{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,23]],"date-time":"2026-01-23T11:01:20Z","timestamp":1769166080678,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3623174","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"2426-2440","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["The Effectiveness of Security Interventions on GitHub"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9724-5965","authenticated-orcid":false,"given":"Felix","family":"Fischer","sequence":"first","affiliation":[{"name":"Technical University of Munich, Munich, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3797-5691","authenticated-orcid":false,"given":"Jonas","family":"H\u00f6benreich","sequence":"additional","affiliation":[{"name":"Technical University of Munich, Munich, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1093-1282","authenticated-orcid":false,"given":"Jens","family":"Grossklags","sequence":"additional","affiliation":[{"name":"Technical University of Munich, Munich, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.52"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.25"},{"key":"e_1_3_2_1_3_1","first-page":"81","volume-title":"Thirteenth Symposium on Usable Privacy and Security (SOUPS)","author":"Acar Yasemin","year":"2017","unstructured":"Yasemin Acar, Christian Stransky, Dominik Wermke, Michelle L. Mazurek, and Sascha Fahl. Security developer studies with Github users: Exploring a convenience sample. In Thirteenth Symposium on Usable Privacy and Security (SOUPS), pages 81--95, 2017."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP52600.2021.00037"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1162\/003355304772839588"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2018.09.016"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1214\/14-AOAS788"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00065"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380387"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2994475.2994480"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.31"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2022.3142337"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484763"},{"key":"e_1_3_2_1_14_1","first-page":"339","volume-title":"28th USENIX Security Symposium (USENIX Security)","author":"Fischer Felix","year":"2019","unstructured":"Felix Fischer, Huang Xiao, Ching-Yu Kao, Yannick Stachelscheid, Benjamin Johnson, Danial Razar, Paul Fawkesley, Nat Buckley, Konstantin B\u00f6ttinger, Paul Muntean, and Jens Grossklags. Stack overflow considered helpful! Deep learning security nudges towards stronger cryptography. In 28th USENIX Security Symposium (USENIX Security), pages 339--356, 2019."},{"key":"e_1_3_2_1_15_1","volume-title":"Eleventh International Conference on Learning Representations (ICLR)","author":"Fried Daniel","year":"2023","unstructured":"Daniel Fried, Armen Aghajanyan, Jessy Lin, Sida Wang, Eric Wallace, Freda Shi, Ruiqi Zhong, Wen-tau Yih, Luke Zettlemoyer, and Mike Lewis. InCoder: A generative model for code infilling and synthesis. In Eleventh International Conference on Learning Representations (ICLR), 2023."},{"key":"e_1_3_2_1_16_1","volume-title":"Summary analysis of the 2017 GitHub open source survey. arXiv preprint arXiv:1706.02777","author":"Geiger Stuart","year":"2017","unstructured":"Stuart Geiger. Summary analysis of the 2017 GitHub open source survey. arXiv preprint arXiv:1706.02777, 2017."},{"key":"e_1_3_2_1_17_1","volume-title":"Open source survey","year":"2017","unstructured":"GitHub. Open source survey, 2017. Available at: https:\/\/opensourcesurvey.org\/ 2017\/. Last accessed on: September 08, 2023."},{"key":"e_1_3_2_1_18_1","first-page":"265","volume-title":"Fourteenth Symposium on Usable Privacy and Security (SOUPS)","author":"Gorski Peter Leo","year":"2018","unstructured":"Peter Leo Gorski, Luigi Lo Iacono, Dominik Wermke, Christian Stransky, Sebastian M\u00f6ller, Yasemin Acar, and Sascha Fahl. Developers deserve security warnings, too: On the effect of integrated security advice on cryptographic API misuse. In Fourteenth Symposium on Usable Privacy and Security (SOUPS), pages 265--281, 2018."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2015.55"},{"key":"e_1_3_2_1_20_1","volume-title":"Identifying unusual commits on GitHub. Journal of Software: Evolution and Process, 30(1):Article No. e1893","author":"Goyal Raman","year":"2018","unstructured":"Raman Goyal, Gabriel Ferreira, Christian K\u00e4stner, and James Herbsleb. Identifying unusual commits on GitHub. Journal of Software: Evolution and Process, 30(1):Article No. e1893, 2018."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-016-9436-6"},{"key":"e_1_3_2_1_22_1","first-page":"672","volume-title":"ACM\/IEEE International Conference on Software Engineering (ICSE)","author":"Johnson Brittany","year":"2013","unstructured":"Brittany Johnson, Yoonki Song, Emerson Murphy-Hill, and Robert Bowdidge. Why don't software developers use static analysis tools to find bugs? In ACM\/IEEE International Conference on Software Engineering (ICSE), pages 672--681, 2013."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00060"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSR52588.2021.00054"},{"key":"e_1_3_2_1_25_1","first-page":"1065","volume-title":"ACM Conference on Computer and Communications Security (CCS)","author":"Nguyen Duc Cuong","year":"2017","unstructured":"Duc Cuong Nguyen, Dominik Wermke, Yasemin Acar, Michael Backes, Charles Weir, and Sascha Fahl. A stitch in time: Supporting Android developers in writing secure code. In ACM Conference on Computer and Communications Security (CCS), pages 1065--1077, 2017."},{"key":"e_1_3_2_1_26_1","volume-title":"Information and Software Technology, 139:Article No. 106665","author":"Panichella Sebastiano","year":"2021","unstructured":"Sebastiano Panichella, Gerardo Canfora, and Andrea Di Sorbo. ?Won't we fix this issue?\" Qualitative characterization and automated identification of wontfix issues on GitHub. Information and Software Technology, 139:Article No. 106665, 2021."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833571"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2016.68"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3001878.3001881"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2889160.2891035"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3173574.3174086"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/IWESEP.2016.19"},{"key":"e_1_3_2_1_33_1","volume-title":"Investigating the geography of open source software through GitHub. Technical report","author":"Takhteyev Yuri","year":"2010","unstructured":"Yuri Takhteyev and Andrew Hilts. Investigating the geography of open source software through GitHub. Technical report, University of Toronto, 2010."},{"key":"e_1_3_2_1_34_1","first-page":"1","volume-title":"2021 IEEE\/ACM 43rd International Conference on Software Engineering: Software Engineering Education and Training (ICSE-SEET)","author":"Tan Shin Hwei","year":"2021","unstructured":"Shin Hwei Tan, Chunfeng Hu, Ziqiang Li, Xiaowen Zhang, and Ying Zhou. GitHub-OSS Fixit: Fixing bugs at scale in a software engineering course. In 2021 IEEE\/ACM 43rd International Conference on Software Engineering: Software Engineering Education and Training (ICSE-SEET), pages 1--10, 2021."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/CHASE.2015.14"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/2702123.2702549"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2556420.2556483"}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623174","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3623174","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:48:56Z","timestamp":1755740936000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623174"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":37,"alternative-id":["10.1145\/3576915.3623174","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3623174","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}