{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T11:01:15Z","timestamp":1785495675502,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T00:00:00Z","timestamp":1776038400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"CAPES","award":["0001"],"award-info":[{"award-number":["0001"]}]},{"name":"FAPERJ","award":["E-26\/204.268\/2024"],"award-info":[{"award-number":["E-26\/204.268\/2024"]}]},{"name":"FAPERJ","award":["E-26\/260.168\/2026"],"award-info":[{"award-number":["E-26\/260.168\/2026"]}]},{"DOI":"10.13039\/501100012461","name":"CNPQ","doi-asserted-by":"publisher","award":["444956\/2024-7"],"award-info":[{"award-number":["444956\/2024-7"]}],"id":[{"id":"10.13039\/501100012461","id-type":"DOI","asserted-by":"publisher"}]},{"name":"CNPQ","award":["424622\/2021-1"],"award-info":[{"award-number":["424622\/2021-1"]}]},{"name":"CNPQ","award":["315106\/2023-9"],"award-info":[{"award-number":["315106\/2023-9"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,13]]},"DOI":"10.1145\/3793302.3793360","type":"proceedings-article","created":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T10:42:54Z","timestamp":1785494574000},"page":"311-322","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Characterizing and Modeling the GitHub Security Advisories Review Pipeline"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-4101-4191","authenticated-orcid":false,"given":"Claudio Marcos Durand","family":"Segal","sequence":"first","affiliation":[{"name":"Institute of Computing, UFF, Niteroi, RJ, Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-3265-3047","authenticated-orcid":false,"given":"Paulo Marcos Durand","family":"Segal","sequence":"additional","affiliation":[{"name":"Institute of Computing, UFF, Niteroi, RJ, Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1576-3863","authenticated-orcid":false,"given":"Carlos Eduardo de Schuller","family":"Banjar","sequence":"additional","affiliation":[{"name":"Institute of Computing, UFRJ, Rio de Janeiro, RJ, Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-7370-5478","authenticated-orcid":false,"given":"Felipe de Sant'Anna","family":"Paix\u00e3o","sequence":"additional","affiliation":[{"name":"Institute of Computing, UFBA, Salvador, BA, Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8325-8773","authenticated-orcid":false,"given":"Hudson","family":"Borges","sequence":"additional","affiliation":[{"name":"UFMS, Campo Grande, MS, Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0197-8249","authenticated-orcid":false,"given":"Paulo Silveira","family":"Neto","sequence":"additional","affiliation":[{"name":"Federal University Rural of Pernambuco, Recife, PE, Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9312-6715","authenticated-orcid":false,"given":"Eduardo","family":"Santana de Almeida","sequence":"additional","affiliation":[{"name":"Institute of Computing, Federal University of Bahia (UFBA), Salvador, BA, Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8743-2516","authenticated-orcid":false,"given":"Joanna C.S.","family":"Santos","sequence":"additional","affiliation":[{"name":"University of Notre Dame, South Bend, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2549-9146","authenticated-orcid":false,"given":"Anton","family":"Kocheturov","sequence":"additional","affiliation":[{"name":"Siemens, Princeton, NJ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-2755-629X","authenticated-orcid":false,"given":"Gaurav Kumar","family":"Srivastava","sequence":"additional","affiliation":[{"name":"Siemens, Princeton, NJ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8953-4003","authenticated-orcid":false,"given":"Daniel Sadoc","family":"Menasch\u00e9","sequence":"additional","affiliation":[{"name":"Institute of Computing, UFRJ, Rio de Janeiro, Rio de Janeiro, Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,7,31]]},"reference":[{"key":"e_1_3_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSCI51800.2020.00044"},{"key":"e_1_3_3_2_3_2","first-page":"1","volume-title":"Proceedings of the 15th ACM\/IEEE international symposium on empirical software engineering and measurement (ESEM)","author":"Alexopoulos Nikolaos","year":"2021","unstructured":"Nikolaos Alexopoulos, Andrew Meneely, Dorian Arnouts, and Max M\u00fchlh\u00e4user. 2021. Who are vulnerability reporters? A large-scale empirical study on FLOSS. In Proceedings of the 15th ACM\/IEEE international symposium on empirical software engineering and measurement (ESEM). 