis, Massachusetts Institute of Technology, 2019. https:\/\/dspace.mit.edu\/handle\/1721.1\/122755.\u00a0Accessed 5 Aug 2024"},{"issue":"1","key":"10606_CR13","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1177\/001316446002000104","volume":"20","author":"J Cohen","year":"1960","unstructured":"Cohen J (1960) A coefficient of agreement for nominal scales. Educ Psy- Chological Meas 20(1):37\u201346. https:\/\/doi.org\/10.1177\/001316446002000104","journal-title":"Educ Psy- Chological Meas"},{"key":"10606_CR14","unstructured":"Computing J (2021) Julia computing celebrates 10 years with retrospective, 2022. URL https:\/\/www.hpcwire.com\/off-the-wire\/julia-computing-celebrates-10-years-with-retrospective\/.cvedetails. Vulnerability details : Cve-2021\u20134048. https:\/\/www.cvedetails.com\/ cve\/CVE-2021\u20134048\/. [Online; accessed 19-June-2024]"},{"key":"10606_CR15","unstructured":"cvedetails (2021) Vulnerability details : Cve-2021-4048. https:\/\/www.cvedetails.com\/cve\/CVE-2021-4048\/. Accessed 19 June 2024"},{"key":"10606_CR16","doi-asserted-by":"crossref","unstructured":"Dogaru I, Dogaru R (2015) Using Python and Julia for efficient implementation of natural computing and complexity related algorithms. In: 2015 20th International Conference on Control Systems and Computer Science. IEEE, pp 599\u2013 604. https:\/\/ieeexplore.ieee.org\/abstract\/document\/7168488.\u00a0Accessed 5 Aug 2024","DOI":"10.1109\/CSCS.2015.37"},{"key":"10606_CR17","doi-asserted-by":"crossref","unstructured":"Farhana E, Imtiaz N, Rahman A (2019) Synthesizing program execution time discrepancies in julia used for scientific software. In: 2019 IEEE International Conference on Software Maintenance and Evolution (ICSME). pp 496\u2013500","DOI":"10.1109\/ICSME.2019.00083"},{"key":"10606_CR18","doi-asserted-by":"crossref","unstructured":"Fu M, Tantithamthavorn C (2022) Linevul: A transformer-based line-level vulnerability prediction. In: Proceedings of the 19th International Conference on Mining Software Repositories. pp 608\u2013620","DOI":"10.1145\/3524842.3528452"},{"issue":"1","key":"10606_CR19","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1109\/TSE.2017.2755013","volume":"45","author":"L Gazzola","year":"2019","unstructured":"Gazzola L, Micucci D, Mariani L (2019) Automatic software repair: A survey. IEEE Trans Software Eng 45(1):34\u201367. https:\/\/doi.org\/10.1109\/TSE.2017.2755013","journal-title":"IEEE Trans Software Eng"},{"key":"10606_CR20","unstructured":"Gibson J (2017) The julia programming language: the future of scientific computing. APS, pp L39\u2013011.\u00a0 https:\/\/ui.adsabs.harvard.edu\/abs\/2017APS..DFDL39011G\/abstract.\u00a0Accessed 5 Aug 2024"},{"key":"10606_CR21","doi-asserted-by":"crossref","unstructured":"Gmys J, Carneiro T, Melab N, Talbi E-G, Tuyttens D (2020) A comparative study of high-productivity high-performance programming languages for parallel metaheuristics. Swarm and Evolutionary Computation, p 100720. https:\/\/www.sciencedirect.com\/science\/article\/abs\/pii\/S22106.