{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:59:59Z","timestamp":1783007999884,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":49,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,4,25]],"date-time":"2022-04-25T00:00:00Z","timestamp":1650844800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"U.S. ARMY","award":["W56KGU-20-C-0008"],"award-info":[{"award-number":["W56KGU-20-C-0008"]}]},{"DOI":"10.13039\/501100013105","name":"Shanghai Rising-Star Program","doi-asserted-by":"publisher","award":["21QA1400700"],"award-info":[{"award-number":["21QA1400700"]}],"id":[{"id":"10.13039\/501100013105","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100009896","name":"U.S. NAVY","doi-asserted-by":"publisher","award":["N00014-20-1-2407"],"award-info":[{"award-number":["N00014-20-1-2407"]}],"id":[{"id":"10.13039\/100009896","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1836210, U1836213, 62172105, 61972099, 62172104, 62102091, 62102093"],"award-info":[{"award-number":["U1836210, U1836213, 62172105, 61972099, 62172104, 62102091, 62102093"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Natural Science Foundation of Shanghai","award":["19ZR1404800"],"award-info":[{"award-number":["19ZR1404800"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,4,25]]},"DOI":"10.1145\/3485447.3512236","type":"proceedings-article","created":{"date-parts":[[2022,4,25]],"date-time":"2022-04-25T05:11:23Z","timestamp":1650863483000},"page":"767-777","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":17,"title":["Understanding the Practice of Security Patch Management across Multiple Branches in OSS Projects"],"prefix":"10.1145","author":[{"given":"Xin","family":"Tan","sequence":"first","affiliation":[{"name":"Fudan University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Fudan University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiajun","family":"Cao","sequence":"additional","affiliation":[{"name":"Fudan University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kun","family":"Sun","sequence":"additional","affiliation":[{"name":"George Mason University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mi","family":"Zhang","sequence":"additional","affiliation":[{"name":"Fudan University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Min","family":"Yang","sequence":"additional","affiliation":[{"name":"Fudan University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,4,25]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2010. American Fuzzy Lop. https:\/\/lcamtuf.coredump.cx\/afl\/."},{"key":"e_1_3_2_1_2_1","unstructured":"2016. Syzkaller. https:\/\/github.com\/google\/syzkaller."},{"key":"e_1_3_2_1_3_1","unstructured":"2018. syzbot dashboard. https:\/\/syzkaller.appspot.com\/upstream."},{"key":"e_1_3_2_1_4_1","unstructured":"2021. Bigtree CMS. https:\/\/www.bigtreecms.org\/."},{"key":"e_1_3_2_1_5_1","unstructured":"2021. Bigtree CMS release cycle. https:\/\/www.bigtreecms.org\/developers\/dev-guide\/release-cycle\/."},{"key":"e_1_3_2_1_6_1","unstructured":"2021. github. https:\/\/github.com\/."},{"key":"e_1_3_2_1_7_1","unstructured":"2021. HHVM. https:\/\/hhvm.com\/."},{"key":"e_1_3_2_1_8_1","unstructured":"2021. HHVM release policy. https:\/\/docs.hhvm.com\/hhvm\/FAQ\/faq."},{"key":"e_1_3_2_1_9_1","unstructured":"2021. Jackson databind. https:\/\/github.com\/FasterXML\/jackson-databind."},{"key":"e_1_3_2_1_10_1","unstructured":"2021. OpenEMR. https:\/\/www.open-emr.org\/."},{"key":"e_1_3_2_1_11_1","unstructured":"2021. phpMyAdmin. https:\/\/www.phpmyadmin.net\/."},{"key":"e_1_3_2_1_12_1","unstructured":"2021. QEMU. https:\/\/www.qemu.org\/."},{"key":"e_1_3_2_1_13_1","unstructured":"2021. Semantic Versioning 2.0.0. https:\/\/semver.org\/."},{"key":"e_1_3_2_1_14_1","volume-title":"CWE: Common Weakness Enumeration.https:\/\/cwe.mitre.org\/.","author":"MITRE Corporation","year":"2021","unstructured":"MITRE Corporation. 2021. CWE: Common Weakness Enumeration.https:\/\/cwe.mitre.org\/."