{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T16:36:34Z","timestamp":1784997394367,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,4,15]],"date-time":"2024-04-15T00:00:00Z","timestamp":1713139200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100002661","name":"Fonds De La Recherche Scientifique - FNRS","doi-asserted-by":"publisher","award":["J.0147.24 and T.0149.22"],"award-info":[{"award-number":["J.0147.24 and T.0149.22"]}],"id":[{"id":"10.13039\/501100002661","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,4,15]]},"DOI":"10.1145\/3643662.3643961","type":"proceedings-article","created":{"date-parts":[[2024,8,26]],"date-time":"2024-08-26T18:16:08Z","timestamp":1724696168000},"page":"6-11","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Mitigating Security Issues in GitHub Actions"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-7935-4147","authenticated-orcid":false,"given":"Hassan Onsori","family":"Delicheh","sequence":"first","affiliation":[{"name":"University of Mons, Mons, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3636-5020","authenticated-orcid":false,"given":"Tom","family":"Mens","sequence":"additional","affiliation":[{"name":"University of Mons, Mons, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,8,26]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.25"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","unstructured":"M. Alfadel D. E. Costa and E. Shihab. 2021. Empirical Analysis of Security Vulnerabilities in Python Packages. In Int'l Conf. Software Analysis Evolution and Reengineering. 10.1109\/saner50967.2021.00048","DOI":"10.1109\/saner50967.2021.00048"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP52600.2021.00037"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","unstructured":"M. Chen F. Fischer N. Meng X. Wang and J. Grossklags. 2019. How Reliable is the Crowdsourced Knowledge of Security Implementation?. In Int'l Conf. Software Engineering. 536--547. 10.1109\/ICSE.2019.00065","DOI":"10.1109\/ICSE.2019.00065"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","unstructured":"J. Cox E. Bouwers M. van Eekelen and J. Visser. 2015. Measuring Dependency Freshness in Software Systems. In Int'l Conf. Software Engineering. IEEE 109--118. 10.1109\/ICSE.2015.140","DOI":"10.1109\/ICSE.2015.140"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","unstructured":"A. Decan T. Mens and E. Constantinou. 2018. On the impact of security vulnerabilities in the npm package dependency network. In Int'l Conf. Mining Software Repositories. 181--191. 10.1145\/3196398.3196401","DOI":"10.1145\/3196398.3196401"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9589-y"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2023.111827"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","unstructured":"A. Decan T. Mens P. Rostami Mazrae and M. Golzadeh. 2022. On the Use of GitHub Actions in Software Development Repositories. In Int'l Conf. Software Maintenance and Evolution. IEEE. 10.1109\/ICSME55016.2022.00029","DOI":"10.1109\/ICSME55016.2022.00029"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2022.3142338"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2005.85"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","unstructured":"M. Golzadeh A. Decan and T. Mens. 2021. On the rise and fall of CI services in GitHub. In Int'l Conf. Software Analysis Evolution and Reengineering. IEEE. 10.1109\/SANER53432.2022.00084","DOI":"10.1109\/SANER53432.2022.00084"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179471"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-021-10071-9"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2205.02544"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","unstructured":"R. Kikas G. Gousios M. Dumas and D. Pfahl. 2017. Structure and Evolution of Package Dependency Networks. In Int'l Conf. Mining Software Repositories. 102--112. 10.1109\/MSR.2017.55","DOI":"10.1109\/MSR.2017.55"},{"key":"e_1_3_2_1_17_1","volume-title":"Characterizing the Security of Github CI Workflows. In USENIX Security Symposium.","author":"Koishybayev I.","unstructured":"I. Koishybayev, A. Nahapetyan, R. Zachariah, S. Muralee, B. Reaves, A. Kapravelos, and A. Machiry. 2022. Characterizing the Security of Github CI Workflows. In USENIX Security Symposium."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9521-5"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3190562"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","unstructured":"C. Liu S. Chen L. Fan B. Chen Y. Liu and X. Peng. 2022. Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM Ecosystem. In Int'l Conf. Software Engineering. 672--684. 10.1145\/3510003.3510142","DOI":"10.1145\/3510003.3510142"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58951-6_13"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(18)30005-9"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103478"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-67383-7_2"},{"key":"e_1_3_2_1_25_1","volume-title":"CEUR Workshop Proc., 66--77","author":"Onsori Delicheh H.","unstructured":"H. Onsori Delicheh, A. Decan, and T. Mens. 2023. A Preliminary Study of GitHub Actions Dependencies. In Post-proceedings of the 15th Seminar on Advanced Techniques and Tools for Software Evolution (SATToSE),, Vol. 3483. CEUR Workshop Proc., 66--77."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"crossref","unstructured":"H. Onsori Delicheh A. Decan and T. Mens. 2024. Quantifying Security Issues in Reusable JavaScript Actions in GitHub Workflows. In Int'l Confn Mining Software Repositories.","DOI":"10.1145\/3643991.3644899"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2021.106700"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10285-5"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3029806.3029832"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1219078"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"crossref","unstructured":"N. Tomas J. Li and H. Huang. 2019. An Empirical Study on Culture Automation Measurement and Sharing of DevSecOps. In Int'l Conf. Cyber Security and Protection of Digital Services. IEEE.","DOI":"10.1109\/CyberSecPODS.2019.8884935"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-36060-2_8"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2022.3173123"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10154-1"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-020-09908-6"}],"event":{"name":"EnCyCriS\/SVM '24: 2024 ACM\/IEEE 4th International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS) and 2024 IEEE\/ACM Second International Workshop on Software Vulnerability","location":"Lisbon Portugal","acronym":"EnCyCriS\/SVM '24","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS","Faculty of Engineering of University of Porto"]},"container-title":["Proceedings of the 2024 ACM\/IEEE 4th International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS) and 2024 IEEE\/ACM Second International Workshop on Software Vulnerability"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3643662.3643961","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3643662.3643961","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:05:32Z","timestamp":1750291532000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3643662.3643961"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,15]]},"references-count":35,"alternative-id":["10.1145\/3643662.3643961","10.1145\/3643662"],"URL":"https:\/\/doi.org\/10.1145\/3643662.3643961","relation":{},"subject":[],"published":{"date-parts":[[2024,4,15]]},"assertion":[{"value":"2024-08-26","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}