{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,13]],"date-time":"2026-06-13T05:39:15Z","timestamp":1781329155126,"version":"3.54.1"},"reference-count":80,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"U.S. National Science Foundation","doi-asserted-by":"crossref","award":["2247141"],"award-info":[{"award-number":["2247141"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/100000001","name":"U.S. National Science Foundation","doi-asserted-by":"crossref","award":["2310179"],"award-info":[{"award-number":["2310179"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/100009226","name":"U.S. National Security Agency","doi-asserted-by":"crossref","award":["H98230-21-1-0175"],"award-info":[{"award-number":["H98230-21-1-0175"]}],"id":[{"id":"10.13039\/100009226","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IIEEE Trans. Software Eng."],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/tse.2023.3265962","type":"journal-article","created":{"date-parts":[[2023,4,14]],"date-time":"2023-04-14T17:28:04Z","timestamp":1681493284000},"page":"1-18","source":"Crossref","is-referenced-by-count":20,"title":["Detecting and Characterizing Propagation of Security Weaknesses in Puppet-based infrastructure Management"],"prefix":"10.1109","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5056-757X","authenticated-orcid":false,"given":"Akond","family":"Rahman","sequence":"first","affiliation":[{"name":"Computer Science and Software Engineering, Auburn University, Auburn, AL, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6182-815X","authenticated-orcid":false,"given":"Chris","family":"Parnin","sequence":"additional","affiliation":[{"name":"Microsoft Research, Microsoft Corp, Redmond, WA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2009.5069475"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/s11859-019-1379-5"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3417113.3422154"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3236029"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00068"},{"key":"ref59","article-title":"About KPN","year":"2021"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/4236.769420"},{"key":"ref58","article-title":"Ambit energy's competitive advantage? it's really a devops software company","year":"2018","journal-title":"Puppet Tech Rep"},{"key":"ref53","article-title":"ONOS","year":"2020"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9512-6"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3236040"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/s10488-013-0528-y"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/1251535.1251536"},{"key":"ref54","article-title":"OpenStack git repository browser","year":"2020"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/1655121.1655125"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICSA-C54293.2022.00049"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-27937-9_15"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1177\/001316446002000104"},{"key":"ref51","article-title":"Mozilla mercurial repositories index","year":"2021"},{"key":"ref50","article-title":"CWE-327: Use of a broken or risky cryptographic algorithm","year":"2022"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1093\/fampra\/13.6.522"},{"key":"ref45","first-page":"1517","article-title":"Cardpliance: PCI DSS compliance of Android applications","author":"mahmud","year":"2020","journal-title":"Proc 29th USENIX Secur Symp"},{"key":"ref48","article-title":"Hardcoded and embedded credentials are an IT security Hazard&#x2013;Here's what you need to know","author":"miller","year":"2019"},{"key":"ref47","author":"martin","year":"2021","journal-title":"Hacking Kubernetes Threat-Driven Analysis and Defense"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.2307\/2529310"},{"key":"ref41","article-title":"Puppet documentation","author":"labs","year":"2021"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833803"},{"key":"ref43","article-title":"leapcode\/leap_platform","year":"2018"},{"key":"ref49","article-title":"CWE-Common weakness enumeration","year":"2021"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2019.04.013"},{"key":"ref7","volume":"7","author":"aho","year":"1986","journal-title":"Compilers Principles Techniques"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594299"},{"key":"ref4","article-title":"US investigators probing breach at code testing company Codecov","author":"satter","year":"2021"},{"key":"ref3","article-title":"Attacks against container infrastructures increasing, including supply chain attacks","author":"townsend","year":"2021"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3183519.3183549"},{"key":"ref5","article-title":"Attacks in the wild on the container supply chain and infrastructure","year":"2021"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3183519.3183548"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.60"},{"key":"ref35","article-title":"Jenkins","year":"2022"},{"key":"ref79","article-title":"Wikimedia code review","year":"2021"},{"key":"ref34","author":"humble","year":"2010","journal-title":"Continuous Delivery Reliable Software Releases Through Build Test and Deployment Automation"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2018.8330206"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606613"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2015.12"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.7748\/nr.4.1.81.s9"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1145\/2786805.2786812"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/2499393.2499399"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/CHASE.2013.6614738"},{"key":"ref33","article-title":"Security smells in open-source infrastructure as code scripts: A replication study","author":"hortlund","year":"2021"},{"key":"ref77","author":"tan","year":"2005","journal-title":"Introduction to Data Mining"},{"key":"ref32","article-title":"GitHub on BigQuery: Analyze all the open source code","author":"hoffa","year":"2016"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1111\/j.1369-7625.2012.00810.x"},{"key":"ref2","article-title":"Codecov hackers breached hundreds of restricted customer sites - sources","author":"menn","year":"2021"},{"key":"ref1","article-title":"Securing CI\/CD pipelines: 6 best practices","author":"sharma","year":"2021"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-84800-044-5_3"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-015-9393-5"},{"key":"ref71","article-title":"Hardcoded and embedded credentials are an IT security Hazard&#x2013;Here's what you need to know","author":"schwarz","year":"2021"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2009.5314220"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/CHASE.2013.6614738"},{"key":"ref72","first-page":"189","article-title":"Does Your Configuration Code Smell?","author":"sharma","year":"2016","journal-title":"2016 IEEE\/ACM 13th Conference on Mining Software Repositories (MSR)"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-30921-2_17"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/3188720"},{"key":"ref23","article-title":"Over a billion pharmacy records exposed&#x2013;What it means for your privacy","author":"fripp","year":"2021"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2021.3065190"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23089"},{"key":"ref25","article-title":"REST Gitlab API Docs","year":"2019"},{"key":"ref69","author":"salda\u00f1a","year":"2015","journal-title":"The Coding Manual for Qualitative Researchers"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/LADC.2016.25"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00033"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-020-09841-8"},{"key":"ref22","article-title":"Data breach alert: Info on millions of seniors leaked online","author":"fripp","year":"2021"},{"key":"ref66","article-title":"Security misconfigurations in open source Kubernetes manifests: An empirical study","author":"rahman","year":"2022","journal-title":"ACM Trans Softw Eng Methodol"},{"key":"ref21","author":"duvall","year":"2007","journal-title":"Continuous Integration Improving Software Quality and Reducing Risk (The Addison-Wesley Signature Series)"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/3408897"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1088\/1757-899X\/1043\/3\/032008"},{"key":"ref27","article-title":"The reliable, high performance TCP\/HTTP load balancer","year":"2022"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2009.45"},{"key":"ref60","article-title":"Verifiability package for paper","author":"rahman","year":"2021"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380409"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev51306.2021.00024"}],"container-title":["IEEE Transactions on Software Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/32\/4359463\/10102545.pdf?arnumber=10102545","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,6,13]],"date-time":"2023-06-13T21:18:22Z","timestamp":1686691102000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10102545\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":80,"URL":"https:\/\/doi.org\/10.1109\/tse.2023.3265962","relation":{},"ISSN":["0098-5589","1939-3520","2326-3881"],"issn-type":[{"value":"0098-5589","type":"print"},{"value":"1939-3520","type":"electronic"},{"value":"2326-3881","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]}}}