},{"key":"e_1_3_2_1_15_1","volume-title":"BScout: Direct Whole Patch Presence Test for Java Executables. In 29th USENIX Security Symposium (USENIX Security).","author":"Dai Jiarun","year":"2020","unstructured":"Jiarun Dai, Yuan Zhang, Zheyue Jiang, Yingtian Zhou, Junyan Chen, Xinyu Xing, Xiaohan Zhang, Xin Tan, Min Yang, and Zhemin Yang. 2020. BScout: Direct Whole Patch Presence Test for Java Executables. In 29th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484594"},{"key":"e_1_3_2_1_17_1","volume-title":"Proceedings of the 28th USENIX Security Symposium (USENIX Security).","author":"Dong Ying","year":"2019","unstructured":"Ying Dong, Wenbo Guo, Yueqi Chen, Xinyu Xing, Yuqing Zhang, and Gang Wang. 2019. Towards the Detection of Inconsistencies in Public Security Vulnerability Reports. In Proceedings of the 28th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_18_1","unstructured":"Sadegh Farhang Mehmet\u00a0Bahadir Kirdan Aron Laszka and Jens Grossklags. 2019. Hey google what exactly do your security patches tell us? a large-scale empirical study on android patched vulnerabilities. arXiv preprint arXiv:1905.09352(2019)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1162666.1162671"},{"key":"e_1_3_2_1_20_1","unstructured":"Google. 2016. OSS-Fuzz. https:\/\/github.com\/google\/oss-fuzz."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380361"},{"key":"e_1_3_2_1_22_1","volume-title":"PatchNet: A Tool for Deep Patch Classification. In 2019 IEEE\/ACM 41st International Conference on Software Engineering: Companion Proceedings (ICSE-Companion).","author":"Hoang Thong","year":"2019","unstructured":"Thong Hoang, Julia Lawall, Richard J.\u00a0Oentaryo, Yuan Tian, and David Lo. 2019. PatchNet: A Tool for Deep Patch Classification. In 2019 IEEE\/ACM 41st International Conference on Software Engineering: Companion Proceedings (ICSE-Companion)."},{"key":"e_1_3_2_1_23_1","volume-title":"PatchNet: Hierarchical Deep Learning-Based Stable Patch Identification for the Linux Kernel","author":"Hoang Thong","year":"2021","unstructured":"Thong Hoang, Julia Lawall, Yuan Tian, Richard\u00a0J. Oentaryo, and David Lo. 2021. PatchNet: Hierarchical Deep Learning-Based Stable Patch Identification for the Linux Kernel. IEEE Transactions on Software Engineering (TSE) (2021)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417240"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134072"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00038"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1126\/science.159.3810.56"},{"key":"e_1_3_2_1_28_1","volume-title":"The Matthew effect in science, II: Cumulative advantage and the symbolism of intellectual property. isis","author":"Merton K","year":"1988","unstructured":"Robert\u00a0K Merton. 1988. The Matthew effect in science, II: Cumulative advantage and the symbolism of intellectual property. isis (1988)."},{"key":"e_1_3_2_1_29_1","volume-title":"Proceedings 2000 International Conference on Software Maintenance.","author":"Votta Mockus","year":"2000","unstructured":"Mockus and Votta. 2000. Identifying reasons for software changes using historic databases (ICSM). In Proceedings 2000 International Conference on Software Maintenance."},{"key":"e_1_3_2_1_30_1","volume-title":"Proceedings of the 27th USENIX Security Symposium (USENIX Security).","author":"Mu Dongliang","year":"2018","unstructured":"Dongliang Mu, Alejandro Cuevas, Limin Yang, Hang Hu, Xinyu Xing, Bing Mao, and Gang Wang. 2018. Understanding the Reproducibility of Crowd-reported Security Vulnerabilities. In Proceedings of the 27th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_31_1","volume-title":"National\u00a0Institute of Standards and Technology","author":"S.","year":"2021","unstructured":"U.S. National\u00a0Institute of Standards and Technology. 2021. National Vulnerability Database. https:\/\/nvd.nist.gov\/home.cfm."},{"key":"e_1_3_2_1_32_1","volume-title":"National\u00a0Institute of Standards and Technology","author":"S.","year":"2021","unstructured":"U.S. National\u00a0Institute of Standards and Technology. 2021. NVD Data Feed.https:\/\/nvd.nist.gov\/vuln\/data-feeds."},{"key":"e_1_3_2_1_33_1","volume-title":"National\u00a0Institute of Standards and Technology","author":"S.","year":"2021","unstructured":"U.S. National\u00a0Institute of Standards and Technology. 2021. NVD Specific CVSS Information.https:\/\/nvd.nist.gov\/vuln-metrics\/cvss."},{"key":"e_1_3_2_1_34_1","volume-title":"National\u00a0Institute of Standards and Technology","author":"S.","year":"2021","unstructured":"U.S. National\u00a0Institute of Standards and Technology. 2021. Official Common Platform Enumeration Dictionary.https:\/\/nvd.nist.gov\/products\/cpe."