{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,30]],"date-time":"2026-01-30T02:46:13Z","timestamp":1769741173798,"version":"3.49.0"},"reference-count":82,"publisher":"Association for Computing Machinery (ACM)","issue":"ISSTA","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2025,6,22]]},"abstract":"<jats:p>In the rapidly evolving landscape of software development, addressing security vulnerabilities in open-source  \nsoftware (OSS) has become critically important. However, existing research and tools from both academia and  \nindustry mainly relied on limited solutions, such as vulnerable version adjustment and adopting patches, to  \nhandle identified vulnerabilities. However, far more flexible and diverse countermeasures have been actively  \nadopted in the open-source communities. A holistic empirical study is needed to explore the prevalence,  \ndistribution, preferences, and effectiveness of these diverse strategies.  \nTo this end, in this paper, we conduct a comprehensive study on the taxonomy of vulnerability remediation  \ntactics (RT) in OSS projects and investigate their pros and cons. This study addresses this oversight by  \nconducting a comprehensive empirical analysis of 21,187 issues from GitHub, aiming to understand the range  \nand efficacy of remediation tactics within the OSS community. We developed a hierarchical taxonomy of  \n44 distinct RT and evaluated their effectiveness and costs. Our findings highlight a significant reliance on  \ncommunity-driven strategies, like using alternative libraries and bypassing vulnerabilities, 44% of which are  \ncurrently unsupported by cutting-edge tools. Additionally, this research exposes the community\u2019s preferences  \nfor certain fixing approaches by analyzing their acceptance and the reasons for rejection. It also underscores a  \ncritical gap in modern vulnerability databases, where 54% of CVEs lack fixing suggestions\u2014a gap that can be  \nsignificantly mitigated by leveraging the 93% of actionable solutions provided through GitHub issues.<\/jats:p>","DOI":"10.1145\/3728977","type":"journal-article","created":{"date-parts":[[2025,6,22]],"date-time":"2025-06-22T10:52:56Z","timestamp":1750589576000},"page":"2273-2295","source":"Crossref","is-referenced-by-count":3,"title":["Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue Management"],"prefix":"10.1145","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3087-9645","authenticated-orcid":false,"given":"Lyuye","family":"Zhang","sequence":"first","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6758-4635","authenticated-orcid":false,"given":"Jiahui","family":"Wu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1175-2753","authenticated-orcid":false,"given":"Chengwei","family":"Liu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3517-353X","authenticated-orcid":false,"given":"Kaixuan","family":"Li","sequence":"additional","affiliation":[{"name":"East China Normal University, Singapore, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7434-0452","authenticated-orcid":false,"given":"Xiaoyu","family":"Sun","sequence":"additional","affiliation":[{"name":"Australian National University, Canberra, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-9832-8948","authenticated-orcid":false,"given":"Lida","family":"Zhao","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1424-6290","authenticated-orcid":false,"given":"Chong","family":"Wang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,6,22]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"2017. Hybrid Card Sorting