← All news

Dec 2024

Security reporting study accepted at SANER 2025

Security reporting study accepted at SANER 2025

Sushawapak Kancharoendee, Thanat Phichitphanphong, and Chanikarn Jongyingyos had their paper “On Categorizing Open Source Software Security Vulnerability Reporting Mechanisms on GitHub” accepted in the ERA track of SANER 2025. The study grew from their summer internship at NAIST. It examined 679 open-source projects to see how they ask people to report security vulnerabilities. Email is still the main reporting channel, and projects without a SECURITY.md file tend to be less secure, with lower OpenSSF scores. Many maintainers ask for private reporting, but some contributors still disclose vulnerabilities in public.

Paper

Sushawapak Kancharoendee, Thanat Phichitphanphong, Chanikarn Jongyingyos, Brittany Reid, Raula Gaikovina Kula, Morakot Choetkiertikul, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta
SANER 2025, ERA Track

← All news