{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T16:36:34Z","timestamp":1784997394660,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,4,15]],"date-time":"2024-04-15T00:00:00Z","timestamp":1713139200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100002661","name":"Fonds De La Recherche Scientifique - FNRS","doi-asserted-by":"publisher","award":["T.0149.22"],"award-info":[{"award-number":["T.0149.22"]}],"id":[{"id":"10.13039\/501100002661","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002661","name":"Fonds De La Recherche Scientifique - FNRS","doi-asserted-by":"publisher","award":["F.4515.23"],"award-info":[{"award-number":["F.4515.23"]}],"id":[{"id":"10.13039\/501100002661","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002661","name":"Fonds De La Recherche Scientifique - FNRS","doi-asserted-by":"publisher","award":["J.0147.24"],"award-info":[{"award-number":["J.0147.24"]}],"id":[{"id":"10.13039\/501100002661","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,4,15]]},"DOI":"10.1145\/3643991.3644899","type":"proceedings-article","created":{"date-parts":[[2024,8,6]],"date-time":"2024-08-06T21:19:25Z","timestamp":1722979165000},"page":"692-703","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["Quantifying Security Issues in Reusable JavaScript Actions in GitHub Workflows"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-7935-4147","authenticated-orcid":false,"given":"Hassan","family":"Onsori Delicheh","sequence":"first","affiliation":[{"name":"Software Engineering Lab, University of Mons, Belgium, Mons, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5824-5823","authenticated-orcid":false,"given":"Alexandre","family":"Decan","sequence":"additional","affiliation":[{"name":"Software Engineering Lab, University of Mons, Belgium, Mons, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3636-5020","authenticated-orcid":false,"given":"Tom","family":"Mens","sequence":"additional","affiliation":[{"name":"Software Engineering Lab, University of Mons, Belgium, Mons, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,7,2]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.25"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","unstructured":"M. Alfadel D. E. Costa and E. Shihab. 2021. Empirical Analysis of Security Vulnerabilities in Python Packages. In Int'l Conf. Software Analysis Evolution and Reengineering. 10.1109\/saner50967.2021.00048","DOI":"10.1109\/saner50967.2021.00048"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP52600.2021.00037"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3560835.3564554"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","unstructured":"M. Chen F. Fischer N. Meng X. Wang and J. Grossklags. 2019. How Reliable is the Crowdsourced Knowledge of Security Implementation?. In Int'l Conf. Software Engineering. 536--547. 10.1109\/ICSE.2019.00065","DOI":"10.1109\/ICSE.2019.00065"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/QRS-C55045.2021.00163"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","unstructured":"E. Constantinou and T. Mens. 2017. An empirical comparison of developer retention in the RubyGems and npm software ecosystems. Innovations in Systems and Software Engineering 13 101 (2017). 10.1007\/s11334-017-0303-4","DOI":"10.1007\/s11334-017-0303-4"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","unstructured":"A. Decan T. Mens and E. Constantinou. 2018. On the impact of security vulnerabilities in the npm package dependency network. In Int'l Conf. Mining Software Repositories. 181--191. 10.1145\/3196398.3196401","DOI":"10.1145\/3196398.3196401"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9589-y"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2023.111827"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","unstructured":"A. Decan T. Mens P. Rostami Mazrae and M. Golzadeh. 2022. On the Use of GitHub Actions in Software Development Repositories. In Int'l Conf. Software Maintenance and Evolution. IEEE. 10.1109\/ICSME55016.2022.00029","DOI":"10.1109\/ICSME55016.2022.00029"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","unstructured":"J. Dietrich S. Rasheed and A. Jordan. 2023. On the Security Blind Spots of Software Composition Analysis. Technical Report. 10.48550\/arXiv.2306.05534","DOI":"10.48550\/arXiv.2306.05534"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2022.3142338"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2005.85"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","unstructured":"M. Golzadeh A. Decan and T. Mens. 2021. On the rise and fall of CI services in GitHub. In Int'l Conf. Software Analysis Evolution and Reengineering. IEEE. 10.1109\/SANER53432.2022.00084","DOI":"10.1109\/SANER53432.2022.00084"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179471"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-021-10071-9"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2205.02544"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","unstructured":"N. Imtiaz S. Thorn and L. A. Williams. 