1\u201312."},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"crossref","unstructured":"Luca Allodi Marco Cremonini Fabio Massacci and Woohyun Shim. 2020. Measuring the accuracy of software vulnerability assessments: experiments with students and professionals. Empirical Software Engineering 25 2 (2020) 1063\u20131094.","DOI":"10.1007\/s10664-019-09797-4"},{"key":"e_1_3_3_2_5_2","doi-asserted-by":"crossref","unstructured":"Luca Allodi and Fabio Massacci. 2017. Security events and vulnerability data for cybersecurity risk estimation. Risk Analysis 37 8 (2017) 1606\u20131627.","DOI":"10.1111\/risa.12864"},{"key":"e_1_3_3_2_6_2","doi-asserted-by":"crossref","unstructured":"Ashish Arora Ramayya Krishnan Rahul Telang and Yubao Yang. 2010. An empirical analysis of software vendors\u2019 patch release behavior: impact of vulnerability disclosure. Information Systems Research 21 1 (2010) 115\u2013132.","DOI":"10.1287\/isre.1080.0226"},{"key":"e_1_3_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00063"},{"key":"e_1_3_3_2_8_2","volume-title":"Proceedings of the 45th IEEE Symposium on Security and Privacy (S&P)","author":"Ayala Jessy","year":"2024","unstructured":"Jessy Ayala, Yu-Jye Tung, and Joshua Garcia. 2024. Poster: A glimpse of vulnerability disclosure behaviors and practices using GitHub projects. In Proceedings of the 45th IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_3_2_9_2","first-page":"2105","volume-title":"34th USENIX Security Symposium (USENIX Security 25)","author":"Ayala Jessy","year":"2025","unstructured":"Jessy Ayala, Yu-Jye Tung, and Joshua Garcia. 2025. A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features. In 34th USENIX Security Symposium (USENIX Security 25). 2105\u20132124."},{"key":"e_1_3_3_2_10_2","unstructured":"Jessy Ayala Yu-Jye Tung and Joshua Garcia. 2025. Investigating Vulnerability Disclosures in Open-Source Software Using Bug Bounty Reports and Security Advisories. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2501.17748 (2025)."},{"key":"e_1_3_3_2_11_2","doi-asserted-by":"crossref","unstructured":"Hudson Borges and Marco\u00a0Tulio Valente. 2018. What\u2019s in a GitHub star? understanding repository starring practices in a social coding platform. Journal of Systems and Software 146 (2018) 112\u2013129.","DOI":"10.1016\/j.jss.2018.09.016"},{"key":"e_1_3_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/1835804.1835821"},{"key":"e_1_3_3_2_13_2","doi-asserted-by":"crossref","unstructured":"Valerio Cosentino Javier L\u00a0C\u00e1novas Izquierdo and Jordi Cabot. 2017. A systematic mapping study of software development with GitHub. Ieee access 5 (2017) 7173\u20137192.","DOI":"10.1109\/ACCESS.2017.2682323"},{"key":"e_1_3_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3196398.3196401"},{"key":"e_1_3_3_2_15_2","unstructured":"Jonathan Evans. 2025. GitHub Advisory Database by the numbers: Known security vulnerabilities and what you can do about them. https:\/\/github.blog\/security\/github-advisory-database-by-the-numbers-known-security-vulnerabilities-and-what-you-can-do-about-them\/ Accessed: 2025-09-30."},{"key":"e_1_3_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2010.5463340"},{"key":"e_1_3_3_2_17_2","unstructured":"GitHub. 