{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T10:18:40Z","timestamp":1778667520533,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":44,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,4,12]],"date-time":"2026-04-12T00:00:00Z","timestamp":1775952000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Office of Naval Research (ONR)","award":["G2A62826"],"award-info":[{"award-number":["G2A62826"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,12]]},"DOI":"10.1145\/3786165.3788438","type":"proceedings-article","created":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T09:49:18Z","timestamp":1778665758000},"page":"9-16","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Process-based Indicators of Vulnerability Re-Introducing Code Changes: An Exploratory Case Study"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5307-8819","authenticated-orcid":false,"given":"Samiha","family":"Shimmi","sequence":"first","affiliation":[{"name":"Northern Illinois University, DeKalb, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0413-4594","authenticated-orcid":false,"given":"Nicholas M.","family":"Synovic","sequence":"additional","affiliation":[{"name":"Loyola University Chicago, Chicago, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7228-7520","authenticated-orcid":false,"given":"Mona","family":"Rahimi","sequence":"additional","affiliation":[{"name":"Northern Illinois University, DeKalb, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0452-5571","authenticated-orcid":false,"given":"George K.","family":"Thiruvathukal","sequence":"additional","affiliation":[{"name":"Loyola University Chicago, Chicago, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,5,13]]},"reference":[{"key":"e_1_3_3_2_2_2","doi-asserted-by":"publisher","unstructured":"Suliman Alazmi and Daniel\u00a0Conte De\u00a0Leon. 2022. A Systematic Literature Review on the Characteristics and Effectiveness of Web Application Vulnerability Scanners. IEEE Access 10 (2022) 33200\u201333219. doi:10.1109\/ACCESS.2022.3161522","DOI":"10.1109\/ACCESS.2022.3161522"},{"key":"e_1_3_3_2_3_2","first-page":"2105","volume-title":"34th USENIX Security Symposium (USENIX Security 25)","author":"Ayala Jessy","year":"2025","unstructured":"Jessy Ayala, Yu-Jye Tung, and Joshua Garcia. 2025. A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features. In 34th USENIX Security Symposium (USENIX Security 25). USENIX Association, Seattle, WA, 2105\u20132124. https:\/\/www.usenix.org\/conference\/usenixsecurity25\/presentation\/ayala"},{"key":"e_1_3_3_2_4_2","volume-title":"Redis Lua Use-After-Free may lead to remote code execution","author":"Isaacs Benny","year":"2025","unstructured":"Benny Isaacs, Nir Brakha, and Sagi Tzadik. 2025. Redis Lua Use-After-Free may lead to remote code execution. CVE. https:\/\/www.cve.org\/CVERecord?id=CVE-2025-49844"},{"key":"e_1_3_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/3544902.3546250"},{"key":"e_1_3_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3607199.3607242"},{"key":"e_1_3_3_2_7_2","volume-title":"Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints","author":"Zhaojun Chen","year":"2021","unstructured":"Chen Zhaojun. 2021. Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints. CVE. https:\/\/www.cve.org\/CVERecord?id=CVE-2021-44228"},{"key":"e_1_3_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2015.7081864"},{"key":"e_1_3_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSAA53316.2021.9564227"},{"key":"e_1_3_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/eScience.2018.00036"},{"key":"e_1_3_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387501"},{"key":"e_1_3_3_2_12_2","volume-title":"Software Metrics: A Rigorous and Practical Approach, Third Edition (3rd edition ed.)","author":"Fenton Norman","unstructured":"Norman Fenton and James Bieman. 201. Software Metrics: A Rigorous and Practical Approach, Third Edition (3rd edition ed.). CRC Press, Boca Raton."