计算机科学
软件安全保证
软件质量分析员
软件质量
软件质量控制
软件工程
风险分析(工程)
依赖关系(UML)
软件开发
软件
软件建设
计算机安全
基于构件的软件工程
软件质量管理
可靠性工程
软件维护
软件系统
工作组
脆弱性(计算)
软件包开发过程
背景(考古学)
组分(热力学)
软件质量保证
软件开发过程
验证和确认
应用程序安全性
软件度量
航空电子软件
质量(理念)
漏洞管理
自动化
作者
Seongkyoon Jeong,Eunae Yoo
标识
DOI:10.1287/msom.2024.0827
摘要
Problem definition: For software products, a significant quality concern is security vulnerabilities in external software components that offer prebuilt functionalities (i.e., dependencies). If a dependency with a vulnerability (i.e., vulnerable dependency) is exploited by hackers, it can compromise and cause operational disruptions for all downstream software products relying on it. To ensure the quality and security of their software products, developers must promptly resolve each vulnerable dependency that their software uses (e.g., by updating the vulnerable version to a safe version). One promising strategy to expedite this process is automation. We investigate how the adoption of an automated dependency management tool called Dependabot improves the resolution speed of vulnerable dependencies. Methodology/results: Through the analysis of 1,963,957 JavaScript open-source software packages, we identified 476,738 instances of vulnerable dependencies. Our findings from survival analysis models reveal that packages adopting Dependabot exhibit a 2.499 times higher resolution hazard and, thus, are 60% faster at resolving vulnerable dependencies. However, automation may not be a panacea for addressing defective software components. Surprisingly, even among Dependabot adopters, vulnerable dependencies are not addressed immediately, with the median resolution time being 82 days. We unpack why automation’s benefits are bounded in this context and show that whereas Dependabot mitigates attention-related constraints by reengaging developers with stale or inactive packages, delays can persist because of human-driven constraints, such as slow processing of proposed code modifications and complexity of verifying compatibility with other components. Managerial implications: Our results shed light on how automation can be harnessed to better safeguard the quality of external components in software products and provide guidance for overcoming technical and human impediments that limit its impact. Supplemental Material: The e-companion is available at https://doi.org/10.1287/msom.2024.0827 .
科研通智能强力驱动
Strongly Powered by AbleSci AI