OSS 2019
Sun 26 - Mon 27 May 2019 Montreal, QC, Canada
co-located with ICSE 2019
Mon 27 May 2019 14:30 - 14:45 at Mansfield - Practitioners Session 2

The use of third-party libraries to manage software complexity can expose open source software projects to vulnerabilities. However, project owners do not currently have a standard way to enable private disclosure of potential security vulnerabilities. This neglect may be caused in part by having no template to follow for disclosing such vulnerabilities. We analyzed 600 GitHub projects to determine how many projects contained a vulnerable dependency and whether the projects had a process in place to privately communicate security issues. We found that 385 out of 600 open source Java projects contained at least one vulnerable dependency, and only 13 of those 385 projects had a security vulnerability reporting process. That is, 96.6% of the projects with a vulnerability did not have a security noti fication process in place to allow for private disclosure. In determining whether the projects even had contact information publicly available, we found that 19.8% had no contact information publicly available, let alone a security vulnerability reporting process. We suggest two methods to allow for community members to privately disclose potential security vulnerabilities.

Mon 27 May

Displayed time zone: Eastern Time (US & Canada) change

14:00 - 14:45
Practitioners Session 2OSS 2019 Papers at Mansfield
14:00
15m
Experience report
Introducing Agile Product Owners in a FLOSS Project
OSS 2019 Papers
Matthias Müller Institute of Software Technology, Graz University of Technology , Christian Schindler Institute of Software Technology, Graz University of Technology , Wolfgang Slany Institute of Software Technology, Graz University of Technology
14:15
15m
Experience report
Building an Open-Source Cross-Cloud DevOps stack for a CRM Enterprise Application: A Case Study
OSS 2019 Papers
Sebastian Schork CAS Software AG, Karlsruhe, Germany, Feroz Zahid Simula Research Laboratory, Norway, Dipesh Pradhan Simula Research Laboratory, Norway, Sébastien Kicin CAS Software AG, Karlsruhe, Germany, Antonia Schwichtenberg CAS Software AG, Karlsruhe, Germany
14:30
15m
Experience report
Open Source Vulnerability Notification
OSS 2019 Papers
Brandon Carlson University of Illinois at Urbana-Champaign, USA, Kevin Leach University of Michigan, Darko Marinov University of Illinois at Urbana-Champaign, Mei Nagappan University of Waterloo, Atul Prakash University of Michigan