},{"key":"e_1_3_3_2_13_2","volume-title":"Common Vulnerability Scoring System version 4.0: Specification Document","author":"Teams Forum of Incident Response and Security","year":"2024","unstructured":"Forum of Incident Response and Security Teams. 2024. Common Vulnerability Scoring System version 4.0: Specification Document. Forum of Incident Response and Security Teams. https:\/\/www.first.org\/cvss\/v4-0\/specification-document"},{"key":"e_1_3_3_2_14_2","doi-asserted-by":"publisher","unstructured":"Thomas Fritz Gail\u00a0C. Murphy Emerson Murphy-Hill Jingwen Ou and Emily Hill. 2014. Degree-of-knowledge: Modeling a developer\u2019s knowledge of code. ACM Trans. Softw. Eng. Methodol. 23 2 (2014) 14:1\u201314:42. doi:10.1145\/2512207","DOI":"10.1145\/2512207"},{"key":"e_1_3_3_2_15_2","volume-title":"About the GitHub Advisory database","year":"2025","unstructured":"GitHub. 2025. About the GitHub Advisory database. GitHub. https:\/\/docs-internal.github.com\/en\/code-security\/security-advisories\/working-with-global-security-advisories-from-the-github-advisory-database\/about-the-github-advisory-database"},{"key":"e_1_3_3_2_16_2","volume-title":"GitHub Advisory Database","year":"2025","unstructured":"GitHub. 2025. GitHub Advisory Database. Github. https:\/\/github.com\/advisories"},{"key":"e_1_3_3_2_17_2","volume-title":"GitLab Advisory Database","year":"2025","unstructured":"GitLab. 2025. GitLab Advisory Database. https:\/\/advisories.gitlab.com\/"},{"key":"e_1_3_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/SoHeal52568.2021.00010"},{"key":"e_1_3_3_2_19_2","volume-title":"Open Source Insights","year":"2025","unstructured":"Google. 2025. Open Source Insights. https:\/\/deps.dev\/"},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2017.52"},{"key":"e_1_3_3_2_21_2","doi-asserted-by":"publisher","unstructured":"Richard Hegewald and Rebecca Beyer. 2025. Evaluating Software Supply Chain Security in Research Software. doi:10.48550\/arXiv.2508.03856 arxiv:https:\/\/arXiv.org\/abs\/2508.03856 [cs]","DOI":"10.48550\/arXiv.2508.03856"},{"key":"e_1_3_3_2_22_2","volume-title":"ImageMagick","author":"LLC ImageMagick Studio","year":"2024","unstructured":"ImageMagick Studio LLC. 2024. ImageMagick. https:\/\/imagemagick.org"},{"key":"e_1_3_3_2_23_2","doi-asserted-by":"publisher","unstructured":"Bhupinder Kaur Mathieu Dugr\u00e9 Aiman Hanna and Tristan Glatard. 2021. An analysis of security vulnerabilities in container images for scientific data analysis. 10 6 (2021) giab025. doi:10.1093\/gigascience\/giab025","DOI":"10.1093\/gigascience\/giab025"},{"key":"e_1_3_3_2_24_2","volume-title":"Community Health Analytics in Open Source Software","author":"Foundation Linux","year":"2025","unstructured":"Linux Foundation. 2025. Community Health Analytics in Open Source Software. https:\/\/chaoss.community\/"},{"key":"e_1_3_3_2_25_2","volume-title":"National Vulnerability Database","author":"Technology National Institute Of Standards And","year":"2025","unstructured":"National Institute Of Standards And Technology. 2025. National Vulnerability Database. https:\/\/nvd.nist.gov\/"},{"key":"e_1_3_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISPA-BDCloud-SocialCom-SustainCom57177.2022.00056"},{"key":"e_1_3_3_2_27_2","doi-asserted-by":"publisher","unstructured":"Yu Nong Rainy Sharma Abdelwahab Hamou-Lhadj Xiapu Luo and Haipeng Cai. 2023. Open Science in Software Engineering: A Study on Deep Learning-Based Vulnerability Detection. IEEE Transactions on Software Engineering 49 4 (2023) 1983\u20132005. doi:10.1109\/TSE.2022.3207149","DOI":"10.1109\/TSE.2022.3207149"},{"key":"e_1_3_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-38928-3_3"},{"key":"e_1_3_3_2_29_2","doi-asserted-by":"publisher","unstructured":"Ze Sheng Zhicheng Chen Shuning Gu Heqing Huang Guofei Gu and Jeff Huang. 2025. LLMs in Software Security: A Survey of Vulnerability Detection Techniques and Insights. (2025). doi:10.1145\/3769082Just Accepted.","DOI":"10.1145\/3769082"},{"key":"e_1_3_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3549035.3561181"},{"key":"e_1_3_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3549035.3561181"},{"key":"e_1_3_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.5281\/zenodo.18251736"},{"key":"e_1_3_3_2_33_2","doi-asserted-by":"crossref","unstructured":"Yonghee Shin Andrew Meneely Laurie Williams and Jason\u00a0A Osborne. 