Challenge. https:\/\/medium.com\/design-ibm\/card-sorting-a-powerful-simple-research-method-9d1566be9b62"},{"key":"e_1_2_1_2_1","unstructured":"2018. Hybrid Card Sorting Challenge. https:\/\/www.optimalworkshop.com\/blog\/how-to-interpret-your-card-sort-results-part-1-open-and-hybrid-card-sorts"},{"key":"e_1_2_1_3_1","unstructured":"2021. Hybrid Card Sorting. https:\/\/support.optimalworkshop.com\/en\/articles\/2626850-choose-between-an-open-closed-or-hybrid-card-sort"},{"key":"e_1_2_1_4_1","unstructured":"2022. Example 2 from GitHub. https:\/\/github.com\/nginxinc\/docker-nginx-unprivileged\/issues\/166"},{"key":"e_1_2_1_5_1","unstructured":"2022. Log4j Vulnerability News. https:\/\/thenewstack.io\/one-year-of-log4j"},{"key":"e_1_2_1_6_1","unstructured":"2023. CVE-2023-44487. https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2023-44487"},{"key":"e_1_2_1_7_1","unstructured":"2023. Dependabot. https:\/\/github.com\/dependabot"},{"key":"e_1_2_1_8_1","unstructured":"2023. Eclipse Steady. https:\/\/projects.eclipse.org\/proposals\/eclipse-steady"},{"key":"e_1_2_1_9_1","unstructured":"2023. Github Security Advisory. https:\/\/github.com\/advisories"},{"key":"e_1_2_1_10_1","unstructured":"2023. Log4j Vulnerability News. https:\/\/www.securityweek.com\/one-year-later-log4shell-remediation-slow-painful-slog\/"},{"key":"e_1_2_1_11_1","unstructured":"2023. Log4j Vulnerability News. https:\/\/securityintelligence.com\/articles\/log4j-vulnerability-changed-oss-cybersecurity\/"},{"key":"e_1_2_1_12_1","unstructured":"2023. Maven. https:\/\/maven.apache.org\/"},{"key":"e_1_2_1_13_1","unstructured":"2023. Maven Dependency Management. https:\/\/maven.apache.org\/guides\/introduction\/introduction-to-dependency-mechanism.html"},{"key":"e_1_2_1_14_1","unstructured":"2023. National Vulnerability Database. https:\/\/nvd.nist.gov\/"},{"key":"e_1_2_1_15_1","unstructured":"2023. Node Package Manager (NPM). https:\/\/www.npmjs.com\/"},{"key":"e_1_2_1_16_1","unstructured":"2023. OSV. https:\/\/osv.dev\/ (Accessed on 02\/17\/2023)"},{"key":"e_1_2_1_17_1","unstructured":"2023. OWASP Dependency Check. https:\/\/owasp.org\/www-project-dependency-check\/"},{"key":"e_1_2_1_18_1","unstructured":"2023. Project Object Model. https:\/\/maven.apache.org\/guides\/introduction\/introduction-to-the-pom.html"},{"key":"e_1_2_1_19_1","unstructured":"2023. Snyk. https:\/\/snyk.io\/"},{"key":"e_1_2_1_20_1","unstructured":"2023. Snyk Vulnerability Database. https:\/\/security.snyk.io\/"},{"key":"e_1_2_1_21_1","unstructured":"2023. Sonarqube. https:\/\/www.sonarqube.org\/"},{"key":"e_1_2_1_22_1","unstructured":"2024. Apache Jira Board. https:\/\/issues.apache.org\/jira\/secure\/Dashboard.jspa"},{"key":"e_1_2_1_23_1","unstructured":"2024. Bill of Materials. https:\/\/en.wikipedia.org\/wiki\/Bill_of_materials"},{"key":"e_1_2_1_24_1","unstructured":"2024. CodeQL. https:\/\/codeql.github.com\/"},{"key":"e_1_2_1_25_1","unstructured":"2024. CVE-2023-44487. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-31479"},{"key":"e_1_2_1_26_1","unstructured":"2024. Dataset. https:\/\/github.com\/zly123987\/remediation_study_issta25"},{"key":"e_1_2_1_27_1","unstructured":"2024. Eliminating the Last Mile Between Security Data and Decision Making - Cyber Defense Magazine. https:\/\/www.cyberdefensemagazine.com\/eliminating-the-last-mile-between-security-data-and-decision-making\/ (Accessed on 08\/03\/2024)"},{"key":"e_1_2_1_28_1","unstructured":"2024. Example 1 from GitHub. https:\/\/github.com\/NoMoreFood\/putty-cac\/issues\/126"},{"key":"e_1_2_1_29_1","unstructured":"2024. ExploitDB. https:\/\/www.exploit-db.com\/"},{"key":"e_1_2_1_30_1","unstructured":"2024. IBM