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635922"},{"key":"e_1_3_2_1_36_1","volume-title":"Increasing Automation in the Backporting of Linux Drivers Using Coccinelle. In 2015 11th European Dependable Computing Conference (EDCC).","author":"R.","unstructured":"Luis\u00a0R. Rodriguez and Julia Lawall. 2015. Increasing Automation in the Backporting of Linux Drivers Using Coccinelle. In 2015 11th European Dependable Computing Conference (EDCC)."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.5555\/2337223.2337314"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464821"},{"key":"e_1_3_2_1_39_1","volume-title":"Backporting Security Patches of Web Applications: A Prototype Design and Implementation on Injection Vulnerability Patches. In 31th USENIX Security Symposium (USENIX Security).","author":"Shi Youkun","year":"2022","unstructured":"Youkun Shi, Yuan Zhang, Tianhan Luo, Xiangyu Mao, Yinzhi Cao, Ziwen Wang, Yudi Zhao, Zongan Huang, and Min Yang. 2022. Backporting Security Patches of Web Applications: A Prototype Design and Implementation on Injection Vulnerability Patches. In 31th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"crossref","unstructured":"Yan Sun Qing Wang and Ye Yang. 2017. FRLink: Improving the recovery of missing issue-commit links by revisiting file relevance. Information and Software Technology(2017).","DOI":"10.1016\/j.infsof.2016.11.010"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484593"},{"key":"e_1_3_2_1_42_1","volume-title":"Recommending Code Changes for Automatic Backporting of Linux Device Drivers. In 2016 IEEE International Conference on Software Maintenance and Evolution (ICSME).","author":"Thung Ferdian","year":"2016","unstructured":"Ferdian Thung, Xuan-Bach\u00a0D. Le, David Lo, and Julia Lawall. 2016. Recommending Code Changes for Automatic Backporting of Linux Device Drivers. In 2016 IEEE International Conference on Software Maintenance and Evolution (ICSME)."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.5555\/2337223.2337269"},{"key":"e_1_3_2_1_44_1","unstructured":"Tom Walker. 2021. 20 Most Popular Open Source Software Ever. https:\/\/www.tripwiremagazine.com\/20-most-popular-open-source-software-ever-2\/."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2019.00056"},{"key":"e_1_3_2_1_46_1","volume-title":"PatchDB: A Large-Scale Security Patch Dataset. In 51st Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN).","author":"Wang Xinda","year":"2021","unstructured":"Xinda Wang, Shu Wang, Pengbin Feng, Kun Sun, and Sushil Jajodia. 2021. PatchDB: A Large-Scale Security Patch Dataset. In 51st Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN)."},{"key":"e_1_3_2_1_47_1","volume-title":"The State of Open Source Vulnerabilities","year":"2021","unstructured":"WhiteSource. 2021. The State of Open Source Vulnerabilities 2021. https:\/\/www.whitesourcesoftware.com\/resources\/blog\/2021-state-of-open-source-security-vulnerabilities-cheat-sheet\/."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/2025113.2025120"},{"key":"e_1_3_2_1_49_1","volume-title":"An Investigation of the Android Kernel Patch Ecosystem. In 30th USENIX Security Symposium (USENIX Security).","author":"Zhang Zheng","year":"2021","unstructured":"Zheng Zhang, Hang Zhang, Zhiyun Qian, and Billy Lau. 2021. An Investigation of the Android Kernel Patch Ecosystem. In 30th USENIX Security Symposium (USENIX Security)."}],"event":{"name":"WWW '22: The ACM Web Conference 2022","location":"Virtual Event, Lyon France","acronym":"WWW '22","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM Web Conference 2022"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485447.3512236","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485447.3512236","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485447.3512236","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:30:13Z","timestamp":1750188613000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485447.3512236"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,4,25]]},"references-count":49,"alternative-id":["10.1145\/3485447.3512236","10.1145\/3485447"],"URL":"https:\/\/doi.org\/10.1145\/3485447.3512236","relation":{},"subject":[],"published":{"date-parts":[[2022,4,25]]},"assertion":[{"value":"2022-04-25","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}