2025. GitHub Advisory Database: Security vulnerability database inclusive of CVEs and GitHub-originated security advisories. https:\/\/github.com\/advisories See also https:\/\/github.com\/github\/advisory-database and https:\/\/docs.github.com\/en\/code-security\/security-advisories\/working-with-repository-security-advisories\/about-repository-security-advisories. Accessed: 2025-08-18."},{"key":"e_1_3_3_2_18_2","unstructured":"GitHub Blog. 2021. Advisory Database now includes an Unreviewed Advisories section. https:\/\/github.blog\/changelog\/2021-12-16-advisory-database-now-includes-an-unreviewed-advisories-section\/ Accessed: 2025-09-12."},{"key":"e_1_3_3_2_19_2","unstructured":"GitHub Blog. 2022. All historical NVD advisories are now listed on GitHub. https:\/\/github.blog\/changelog\/2022-06-08-all-historical-nvd-advisories-are-now-listed-on-github\/ Accessed: 2025-09-12."},{"key":"e_1_3_3_2_20_2","unstructured":"GitHub Blog. 2023. Security advisories now have multiple types of credits. https:\/\/github.blog\/changelog\/2023-03-07-security-advisories-now-have-multiple-types-of-credits\/ Accessed: 2025-10-16."},{"key":"e_1_3_3_2_21_2","unstructured":"GitHub Docs. 2025. About credits for repository security advisories. https:\/\/docs.github.com\/en\/code-security\/security-advisories\/working-with-repository-security-advisories\/creating-a-repository-security-advisory#about-credits-for-repository-security-advisories Accessed: 2025-10-20."},{"key":"e_1_3_3_2_22_2","unstructured":"GitHub Docs. 2025. About Dependabot alerts. https:\/\/docs.github.com\/en\/code-security\/dependabot\/dependabot-alerts\/about-dependabot-alerts Accessed: 2025-10-16."},{"key":"e_1_3_3_2_23_2","unstructured":"GitHub Docs. 2025. About the GitHub Advisory Database. https:\/\/docs.github.com\/en\/code-security\/security-advisories\/working-with-global-security-advisories-from-the-github-advisory-database\/about-the-github-advisory-database Accessed: 2025-10-16."},{"key":"e_1_3_3_2_24_2","unstructured":"GitHub Docs. 2025. REST API endpoints for global security advisories. https:\/\/docs.github.com\/en\/rest\/security-advisories\/global-advisories?apiVersion=2022-11-28#list-global-security-advisories Acessed: 2025-08-29."},{"key":"e_1_3_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781139226424"},{"key":"e_1_3_3_2_26_2","doi-asserted-by":"crossref","unstructured":"Runzhi He Hao He Yuxia Zhang and Minghui Zhou. 2023. Automating dependency updates in practice: An exploratory study on GitHub Dependabot. IEEE Transactions on Software Engineering 49 8 (2023) 4004\u20134022.","DOI":"10.1109\/TSE.2023.3278129"},{"key":"e_1_3_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/SANER64311.2025.00076"},{"key":"e_1_3_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR52588.2021.00054"},{"key":"e_1_3_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134072"},{"key":"e_1_3_3_2_30_2","unstructured":"Shuhan Liu Jiayuan Zhou Xing Hu Filipe\u00a0Roseiro Cogo Xin Xia and Xiaohu Yang. 2025. An empirical study on vulnerability disclosure management of open source software systems. ACM Transactions on Software Engineering and Methodology (2025)."},{"key":"e_1_3_3_2_31_2","doi-asserted-by":"publisher","unstructured":"B.\u00a0F. Logan and L.\u00a0A. Shepp. 1977. A variational problem for random Young tableaux. Advances in Mathematics 26 2 (1977) 206\u2013222. 10.1016\/0001-8708(77)90030-5","DOI":"10.1016\/0001-8708(77)90030-5"},{"key":"e_1_3_3_2_32_2","doi-asserted-by":"publisher","unstructured":"Lucas Miranda Daniel Vieira Leandro Aguiar Daniel Menasch\u00e9 Miguel\u00a0Angelo Bicudo Mateus Nogueira Matheus Martins Leonardo Ventura Lucas Senos and Enrico Lovat. 2021. On the Flow of Software Security Advisories. IEEE Transactions on Network and Service Management PP (05 2021) 1\u20131. 10.1109\/TNSM.2021.3078727","DOI":"10.1109\/TNSM.2021.3078727"},{"key":"e_1_3_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2017.8115621"},{"key":"e_1_3_3_2_34_2","unstructured":"MITRE Corporation. 