\u00a0Accessed 5 Aug 2024","DOI":"10.1016\/j.swevo.2020.100720"},{"key":"10606_CR22","doi-asserted-by":"publisher","unstructured":"Heroux MA, Willenbring JM, Phenow MN (2007) Improving the develop- ment process for cse software. In: 15th EUROMICRO International Conference on Parallel, Distributed and Network-Based Processing (PDP\u201907). pp 11\u201317. https:\/\/doi.org\/10.1109\/PDP.2007.51","DOI":"10.1109\/PDP.2007.51"},{"key":"10606_CR23","doi-asserted-by":"publisher","unstructured":"Heymann E, Miller BP, Adams A, Avila K, Krenz M, Lee JR, Peisert S (2023) Guide to securing scientific software. https:\/\/doi.org\/10.5281\/zenodo.8137009. This document is a product of Trusted CI. Trusted CI is supported by the National Science Foundation under Grant #1920430. Any opinions, findings, and conclusions or recommendations expressed in this material are those of the authors and do not necessarily reflect the views of the National Science Foundation","DOI":"10.5281\/zenodo.8137009"},{"issue":"1","key":"10606_CR24","doi-asserted-by":"publisher","first-page":"81","DOI":"10.7748\/nr.4.1.81.s9","volume":"4","author":"G Hickey","year":"1996","unstructured":"Hickey G, Kipping C (1996) A multi-stage approach to the coding of data from open-ended questions. Nurse Res 4(1):81\u201391","journal-title":"Nurse Res"},{"key":"10606_CR25","doi-asserted-by":"crossref","unstructured":"Hin D, Kan A, Chen H, Babar MA (2022) Linevd: Statement-level vulnerability detection using graph neural networks. In: Proceedings of the 19th international conference on mining software repositories. pp 596\u2013607","DOI":"10.1145\/3524842.3527949"},{"key":"10606_CR26","doi-asserted-by":"publisher","unstructured":"Humbatova N, Jahangirova G, Bavota G, Riccio V, Stocco A, Tonella P (2020) Taxonomy of real faults in deep learning systems. In: 2020 IEEE\/ACM 42nd International Conference on Software Engineering (ICSE) pp 1110\u20131121. https:\/\/doi.org\/10.1145\/3377811.3380395","DOI":"10.1145\/3377811.3380395"},{"key":"10606_CR27","unstructured":"Innes M, Edelman A, Fischer K, Rackauckas C, Saba E, Shah VB, Tebbutt W (2019) A differentiable programming system to bridge machine learning and scientific computing. CoRR abs\/1907.07587. https:\/\/deepai.org\/publication\/a-differentiable-programming-system-to-bridge-machine-learning-and-scientific-computing.\u00a0Accessed 5 Aug 2024"},{"key":"10606_CR28","unstructured":"Januszek T, Pleszczy\u0144ski M (2018) Comparative analysis of the efficiency of Julia language against the other classic programming languages. Silesian J Pure Appl Math 8. https:\/\/yadda.icm.edu.pl\/baztech\/element\/bwmeta1.element.baztech-c4339453-4519-4b92-a673-307638a50cb1.\u00a0Accessed 19 Sep 2024"},{"key":"10606_CR29","unstructured":"JLHUB (2024) Julia manual - function list and reference. https:\/\/www.jlhub.com\/julia\/manual\/en\/. [Online; accessed 19-July-2024]"},{"key":"10606_CR30","unstructured":"Julia joins petaflop club (2017) https:\/\/www.hpcwire.com\/off-the-wire\/julia-joins-petaflop-club\/. Accessed 14 Oct 2024"},{"key":"10606_CR31","unstructured":"Julia (2021a) Discourse. https:\/\/discourse.julialang.org\/.\u00a0Accessed 14 Oct 2024"},{"key":"10606_CR32","unstructured":"Julia (2021b) The Julia programming language. https:\/\/docs.julialang.org\/en\/v1\/base\/c\/#Base.unsafe_convert.\u00a0Accessed 14 Oct 2024"},{"key":"10606_CR33","unstructured":"Julia (2021c) https:\/\/docs.julialang.org\/en\/v1\/base\/c\/#Base.unsafe_convert.\u00a0Accessed 14 Oct 2024"},{"key":"10606_CR34","unstructured":"Julia (2024) Julia Documentation. https:\/\/web.mit.edu\/julia_v0.6.2\/julia\/share\/doc\/julia\/html\/en\/index.html.\u00a0Accessed 14 Oct 2024"},{"key":"10606_CR35","unstructured":"Julia (2017) Parallel supercomputing for astronomy. https:\/\/juliacomputing.com\/case-studies\/celeste.html.\u00a0Accessed 14 Oct 2024"},{"key":"10606_CR36","unstructured":"Julia (2020) Programming languages: Developers reveal what they love and loathe, and what pays best. https:\/\/www.zdnet.com\/article\/programming-languages-developers-reveal-what-they-love-and-loathe-and-what-pays-best\/.