{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:59:35Z","timestamp":1784300375950,"version":"3.55.0"},"reference-count":47,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,4,28]],"date-time":"2025-04-28T00:00:00Z","timestamp":1745798400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,4,28]],"date-time":"2025-04-28T00:00:00Z","timestamp":1745798400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,4,28]]},"DOI":"10.1109\/msr66628.2025.11513373","type":"proceedings-article","created":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T19:43:32Z","timestamp":1778528612000},"page":"1-13","source":"Crossref","is-referenced-by-count":1,"title":["Towards Security Commit Message Standardization"],"prefix":"10.1109","author":[{"given":"Sofia","family":"Reis","sequence":"first","affiliation":[{"name":"INESC-ID &#x0026; IST\/T&#x00E9;cnico University of Lisbon,Lisbon,Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rui","family":"Abreu","sequence":"additional","affiliation":[{"name":"University of Porto,INESC-ID &#x0026; FEUP,Porto,Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Corina","family":"P\u0103s\u0103reanu","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"New windows vulnerabilities highlight patch management challenges","author":"Thomas","year":"2020"},{"key":"ref2","volume-title":"Former equifax ceo blames breach on a single person who failed to deploy patch","author":"Brandom","year":"2017"},{"key":"ref3","volume-title":"The continuing threat of unpatched security vulnerabilities","year":"2022"},{"key":"ref4","volume-title":"Alert (aa22-047a) russian statesponsored cyber actors target cleared defense contractor networks to obtain sensitive u.s. defense information and technology","year":"2022"},{"key":"ref5","volume-title":"Majority of 2019 breaches were the result of unapplied security patches","year":"2019"},{"key":"ref6","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.SP.800-40r3","volume-title":"Guide to enterprise patch management technologies","author":"Souppaya","year":"2013"},{"key":"ref7","article-title":"Keepers of the machines: Examining how system administrators manage software updates for multiple machines","volume-title":"SOUPS @ USENIX Security Symposium","author":"Li"},{"key":"ref8","article-title":"Security, availability, and multiple information sources: Exploring update behavior of system administrators","volume-title":"Proceedings of the Sixteenth USENIX Conference on Usable Privacy and Security, ser. SOUPS\u201920. USA: USENIX Association","author":"Tiefenau"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1504\/ijccbs.2019.098812"},{"key":"ref10","doi-asserted-by":"crossref","first-page":"106771","DOI":"10.1016\/j.infsof.2021.106771","article-title":"Software security patch management - a systematic literature review of challenges, approaches, tools and practices","volume":"144","author":"Dissanayake","year":"2022","journal-title":"Information and Software Technology"},{"key":"ref11","article-title":"An investigation of the android kernel patch ecosystem","volume-title":"USENIX Security Symposium","author":"Zhang"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10168-9"},{"key":"ref13","first-page":"69","article-title":"Secbench: A database of real security vulnerabilities","volume-title":"International Workshop on Secure Software Engineering in DevOps and Agile Development @ ESORICS","author":"Reis"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678720"},{"key":"ref15","article-title":"Beyond metadata: Code-centric and usage-based analysis of known vulnerabilities in open-source software","volume":"abs\/1806.05893","author":"Ponta","year":"2018","journal-title":"CoRR"},{"key":"ref16","article-title":"A practical approach to the automatic classification of security-relevant commits","volume":"abs\/1807.02458","author":"Sabetta","year":"2018","journal-title":"CoRR"},{"key":"ref17","article-title":"CERT\u00ae Guide to Coordinated Vulnerability Disclosure","volume":"9","author":"Householder","year":"2020"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3593434.3593481"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3117771"},{"key":"ref20","article-title":"What makes a good commit message?","author":"Tian","year":"2022","journal-title":"ICSE\u201922. ACM"},{"key":"ref21","volume-title":"Conventional commits","year":"2026"},{"key":"ref22","volume-title":"Linus torvalds describes a good commit message","author":"Torvalds","year":"2026"},{"key":"ref23","volume-title":"Developer tip: Keep your commits \u201catomic\u201d","author":"Patterson","year":"2026"},{"key":"ref24","volume-title":"How to write a git commit message","author":"Beams","year":"2026"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE55347.2025.00034"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.63317\/32qwwi833fm3"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/QRS62785.2024.00030"},{"key":"ref28","first-page":"123","article-title":"Few-shot training ll ms for project-specific code summarization","volume-title":"Proceedings of the 2022 Conference on Empirical Methods in Natural Language Processing (EMNLP)","author":"Ahmad"},{"key":"ref29","volume-title":"National vulnerability database","year":"2026"},{"key":"ref30","volume-title":"A distributed vulnerability database for open source","year":"2026"},{"key":"ref31","volume-title":"Open source vulnerability format","author":"Chang","year":"2022"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3125270"},{"key":"ref33","volume-title":"Death knell of the nvd?","author":"Hughes","year":"2024"},{"key":"ref34","volume-title":"Danger is still lurking in the nvd backlog","year":"2024"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.2981314"},{"key":"ref36","first-page":"1","article-title":"Named entity recognition without gazetteers","volume-title":"Ninth Conference of the European Chapter of the Association for Computational Linguistics","author":"Mikheev"},{"key":"ref37","first-page":"260","article-title":"Neural architectures for named entity recognition","volume-title":"Proceedings of the 2016 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies","author":"Lample"},{"key":"ref38","first-page":"56","article-title":"Biomedical named entity recognition with multilingual BERT","volume-title":"Proceedings of the 5th Workshop on BioNLP Open Shared Tasks","author":"Hakala"},{"key":"ref39","first-page":"1","article-title":"PharmaCoNER: Pharmacological substances, compounds and proteins named entity recognition track","volume-title":"Proceedings of the 5th Workshop on BioNLP Open Shared Tasks","author":"Gonzalez-Agirre"},{"key":"ref40","first-page":"869","article-title":"Towards the detection of inconsistencies in public security vulnerability reports","volume-title":"Proceedings of the 28th USENIX Conference on Security Symposium, ser. SEC\u201919","author":"Dong"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134072"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3475716.3475781"},{"key":"ref43","volume-title":"The open source software security mobilization plan","author":"J. A","year":"2022"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2015.229"},{"key":"ref45","volume-title":"Scaling the security researcher to eliminate oss vulnerabilities once and for all","author":"Leitschuh","year":"2026"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660329"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3524842.3528513"}],"event":{"name":"2025 IEEE\/ACM 22nd International Conference on Mining Software Repositories (MSR)","location":"Ottawa, ON, Canada","start":{"date-parts":[[2025,4,28]]},"end":{"date-parts":[[2025,4,29]]}},"container-title":["2025 IEEE\/ACM 22nd International Conference on Mining Software Repositories (MSR)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11025548\/11025536\/11513373.pdf?arnumber=11513373","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,12]],"date-time":"2026-05-12T19:45:17Z","timestamp":1778615117000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11513373\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,28]]},"references-count":47,"URL":"https:\/\/doi.org\/10.1109\/msr66628.2025.11513373","relation":{},"subject":[],"published":{"date-parts":[[2025,4,28]]}}}