XForce. https:\/\/exchange.xforce.ibmcloud.com\/ip\/"},{"key":"e_1_2_1_31_1","unstructured":"2024. Infer. https:\/\/fbinfer.com\/"},{"key":"e_1_2_1_32_1","unstructured":"2024. Mend. https:\/\/www.mend.io\/"},{"key":"e_1_2_1_33_1","unstructured":"2024. Multiple CVE in an Issue. https:\/\/github.com\/bcgit\/bc-java\/issues\/1403"},{"key":"e_1_2_1_34_1","unstructured":"2024. OSV-Scanner Fix. https:\/\/google.github.io\/osv-scanner\/experimental\/guided-remediation\/"},{"key":"e_1_2_1_35_1","unstructured":"2024. OWASP ZAP. https:\/\/www.zaproxy.org\/"},{"key":"e_1_2_1_36_1","unstructured":"2024. SecLists. https:\/\/seclists.org\/"},{"key":"e_1_2_1_37_1","unstructured":"2024. Semgrep. https:\/\/semgrep.dev\/"},{"key":"e_1_2_1_38_1","unstructured":"2024. Sonatype LifeCycle. https:\/\/help.sonatype.com\/en\/sonatype-lifecycle.html"},{"key":"e_1_2_1_39_1","unstructured":"2024. SpotBugs. https:\/\/spotbugs.github.io\/"},{"key":"e_1_2_1_40_1","unstructured":"2024. Ubuntu CVE. https:\/\/ubuntu.com\/security\/cves.json"},{"key":"e_1_2_1_41_1","unstructured":"2024. Ubuntu Forum. https:\/\/ubuntuforums.org\/"},{"key":"e_1_2_1_42_1","unstructured":"2024. VulDB. https:\/\/vuldb.com\/"},{"key":"e_1_2_1_43_1","unstructured":"2024. VulnDB. https:\/\/vulndb.flashpoint.io\/"},{"key":"e_1_2_1_44_1","unstructured":"2025. Override Transitive Dependencies. https:\/\/doc.rust-lang.org\/cargo\/reference\/overriding-dependencies.html"},{"key":"e_1_2_1_45_1","unstructured":"2025. Override Transitive Dependencies. https:\/\/fossa.com\/blog\/overriding-dependency-versions-using-version-ranges-maven\/"},{"key":"e_1_2_1_46_1","unstructured":"2025. Pearson correlation. https:\/\/en.wikipedia.org\/wiki\/Pearson_correlation_coefficient"},{"key":"e_1_2_1_47_1","unstructured":"2025. Remediation Definition. https:\/\/cyberpedia.reasonlabs.com\/EN\/remediation.html?utm_source=chatgpt.com"},{"key":"e_1_2_1_48_1","unstructured":"2025. Veracode. https:\/\/www.veracode.com\/products\/fix\/"},{"key":"e_1_2_1_49_1","doi-asserted-by":"crossref","first-page":"235","DOI":"10.3390\/computers12110235","article-title":"Enhancing Web Application Security through Automated Penetration Testing with Multiple Vulnerability Scanners","volume":"12","author":"Abdulghaffar Khaled","year":"2023","unstructured":"Khaled Abdulghaffar, Nebrase Elmrabit, and Mehdi Yousefi. 2023. Enhancing Web Application Security through Automated Penetration Testing with Multiple Vulnerability Scanners. Computers, 12, 11 (2023), 235.","journal-title":"Computers"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/1134285.1134336"},{"key":"e_1_2_1_51_1","volume-title":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. 2447\u20132449","author":"Bandara Vinuri","year":"2021","unstructured":"Vinuri Bandara, Thisura Rathnayake, Nipuna Weerasekara, Charitha Elvitigala, Kenneth Thilakarathna, Primal Wijesekera, Kasun De Zoysa, and Chamath Keppitiyagama. 2021. Large scale analysis on vulnerability remediation in open-source JavaScript projects. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. 2447\u20132449."},{"key":"e_1_2_1_52_1","volume-title":"2020 IEEE 20th International Working Conference on Source Code Analysis and Manipulation (SCAM). 198\u2013202","author":"Bandara Vinuri","year":"2020","unstructured":"Vinuri Bandara, Thisura Rathnayake, Nipuna Weerasekara, Charitha Elvitigala, Kenneth Thilakarathna, Primal Wijesekera, and Chamath Keppitiyagama. 2020. Fix that Fix Commit: A real-world remediation analysis of JavaScript projects. In 2020 IEEE 20th International Working Conference on Source Code Analysis and Manipulation (SCAM). 