\u00a0Accessed 14 Oct 2024"},{"key":"10606_CR37","unstructured":"Julia (2019) Julia: come for the syntax, stay for the speed. https:\/\/www.nature.com\/articles\/d41586-019-02310-3. Accessed 14 Oct 2024"},{"key":"10606_CR38","unstructured":"julia-vscode (2023) julia-vscode\/staticlint.jl. https:\/\/github.com\/julia-vscode\/StaticLint.jl\/tree\/master.\u00a0Accessed 14 Oct 2024"},{"key":"10606_CR39","doi-asserted-by":"publisher","unstructured":"Kelly D, Smith S, Meng N (2011) Software engineering for scientists. Comput Sci Eng 13(05):7\u201311.\u00a0https:\/\/doi.org\/10.1109\/MCSE.2011.86","DOI":"10.1109\/MCSE.2011.86"},{"key":"10606_CR40","unstructured":"Kelly D, Sanders R, et al (2008) Assessing the quality of scientific software. In First International Workshop on Software Engineering for Computational Science and Engineering. Citeseer"},{"key":"10606_CR41","doi-asserted-by":"crossref","unstructured":"Landis JR, Koch GG (1977) The measurement of observer agreement for cate- gorical data. Biometrics 33(1):159\u2013174. ISSN 0006341X, 15410420.\u00a0 http:\/\/www.jstor.org\/stable\/2529310.\u00a0 Accessed 1 Dec 2024","DOI":"10.2307\/2529310"},{"issue":"4","key":"10606_CR42","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1109\/MCSE.2022.3221877","volume":"24","author":"R Milewicz","year":"2022","unstructured":"Milewicz R, Carver J, Grayson S, Atkison T (2022) A secure future for open-source computational science and engineering. Computing in Science and Engineering 24(4):65\u201369. https:\/\/doi.org\/10.1109\/MCSE.2022.3221877","journal-title":"Computing in Science and Engineering"},{"key":"10606_CR43","unstructured":"MITRE (2021a) Cwe-311: Missing encryption of sensitive data. https:\/\/cwe.mitre.org\/data\/definitions\/311.html.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR44","unstructured":"MITRE (2021b) Cwe-319: Cleartext transmission of sensitive information. https:\/\/cwe.mitre.org\/data\/definitions\/319.html.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR45","unstructured":"MITRE (2021c) Cwe-321: Use of hard-coded cryptographic key. https:\/\/cwe.mitre.org\/data\/definitions\/321.html. Accessed 5 Nov 2024"},{"key":"10606_CR46","unstructured":"MITRE (2021d) Cwe-327: Use of a broken or risky cryptographic algorithm. https:\/\/cwe.mitre.org\/data\/definitions\/327.html.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR47","unstructured":"MITRE (2021e) Cwe-396: Declaration of catch for generic exception. https:\/\/cwe.mitre.org\/data\/definitions\/396.html.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR48","unstructured":"MITRE (2021f) Cwe-546: Suspicious comment. https:\/\/cwe.mitre.org\/data\/definitions\/546.html.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR49","unstructured":"MITRE (2021g) Cwe-78: Improper neutralization of special elements used in an os com- mand (\u2019os command injection\u2019). https:\/\/cwe.mitre.org\/data\/definitions\/78.html.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR50","unstructured":"MITRE (2021h) Cwe-798: Use of hard-coded credentials. https:\/\/cwe.mitre.org\/data\/definitions\/798.html.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR51","unstructured":"MITRE (2021i) Cwe-94: Improper control of generation of code (\u2019code injection\u2019). https:\/\/cwe.mitre.org\/data\/definitions\/94.html.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR52","unstructured":"MITRE (2021j) Common weakness enumeration. https:\/\/cwe.mitre.org\/.