2021. A comparative study of vulnerability reporting by software composition analysis tools. Int'l Symp. Empirical Software Engineering and Measurement (2021). 10.1145\/3475716.3475769","DOI":"10.1145\/3475716.3475769"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","unstructured":"R. Kikas G. Gousios M. Dumas and D. Pfahl. 2017. Structure and Evolution of Package Dependency Networks. In Int'l Conf. Mining Software Repositories. 102--112. 10.1109\/MSR.2017.55","DOI":"10.1109\/MSR.2017.55"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","unstructured":"T. Kinsman M. Wessel M. A. Gerosa and C. Treude. 2021. How do software developers use GitHub Actions to automate their workflows?. In Int'l Conf. Mining Software Repositories. 10.1109\/MSR52588.2021.00054","DOI":"10.1109\/MSR52588.2021.00054"},{"key":"e_1_3_2_1_22_1","volume-title":"Characterizing the Security of Github CI Workflows. In USENIX Security Symposium.","author":"Koishybayev I.","unstructured":"I. Koishybayev, A. Nahapetyan, R. Zachariah, S. Muralee, B. Reaves, A. Kapravelos, and A. Machiry. 2022. Characterizing the Security of Github CI Workflows. In USENIX Security Symposium."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3190562"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","unstructured":"C. Liu S. Chen L. Fan B. Chen Y. Liu and X. Peng. 2022. Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM Ecosystem. In Int'l Conf. Software Engineering. 672--684. 10.1145\/3510003.3510142","DOI":"10.1145\/3510003.3510142"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58951-6_13"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(18)30005-9"},{"key":"e_1_3_2_1_27_1","volume-title":"CEUR Workshop Proceedings 3483","author":"Onsori Delicheh H.","year":"2023","unstructured":"H. Onsori Delicheh, A. Decan, and T. Mens. 2023. A Preliminary Study of GitHub Actions Dependencies. CEUR Workshop Proceedings 3483 (2023), 66--77."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417232"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","unstructured":"H. Plate S. E. Ponta and A. Sabetta. 2015. Impact assessment for vulnerabilities in open-source software libraries. In Int'l Conf. Software Maintenance and Evolution. 411--420. 10.1109\/ICSM.2015.7332492","DOI":"10.1109\/ICSM.2015.7332492"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-020-09830-x"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2018.00054"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10285-5"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","unstructured":"S. G. Saroar and M. Nayebi. 2023. Developers' Perception of GitHub Actions: A Survey Analysis. In Int'l Conf. Evaluation and Assessment in Software Engineering. 10.1145\/3593434.3593475","DOI":"10.1145\/3593434.3593475"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3029806.3029832"},{"key":"e_1_3_2_1_35_1","volume-title":"State of Open Source Security","year":"2022","unstructured":"Snyk. 2022. State of Open Source Security 2022. https:\/\/snyk.io\/reports\/open-source-security\/. [Online; accessed on September 1, 2023]."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-020-09914-8"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.2507\/31st.daaam.proceedings.078"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1219078"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2022.3173123"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/2901739.2901743"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"crossref","unstructured":"C. Wohlin P. Runeson M. H\u00f6st M. C. Ohlsson B. Regnell and A. Wessl\u00e9n. 2012. Experimentation in Software Engineering. Springer.","DOI":"10.1007\/978-3-642-29044-2"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10154-1"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-020-09908-6"}],"event":{"name":"MSR '24: 21st International Conference on Mining Software Repositories","location":"Lisbon Portugal","acronym":"MSR '24","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS"]},"container-title":["Proceedings of the 21st International Conference on Mining Software Repositories"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3643991.3644899","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3643991.3644899","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T23:56:44Z","timestamp":1750291004000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3643991.3644899"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,15]]},"references-count":43,"alternative-id":["10.1145\/3643991.3644899","10.1145\/3643991"],"URL":"https:\/\/doi.org\/10.1145\/3643991.3644899","relation":{},"subject":[],"published":{"date-parts":[[2024,4,15]]},"assertion":[{"value":"2024-07-02","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}