198\u2013202."},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196884"},{"key":"e_1_2_1_54_1","volume-title":"An Exploratory Study on Self-Fixed Software Vulnerabilities in OSS Projects. In 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER). 90\u2013100","author":"Forootani Sara","year":"2022","unstructured":"Sara Forootani, Andrea Di Sorbo, and Corrado A Visaggio. 2022. An Exploratory Study on Self-Fixed Software Vulnerabilities in OSS Projects. In 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER). 90\u2013100."},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549098"},{"key":"e_1_2_1_56_1","volume-title":"Sanchez-Giraldo","author":"Hoyos-Osorio Jhoan K.","year":"2024","unstructured":"Jhoan K. Hoyos-Osorio and Luis G. Sanchez-Giraldo. 2024. The Representation Jensen-Shannon Divergence. arxiv:2305.16446. arxiv:2305.16446"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3639230"},{"key":"e_1_2_1_58_1","volume-title":"2016 IEEE Symposium on Security and Privacy (SP). 618\u2013635","author":"Huang Zhen","year":"2016","unstructured":"Zhen Huang, Mariana DAngelo, Dhaval Miyani, and David Lie. 2016. Talos: Neutralizing vulnerabilities with security workarounds for rapid response. In 2016 IEEE Symposium on Security and Privacy (SP). 618\u2013635."},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.5555\/3138884.3139034"},{"key":"e_1_2_1_60_1","doi-asserted-by":"crossref","first-page":"24","DOI":"10.4018\/IJISP.2018100102","article-title":"VuWaDB: A Vulnerability Workaround Database","volume":"12","author":"Khazaei Atefeh","year":"2018","unstructured":"Atefeh Khazaei, Mohammad Ghasemzadeh, and Christoph Meinel. 2018. VuWaDB: A Vulnerability Workaround Database. International Journal of Information Security and Privacy (IJISP), 12, 4 (2018), 24\u201334.","journal-title":"International Journal of Information Security and Privacy (IJISP)"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134072"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3616262"},{"key":"e_1_2_1_63_1","volume-title":"Proc. ACM Softw. Eng., 1, FSE","author":"Li Kaixuan","year":"2024","unstructured":"Kaixuan Li, Yue Xue, Sen Chen, Han Liu, Kairan Sun, Ming Hu, Haijun Wang, Yang Liu, and Yixiang Chen. 2024. Static Application Security Testing (SAST) Tools for Smart Contracts: How Far Are We? Proc. ACM Softw. Eng., 1, FSE (2024), Article 65, July, 24 pages."},{"key":"e_1_2_1_64_1","volume-title":"Proceedings of the 33rd ACM Sigsoft International Symposium on Software Testing and Analysis. Pages\u2013590","author":"Li Kaixuan","year":"2024","unstructured":"Kaixuan Li, Jian Zhang, Sen Chen, Han Liu, Yang Liu, and Yixiang Chen. 2024. Patchfinder: A Two-phase Approach to Security Patch Tracing for Disclosed Vulnerabilities in Open-source Software. In Proceedings of the 33rd ACM Sigsoft International Symposium on Software Testing and Analysis. Pages\u2013590."},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510142"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598056"},{"key":"e_1_2_1_67_1","volume-title":"Adaptive software search toward users","author":"Liu Jinze","unstructured":"Jinze Liu, Zhixing Li, Tao Wang, Yue Yu, and Gang Yin. 2018. Adaptive software search toward users\u2019 customized requirements in GitHub.. In SEKE. 143\u2013142."},{"key":"e_1_2_1_68_1","volume-title":"Unveil the Mystery of Critical Software Vulnerabilities. In Companion Proceedings of the 32nd ACM International Conference on the Foundations of Software Engineering. 