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR53","unstructured":"MITRE (2023) Cwe-754: Improper check for unusual or exceptional conditions. https:\/\/cwe.mitre.org\/data\/definitions\/754.html.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR54","unstructured":"Mohammad Mehedi H, Rahman A (2022) As code testing: Characterizing test quality in open source ansible development. In: 2022 15th IEEE Conference on Software Testing, Verification and Validation (ICST), Los Alamitos, CA, USA, apr 2022. IEEE Computer Society. https:\/\/akondrahman.github.io\/publication\/icst2022.\u00a0Accessed 5 Oct 2024"},{"key":"10606_CR55","unstructured":"Morris C (2008) Some lessons learned reviewing scientific code. In: Proc 30th Intl Conference Software Eng (iCSE08)"},{"key":"10606_CR56","doi-asserted-by":"publisher","unstructured":"Munaiah N, Kroh S, Cabrey C, Nagappan M (2017) Curating GitHub for engineered software projects. Empir Softw Eng 1\u201335. ISSN 1573\u20137616. https:\/\/doi.org\/10.1007\/s10664-017-9512-6","DOI":"10.1007\/s10664-017-9512-6"},{"key":"10606_CR57","doi-asserted-by":"publisher","unstructured":"Murphy J, Brady ET, Shamim SI, Rahman A (2020) A curated dataset of security defects in scientific software projects. In: Proceedings of the 7th Symposium on Hot Topics in the Science of Security, HotSoS \u201920, New York, NY, USA, 2020. Association for Computing Machinery. ISBN 9781450375610. https:\/\/doi.org\/10.1145\/3384217.3384218","DOI":"10.1145\/3384217.3384218"},{"key":"10606_CR58","unstructured":"NIST (2021) Special publication 800\u201363c conformance criteria. https:\/\/www.nist.gov\/system\/files\/documents\/2021\/04\/27\/800-63C%20Conformance%20Criteria_042621.pdf.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR59","unstructured":"NIST (2021) Source code security analyzers. https:\/\/www.nist.gov\/itl\/ssd\/software-quality-group\/source-code-security-analyzers.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR60","doi-asserted-by":"crossref","unstructured":"Opdebeeck R et al (2022) Smelly variables in ansible infrastructure code: detection, prevalence, and lifetime. In: Proceedings of the 19th international conference on mining software repositories,\u00a0pp 61\u201372","DOI":"10.1145\/3524842.3527964"},{"key":"10606_CR61","unstructured":"OpenAI (2022) ChatGPT: Optimizing Language Models for Dialogue. https:\/\/openai.com\/blog\/chatgpt\/. [Online; accessed 12-July-2023]"},{"key":"10606_CR62","unstructured":"OWASP (2021a) Command injection. https:\/\/owasp.org\/www-community\/attacks\/Command_Injection.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR63","unstructured":"OWASP (2021b) Testing for weak encryption. https:\/\/owasp.org\/www-project-web-security-testing-guide\/latest\/4-Web_Application_Security_Testing\/09-Testing_for_Weak_Cryptography\/04-Testing_for_Weak_Encryption.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR64","unstructured":"OWASP (2021c) Source code analysis tools. https:\/\/owasp.org\/www-community\/Source_Code_Analysis_Tools.