ICPC 2026
Sun 12 - Mon 13 April 2026 Rio de Janeiro, Brazil
co-located with ICSE 2026

The advancing threat of quantum-capable adversaries accelerates the need to locate and replace vulnerable cryptographic assets in software systems. To support this transition, Cryptography Bills of Materials (CBOMs) are becoming essential for capturing and inventorying the cryptographic footprint of software systems as increasingly demanded by regulators in critical domains. While first CBOM generation tools have emerged, they still lack reliable means to comprehend and analyze the cryptographic landscape of codebases. We present BF-CBOM, a first-of-its-kind framework for orchestrating various CBOM generators and analyzing their outputs, enabling holistic comprehension of the cryptographic posture of software projects. BF-CBOM offers a containerized environment designed to accommodate the heterogeneous toolchains of such generators, executes them on GitHub code repositories, and aggregates their outputs for comparative investigation in a unified analysis layer. Our preliminary study reveals striking discrepancies between generated CBOMs, underscoring the need for systematic evaluation. BF-CBOM supports researchers with cryptographic reports, practitioners through CI/CD integration, and tool developers by providing performance feedback relative to other generators. A demonstration video is available at https://youtu.be/-YdBPHsyymU.

Sun 12 Apr

Displayed time zone: Brasilia, Distrito Federal, Brazil change

16:00 - 17:30
Session 3 - Tools and Interfaces for Software AnalysisEarly Research Achievements (ERA) / Replications and Negative Results (RENE) / Tool Demonstration / ICPC Program / Research Track at Europa II
Chair(s): Nicole Novielli University of Bari
16:00
10m
Talk
A Comparative Study of Dual-Monitor and Augmented-Reality Interfaces for Digital-Twin-Based Debugging
Research Track
Lucas Kreber Trier University, Nico Feld Trier University, Stephan Diehl Computer Science, University Trier, Germany, Benjamin Weyers Trier University
16:10
5m
Talk
Understanding CI/CD Workflow Runs Through Interactive and Animated Visualizations
Early Research Achievements (ERA)
Pablo Valenzuela-Toledo University of Bern, Universidad de La Frontera, Sebastiano Panichella University of Bern, Timo Kehrer University of Bern
16:15
5m
Talk
CrossLink: A Tool for Cross-Language (Java-C/C++) Code Comprehension
Tool Demonstration
Ajinkya Sawarkar Indian Institute of Technology Tirupati, Sridhar Chimalakonda Indian Institute of Technology Tirupati, Anirudh Arrepu Indian Institute of Technology Tirupati
Media Attached File Attached
16:20
5m
Talk
BF-CBOM: Uncovering Cryptographic Assets Through Comparative CBOM Analysis at Scale
Tool Demonstration
Roman Bögli University of Bern, Jonas Spieler University of Bern, Timo Kehrer University of Bern
DOI Pre-print Media Attached
16:25
5m
Talk
COBMaker - An Interactive Block-Based Programming Environment for COBOL
Tool Demonstration
Satish Pati IIT Tirupati, Raghavendra Pappu IIT Tirupati, Rahul Krishna Gaddam IIT Tirupati, Sridhar Chimalakonda Indian Institute of Technology Tirupati
Media Attached
16:30
5m
Talk
CPPJoules: An Energy Measurement Tool for C++
Tool Demonstration
Shivadharshan S Indian Institute of Technology Tirupati, Akilesh P Indian Institute of Technology Tirupati, Rajrupa Chattaraj Indian Institute of Technology Tirupati, India, Sridhar Chimalakonda Indian Institute of Technology Tirupati
Media Attached
16:35
10m
Talk
Can We Spot Energy Regressions Using Developers Tests? An Industrial Replication
Replications and Negative Results (RENE)
Louay Khrouf Berger-Levrault, Anas Shatnawi Berger-Levrault, Romain Rouvoy Univ. Lille / Inria / IUF
16:45
10m
Talk
Evaluating the use of Augmented Reality for Dependency Graph Analysis: A Controlled Experiment
Replications and Negative Results (RENE)
Juan Pablo Sandoval Alcocer Pontificia Universidad Católica de Chile, Dussan Freire-Pozo Centro de Investigación en Ciencias Exactas e Ingenierías, Universidad Católica Boliviana, Tiara Rojas-Stambuk Centro de Investigación en Ciencias Exactas e Ingenierías, Universidad Católica Boliviana, Alison Fernandez-Blanco Pontificia Universidad Católica de Chile, Leonel Merino Pontificia Universidad Católica de Chile
16:55
5m
Talk
Test Behaviors, Not Methods! Detecting Tests Obsessed by Methods
Early Research Achievements (ERA)
Andre Hora UFMG, Andy Zaidman TU Delft
Pre-print Media Attached
17:00
10m
Talk
Déjà Vu: A Replication Study on Code Smells and Faults in JavaScript Projects
Replications and Negative Results (RENE)
Kevin Pacifico University of Salerno, Giammaria Giordano University of Salerno, Valeria Pontillo Gran Sasso Science Institute, Massimiliano Di Penta University of Sannio, Italy, Damian Andrew Tamburri University of Sannio - JADS/NXP Semiconductors, Fabio Palomba University of Salerno
Link to publication
17:10
10m
Talk
Industrial Replication of COLOR: Locator Repair in Continuous Integration and Failure Patterns under UI/DOM Evolution
Replications and Negative Results (RENE)
Hilal Taha University of Luxembourg, Luxembourg, Mike Papadakis University of Luxembourg, Joel Muller BGL BNP Paribas
DOI File Attached
17:20
10m
Live Q&A
Joint QA and Discussion
ICPC Program