138\u2013149","author":"Pan Shengyi","year":"2024","unstructured":"Shengyi Pan, Lingfeng Bao, Jiayuan Zhou, Xing Hu, Xin Xia, and Shanping Li. 2024. Unveil the Mystery of Critical Software Vulnerabilities. In Companion Proceedings of the 32nd ACM International Conference on the Foundations of Software Engineering. 138\u2013149."},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2021.106665"},{"key":"e_1_2_1_70_1","volume-title":"2019 12th IEEE Conference on software testing, validation and verification (ICST). 68\u201378","author":"Piantadosi Valentina","year":"2019","unstructured":"Valentina Piantadosi, Simone Scalabrino, and Rocco Oliveto. 2019. Fixing of security vulnerabilities in open source projects: A case study of apache http server and apache tomcat. In 2019 12th IEEE Conference on software testing, validation and verification (ICST). 68\u201378."},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1177\/1548512919874129"},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576039"},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180250"},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2023.3243262"},{"key":"e_1_2_1_75_1","volume-title":"Proceedings of the 44th International Conference on Software Engineering. 274\u2013286","author":"Wessel Mairieli","year":"2022","unstructured":"Mairieli Wessel, Ahmad Abdellatif, Igor Wiese, Tayana Conte, Emad Shihab, Marco A Gerosa, and Igor Steinmacher. 2022. Bots for pull requests: The good, the bad, and the promising. In Proceedings of the 44th International Conference on Software Engineering. 274\u2013286."},{"key":"e_1_2_1_76_1","volume-title":"Proceedings of the ACM on Human-Computer Interaction, 5, CSCW2","author":"Wessel Mairieli","year":"2021","unstructured":"Mairieli Wessel, Igor Wiese, Igor Steinmacher, and Marco Aurelio Gerosa. 2021. Don\u2019t disturb me: Challenges of interacting with software bots on open source software projects. Proceedings of the ACM on Human-Computer Interaction, 5, CSCW2 (2021), 1\u201321."},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00095"},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE56229.2023.00058"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00212"},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534387"},{"key":"e_1_2_1_81_1","volume-title":"Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering. 1\u201313","author":"Zhou Xin","year":"2024","unstructured":"Xin Zhou, Kisub Kim, Bowen Xu, DongGyun Han, and David Lo. 2024. Out of Sight, Out of Mind: Better Automatic Vulnerability Repair by Broadening Input Ranges and Sources. In Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering. 1\u201313."},{"key":"e_1_2_1_82_1","article-title":"A Comprehensive Study on Static Application Security Testing (SAST) Tools for Android","author":"Zhu Jingyun","year":"2024","unstructured":"Jingyun Zhu, Kaixuan Li, Sen Chen, Lingling Fan, and Xiaofei Xie. 2024. A Comprehensive Study on Static Application Security Testing (SAST) Tools for Android. IEEE Transactions on Software Engineering.","journal-title":"IEEE Transactions on Software Engineering."}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3728977","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,16]],"date-time":"2025-07-16T16:46:37Z","timestamp":1752684397000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3728977"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,22]]},"references-count":82,"journal-issue":{"issue":"ISSTA","published-print":{"date-parts":[[2025,6,22]]}},"alternative-id":["10.1145\/3728977"],"URL":"https:\/\/doi.org\/10.1145\/3728977","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,22]]}}}