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR65","doi-asserted-by":"crossref","unstructured":"Perkel JM (2019) Julia: come for the syntax, stay for the speed","DOI":"10.1038\/d41586-019-02310-3"},{"issue":"3","key":"10606_CR66","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1109\/MSEC.2021.3065190","volume":"19","author":"A Rahman","year":"2021","unstructured":"Rahman A, Williams L (2021) Different kind of smells: Security smells in in- frastructure as code scripts. IEEE Secur Priv 19(3):33\u201341. https:\/\/doi.org\/10.1109\/MSEC.2021.3065190","journal-title":"IEEE Secur Priv"},{"key":"10606_CR67","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3408897","volume":"30","author":"A Rahman","year":"2021","unstructured":"Rahman A, Rahman R, Parnin C, Williams L (2021) Security smells in ansible and chef scripts: A replication study. ACM Trans Softw Eng Methodol 30:1\u201331. https:\/\/doi.org\/10.1145\/3408897","journal-title":"ACM Trans Softw Eng Methodol"},{"issue":"93","key":"10606_CR68","first-page":"33","volume":"28","author":"A Rahman","year":"2023","unstructured":"Rahman A, Bose DB, Shakya R, Pandita R (2023a) Come for syntax, stay for speed, understand defects: An empirical study of defects in julia programs. Empir Softw Eng 28(93):33","journal-title":"Empir Softw Eng"},{"key":"10606_CR69","doi-asserted-by":"publisher","unstructured":"Rahman A, Farhana E, Imtiaz N (2019) Snakes in paradise?: Insecure python-related coding practices in stack overflow. In: 2019 IEEE\/ACM 16th Inter- national Conference on Mining Software Repositories (MSR). pp 200\u2013204. https:\/\/doi.org\/10.1109\/MSR.2019.00040","DOI":"10.1109\/MSR.2019.00040"},{"key":"10606_CR70","doi-asserted-by":"crossref","unstructured":"Rahman A, Parnin C, Williams L (2019) The seven sins: security smells in infrastructure as code scripts. In: 2019 IEEE\/ACM 41st International Conference on Software Engineering (ICSE). IEEE, pp 164\u2013175","DOI":"10.1109\/ICSE.2019.00033"},{"key":"10606_CR71","doi-asserted-by":"publisher","unstructured":"Rahman A, Parnin C, Williams L (2019) The seven sins: Security smells in infrastructure as code scripts. In: 2019 IEEE\/ACM 41st International Conference on Software Engineering (ICSE). pp 164\u2013175. https:\/\/doi.org\/10.1109\/ICSE.2019.00033","DOI":"10.1109\/ICSE.2019.00033"},{"key":"10606_CR72","doi-asserted-by":"publisher","unstructured":"Rahman MR, Rahman A, Williams L (2019) Share, but be aware: Security smells in python gists. In: 2019 IEEE International Conference on Software Maintenance and Evolution (ICSME), pp 536\u2013540. https:\/\/doi.org\/10.1109\/ICSME.2019.00087","DOI":"10.1109\/ICSME.2019.00087"},{"key":"10606_CR73","doi-asserted-by":"publisher","unstructured":"Rahman A, Rahman MR, Parnin C, Williams L (2021) Security smells in ansible and chef scripts: A replication study. ACM Trans Softw Eng Methodol 30(1). ISSN 1049\u2013331X. https:\/\/doi.org\/10.1145\/3408897","DOI":"10.1145\/3408897"},{"key":"10606_CR74","doi-asserted-by":"publisher","unstructured":"Rahman A, Shamim SI, Bose DB, Pandita R (2023b) Security misconfigurations in open source kubernetes manifests: An empirical study. ACM Trans Softw Eng Methodol 32(4). ISSN 1049\u2013331X. https:\/\/doi.org\/10.1145\/3579639","DOI":"10.1145\/3579639"},{"key":"10606_CR75","unstructured":"Rahman A, Zhang Y, Murphy J (2023c) Verifiability package for paper. https:\/\/figshare.com\/s\/0e2c77afd8215cbd3be2. [Online; accessed 15-Oct-2023]"},{"key":"10606_CR76","doi-asserted-by":"publisher","unstructured":"Reis S, Abreu R, d\u2019Amorim M, Fortunato D (2023) Leveraging practitioners\u2019 feedback to improve a security linter. In: Proceedings of the 37th IEEE\/ACM International Conference on Automated Software Engineering, ASE \u201922, New York, NY, USA. Association for Computing Machinery. ISBN 9781450394758. https:\/\/doi.org\/10.1145\/3551349.3560419","DOI":"10.1145\/3551349.3560419"},{"key":"10606_CR77","doi-asserted-by":"publisher","unstructured":"Ruohonen