← All news

Dec 2025

SECURITY.md study accepted in EMSE

SECURITY.md study accepted in EMSE

Our paper “Security by Documentation? Characterizing GitHub SECURITY.md Policy and Their Adoption in Python Libraries” has been accepted in Empirical Software Engineering (EMSE), a Q1 journal. Many open-source projects publish a SECURITY.md file that tells users how to report vulnerabilities. Earlier studies counted how many projects adopt such a policy, but they did not examine what the policies say. The study analyzed the security policies of 679 Python libraries from PyPI hosted on GitHub and found that projects with a SECURITY.md file follow recommended security practices more closely. The work grew from internship research by our bachelor's students, with partners at NAIST and The University of Osaka.

The same line of work produced a paper at SANER 2025 before this journal article. The article was published online on 6 February 2026.

Paper

Morakot Choetkiertikul, Sushawapak Kancharoendee, Chanikarn Jongyingyos, Thanat Phichitphanphong, Chaiyong Ragkhitwetsagul, Brittany Reid, Raula Gaikovina Kula, Thanwadee Sunetnanta
Empirical Software Engineering, 2026

← All news