2010. Evaluating complexity code churn and developer activity metrics as indicators of software vulnerabilities. IEEE transactions on software engineering 37 6 (2010) 772\u2013787.","DOI":"10.1109\/TSE.2010.81"},{"key":"e_1_3_3_2_34_2","doi-asserted-by":"crossref","unstructured":"Jacek \u015aliwerski Thomas Zimmermann and Andreas Zeller. 2005. When do changes induce fixes? ACM sigsoft software engineering notes 30 4 (2005) 1\u20135.","DOI":"10.1145\/1082983.1083147"},{"key":"e_1_3_3_2_35_2","volume-title":"Snyk AI-powered Developer Security Platform | AI-powered AppSec Tool & Security Platform","author":"Limited Snyk","year":"2025","unstructured":"Snyk Limited. 2025. Snyk AI-powered Developer Security Platform | AI-powered AppSec Tool & Security Platform. https:\/\/snyk.io\/"},{"key":"e_1_3_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/3551349.3559517"},{"key":"e_1_3_3_2_37_2","volume-title":"Common Vulnerabilities and Exposures","author":"Corporation The MITRE","year":"2025","unstructured":"The MITRE Corporation. 2025. Common Vulnerabilities and Exposures. https:\/\/www.cve.org\/"},{"key":"e_1_3_3_2_38_2","volume-title":"CVE-2018-11625","author":"Corporation The MITRE","year":"2018","unstructured":"The MITRE Corporation. 2018. CVE-2018-11625. https:\/\/www.cve.org\/CVERecord?id=CVE-2018-11625"},{"key":"e_1_3_3_2_39_2","volume-title":"CWE-125: Out-of-bounds Read (4.18)","author":"Corporation The MITRE","year":"2025","unstructured":"The MITRE Corporation. 2025. CWE-125: Out-of-bounds Read (4.18). https:\/\/cwe.mitre.org\/data\/definitions\/125.html"},{"key":"e_1_3_3_2_40_2","doi-asserted-by":"publisher","unstructured":"George\u00a0K. Thiruvathukal Shilpika Nicholas\u00a0J. Hayward and Konstantin L\u00e4ufer. 2018. Metrics Dashboard: A Hosted Platform for Software Quality Metrics. doi:10.48550\/arXiv.1804.02053 arxiv:https:\/\/arXiv.org\/abs\/1804.02053 [cs]version: 2.","DOI":"10.48550\/arXiv.1804.02053"},{"key":"e_1_3_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833686"},{"key":"e_1_3_3_2_42_2","doi-asserted-by":"publisher","unstructured":"Nusrat Zahan Parth Kanakiya Brian Hambleton Shohanuzzaman Shohan and Laurie Williams. 2023. OpenSSF Scorecard: On the Path Toward Ecosystem-Wide Automated Security Metrics. IEEE Security & Privacy01 (June 2023) 2\u201314. doi:10.1109\/MSEC.2023.3279773Publisher: IEEE Computer Society.","DOI":"10.1109\/MSEC.2023.3279773"},{"key":"e_1_3_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510457.3513044"},{"key":"e_1_3_3_2_44_2","unstructured":"Markus Zimmermann Cristian-Alexandru Staicu Cam Tenny and Michael Pradel. 2019. Small World with High Risks: A Study of Security Threats in the npm Ecosystem. 995\u20131010. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/zimmerman"},{"key":"e_1_3_3_2_45_2","doi-asserted-by":"crossref","unstructured":"Jacek \u015aliwerski Thomas Zimmermann and Andreas Zeller. 2005. When do changes induce fixes?30 4 (2005) 1\u20135. Publisher: ACM New York NY USA.","DOI":"10.1145\/1082983.1083147"}],"event":{"name":"SVM '26: 4th International Workshop on Software Vulnerability Management","location":"Rio de Janeiro Brazil","acronym":"SVM '26","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 2026 IEEE\/ACM 4th International Workshop on Software Vulnerability Management"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3786165.3788438","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T09:49:28Z","timestamp":1778665768000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3786165.3788438"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,12]]},"references-count":44,"alternative-id":["10.1145\/3786165.3788438","10.1145\/3786165"],"URL":"https:\/\/doi.org\/10.1145\/3786165.3788438","relation":{},"subject":[],"published":{"date-parts":[[2026,4,12]]},"assertion":[{"value":"2026-05-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}