ESEIW 2026
Sun 4 - Fri 9 October 2026 München, Germany

This program is tentative and subject to change.

Configuration changes — modifications to feature flags and service parameters — are important to operating services, but they can cause severe outages (SEVs) with notable service disruption. While code diff risk prediction is well studied, configuration diff risk has received little attention. The code-oriented Diff Risk Score (DRS) model provides limited discriminatory power for config diffs because config risk stems not from code complexity but from the importance, blast radius, and operational readiness of the affected services. We describe the development of CORA (COnfig R}isk Analyzer), a dedicated risk model for config diffs. A notable insight is that the config-path-to-service mapping bridges from what changed to which services are affected, enabling risk assessment in terms of service criticality rather than code properties.

CORA evolved through three iterations. A logistic regression model with config-specific features achieved an 11% improvement in recall at 5% gating over the DRS model on config diffs. Used for a freeze period, it reduced config gating while outage impact decreased 16.4% and config diff landing volume increased 47.7%. A unified LightGBM model trained on Meta-wide data achieved a 25.95% improvement in recall at 10% gating, with organization-level improvements ranging from 15% to 66%. An enhanced model with Bayesian hyperparameter optimization, SEV-severity-aware training, and enriched service features achieved a 22% improvement in recall at 15% gating with notable additional outage prevention. To our knowledge, CORA is the first system to apply predictive risk modeling specifically to configuration changes.

This program is tentative and subject to change.

Fri 9 Oct

Displayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change

14:00 - 15:30
14:00
15m
Talk
Evaluating CI/CD Security Best Practices in the GitHub Actions Documentation
ESEM - Technical Track
Lukas Boschanski University of North Carolina at Charlotte, Marco Vieira University of North Carolina at Charlotte
14:15
15m
Talk
Does Fixing Break Security? An Empirical Study of Security Degradation in Iterative LLM-Driven Infrastructure-as-Code Repair
ESEM - Technical Track
Benjamin Agyekum Colorado State University, Fabio Marcos De Abreu Santos Colorado State University, USA
14:30
15m
Talk
A Nightly Feedback-Driven Strategy for Quality Control in Safety-Critical Software Development
ESEM - Software Engineering in Practice Track
Simin Sun Chalmers University of Technology and University of Gothenburg, Peter Nemeth Zenseact, Staffan Johansson Zenseact, Theo Wiik Zenseact, David Friberg Zenseact, Farnaz Fotrousi Chalmers University of Technology and University of Gothenburg, Miroslaw Staron Chalmers University of Technology and University of Gothenburg
14:45
15m
Talk
CORA: Config Risk Analyzer --- Predicting Risk of Configuration Changes at Scale
ESEM - Software Engineering in Practice Track
Weiyan Sun Meta Platforms, Inc., Audris Mockus University of Tennessee, Nachiappan Nagappan Meta Platforms, Inc.
15:00
10m
Talk
Tools for Detecting Security Issues in Infrastructure-as-Code: A Focused Literature Review
ESEM - Emerging Results, Vision, and Reflection Papers Track
Mohamed Haady Tiemtore, Frederic Loulergue Université d'Orléans
15:10
10m
Talk
TerraRepair: A Tool-Grounded LLM Agent for Infrastructure-as-Code Repair
ESEM - Emerging Results, Vision, and Reflection Papers Track
Minase Mekete Mengistu University of L'Aquila, Juri Di Rocco University of L'Aquila, Phuong T. Nguyen University of L’Aquila, Davide Di Ruscio University of L'Aquila
Pre-print
15:20
10m
Talk
An Agentic Approach Towards Replication Package Quality Evaluation
ESEM - Emerging Results, Vision, and Reflection Papers Track
Maximilian Amougou Technical University of Munich, Florian Angermeir fortiss