J, Hjerppe K, Rindell K (2021) A large-scale security-oriented static analysis of python packages in pypi. In: 2021 18th International Conference on Privacy, Security and Trust (PST) pp 1\u201310. https:\/\/doi.org\/10.1109\/PST52912.2021.9647791","DOI":"10.1109\/PST52912.2021.9647791"},{"key":"10606_CR78","doi-asserted-by":"publisher","unstructured":"Saavedra N, Ferreira JF (2023) Glitch: Automated polyglot security smell detection in infrastructure as code. In: Proceedings of the 37th IEEE\/ACM International Conference on Automated Software Engineering, ASE \u201922, New York, NY, USA. Association for Computing Machinery. ISBN 9781450394758. https:\/\/doi.org\/10.1145\/3551349.3556945","DOI":"10.1145\/3551349.3556945"},{"key":"10606_CR79","unstructured":"Salda\u00f1a J (2015) The coding manual for qualitative researchers,\u00a04th edn.\u00a0Sage Publications Limited\u00a0Fourth Edition, pp\u00a01\u2013440"},{"key":"10606_CR80","doi-asserted-by":"publisher","unstructured":"Sedgewick A, Souppaya M, Scarfone K (2015) Guide toApplicationWhitelisting. https:\/\/doi.org\/10.6028\/NIST.SP.800-167","DOI":"10.6028\/NIST.SP.800-167"},{"key":"10606_CR81","doi-asserted-by":"publisher","unstructured":"Sells R (2020) Julia programming language benchmark using a flight simulation. In: 2020 IEEE Aerospace Conference. pp 1\u20138. https:\/\/doi.org\/10.1109\/AERO47225.2020.9172277","DOI":"10.1109\/AERO47225.2020.9172277"},{"key":"10606_CR82","doi-asserted-by":"publisher","unstructured":"Shamim MI, Bhuiyan FA, Rahman A (2020) Xi commandments of kubernetes security: A systematization of knowledge related to kubernetes security practices. In: 2020 IEEE Secure Development (SecDev), Los Alamitos, CA, USA, pp 58\u201364. IEEE Computer Society. https:\/\/doi.org\/10.1109\/SecDev45635.2020.00025.","DOI":"10.1109\/SecDev45635.2020.00025"},{"key":"10606_CR83","doi-asserted-by":"publisher","unstructured":"Storey M-A, Ryall J, Bull RI, Myers D, Singer J (2008) Todo or to bug: Exploring how task annotations play a role in the work practices of software developers. In: Proceedings of the 30th International Conference on Software Engineering, ICSE \u201908, New York, NY, USA, pp 251\u2013260. Association for Computing Machinery. ISBN 9781605580791. https:\/\/doi.org\/10.1145\/1368088.1368123","DOI":"10.1145\/1368088.1368123"},{"issue":"4","key":"10606_CR84","doi-asserted-by":"publisher","first-page":"e89","DOI":"10.1111\/j.1369-7625.2012.00810.x","volume":"16","author":"A Sweeney","year":"2013","unstructured":"Sweeney A, Greenwood KE, Williams S, Wykes T, Rose DS (2013) Hearing the voices of service user researchers in collaborative qualitative data analysis: the case for multiple coding. Health Expect 16(4):e89\u2013e99","journal-title":"Health Expect"},{"key":"10606_CR85","unstructured":"Tan L, Yuan D, Zhou Y (2007) Hotcomments: How to make program comments more useful?"},{"key":"10606_CR86","unstructured":"The Julia language (2022) https:\/\/docs.julialang.org\/en\/v1\/.\u00a0Accessed 5 Nov 2024"},{"key":"10606_CR87","unstructured":"Tomasi M, Giordano M (2018) Towards new solutions for scientific computing: the case of Julia. arXiv preprint arXiv:1812.01219. https:\/\/arxiv.org\/abs\/1812.01219.