2023. CNA Rules and CVE Program Governance. https:\/\/www.cve.org\/resourcessupport\/allresources\/cnarules. Accessed: 2025-10-23."},{"key":"e_1_3_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.48"},{"key":"e_1_3_3_2_36_2","unstructured":"NIST. 2025. NVD - Home. https:\/\/nvd.nist.gov\/. [Accessed 23-10-2025]."},{"key":"e_1_3_3_2_37_2","unstructured":"OSSF. 2025. OpenSSF Scorecard Checks. https:\/\/github.com\/ossf\/scorecard\/blob\/main\/docs\/checks.md Accessed: 2025-10-19."},{"key":"e_1_3_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR59073.2023.00073"},{"key":"e_1_3_3_2_39_2","doi-asserted-by":"crossref","unstructured":"Serena\u00a0Elisa Ponta Henrik Plate and Antonino Sabetta. 2020. Detection assessment and mitigation of vulnerabilities in open source dependencies. Empirical Software Engineering 25 5 (2020) 3175\u20133215.","DOI":"10.1007\/s10664-020-09830-x"},{"key":"e_1_3_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR59073.2023.00056"},{"key":"e_1_3_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00215"},{"key":"e_1_3_3_2_42_2","doi-asserted-by":"crossref","unstructured":"Rahul Telang and Sunil Wattal. 2007. An empirical analysis of the impact of software vulnerability announcements on firm stock price. IEEE Transactions on Software engineering 33 8 (2007) 544\u2013557.","DOI":"10.1109\/TSE.2007.70712"},{"key":"e_1_3_3_2_43_2","unstructured":"Saad Ullah Praneeth Balasubramanian Wenbo Guo Amanda Burnett Hammond Pearce Christopher Kruegel Giovanni Vigna and Gianluca Stringhini. 2025. From CVE Entries to Verifiable Exploits: An Automated Multi-Agent Framework for Reproducing CVEs. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2509.01835 (2025)."},{"key":"e_1_3_3_2_44_2","unstructured":"A.\u00a0M. Vershik and S.\u00a0V. Kerov. 1977. Asymptotics of the Plancherel measure of the symmetric group and the limit form of Young tableaux. Soviet Mathematics Doklady 18 (1977) 527\u2013531."},{"key":"e_1_3_3_2_45_2","doi-asserted-by":"crossref","unstructured":"Brandon Wang Xiaoye Li Leandro\u00a0P de Aguiar Daniel\u00a0S Menasche and Zubair Shafiq. 2017. Characterizing and modeling patching practices of industrial control systems. Proceedings of the ACM on Measurement and Analysis of Computing Systems 1 1 (2017) 1\u201323.","DOI":"10.1145\/3084455"},{"key":"e_1_3_3_2_46_2","doi-asserted-by":"publisher","unstructured":"H.\u00a0W. Wendt. 1972. Dealing with a common problem in Social Science: A simplified rank\u2010biserial coefficient of correlation based on the U statistic. European Journal of Social Psychology 2 4 (1972) 463\u2013465. 10.1002\/ejsp.2420020412","DOI":"10.1002\/ejsp.2420020412"},{"key":"e_1_3_3_2_47_2","first-page":"995","volume-title":"28th USENIX Security symposium (USENIX security 19)","author":"Zimmermann Markus","year":"2019","unstructured":"Markus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, and Michael Pradel. 2019. Small world with high risks: A study of security threats in the npm ecosystem. In 28th USENIX Security symposium (USENIX security 19). 995\u20131010."}],"event":{"name":"MSR '26: 23rd International Conference on Mining Software Repositories","location":"Rio de Janeiro Brazil","acronym":"MSR '26","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 23rd International Conference on Mining Software Repositories"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3793302.3793360","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T10:46:29Z","timestamp":1785494789000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3793302.3793360"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,13]]},"references-count":46,"alternative-id":["10.1145\/3793302.3793360","10.1145\/3793302"],"URL":"https:\/\/doi.org\/10.1145\/3793302.3793360","relation":{},"subject":[],"published":{"date-parts":[[2026,4,13]]},"assertion":[{"value":"2026-07-31","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}