\u00a0Accessed 5 Nov 2024"},{"issue":"5","key":"10606_CR88","doi-asserted-by":"publisher","first-page":"1497","DOI":"10.1109\/TSE.2020.3023664","volume":"48","author":"M Verdi","year":"2022","unstructured":"Verdi M, Sami A, Akhondali J, Khomh F, Uddin G, Motlagh AK (2022) An empirical study of c++ vulnerabilities in crowd-sourced code examples. IEEE Trans Software Eng 48(5):1497\u20131514. https:\/\/doi.org\/10.1109\/TSE.2020.3023664","journal-title":"IEEE Trans Software Eng"},{"key":"10606_CR89","unstructured":"Wallace B (2016) Compromising an entire julia cluster. https:\/\/blogs.blackberry.com\/en\/2016\/05\/compromising-an-entire-julia-cluster.\u00a0Accessed 1 Nov 2024"},{"key":"10606_CR90","doi-asserted-by":"crossref","unstructured":"Zappa Nardelli F, Belyakova J, Pelenitsyn A, Chung B, Bezanson J, Vitek J (2018) Julia subtyping: a rational reconstruction. Proce ACM Prog Lang 2:1\u201327","DOI":"10.1145\/3276483"},{"key":"10606_CR91","doi-asserted-by":"publisher","unstructured":"Zhang H, Wang S, Li H, Chen T-H, Hassan AE (2022) A study of c\/c++ code weaknesses on stack overflow. IEEE Trans Software Eng 48(7):2359\u20132375. https:\/\/doi.org\/10.1109\/TSE.2021.3058985","DOI":"10.1109\/TSE.2021.3058985"},{"issue":"12","key":"10606_CR92","doi-asserted-by":"publisher","first-page":"7204","DOI":"10.1002\/int.22586","volume":"36","author":"Q Zheng","year":"2021","unstructured":"Zheng Q, Zhao P, Zhang D, Wang H (2021) Mr-dcae: Manifold regularization-based deep convolutional autoencoder for unauthorized broadcasting identification. Int J Intell Syst 36(12):7204\u20137238","journal-title":"Int J Intell Syst"},{"issue":"6","key":"10606_CR93","doi-asserted-by":"publisher","first-page":"1298","DOI":"10.1109\/LCOMM.2022.3145647","volume":"26","author":"Q Zheng","year":"2022","unstructured":"Zheng Q, Zhao P, Wang H, Elhanashi A, Saponara S (2022) Fine-grained mod- ulation classification using multi-scale radio transformer with dual-channel rep- resentation. IEEE Commun Lett 26(6):1298\u20131302","journal-title":"IEEE Commun Lett"},{"issue":"10","key":"10606_CR94","doi-asserted-by":"publisher","first-page":"596","DOI":"10.3390\/drones7100596","volume":"7","author":"Q Zheng","year":"2023","unstructured":"Zheng Q, Tian X, Yu Z, Ding Y, Elhanashi A, Saponara S, Kpalma K (2023) Mobilerat: A lightweight radio transformer method for automatic modulation classification in drone communication systems. Drones 7(10):596","journal-title":"Drones"},{"issue":"2","key":"10606_CR95","doi-asserted-by":"publisher","first-page":"659","DOI":"10.1007\/s11571-023-10015-7","volume":"18","author":"Q Zheng","year":"2024","unstructured":"Zheng Q, Saponara S, Tian X, Yu Z, Elhanashi A, Yu R (2024) A real-time con- stellation image classification method of wireless communication signals based on the lightweight network mobilevit. Cogn Neurodyn 18(2):659\u2013671","journal-title":"Cogn Neurodyn"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-024-10606-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-024-10606-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-024-10606-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,2]],"date-time":"2025-05-02T13:47:00Z","timestamp":1746193620000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-024-10606-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,20]]},"references-count":95,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,3]]}},"alternative-id":["10606"],"URL":"https:\/\/doi.org\/10.1007\/s10664-024-10606-w","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,20]]},"assertion":[{"value":"16 December 2024","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 January 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"We, the authors have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflicts of Interests"}}],"article-number":"58"}}