On the use of github actions in software development repositories

A Decan, T Mens, PR Mazrae… - 2022 IEEE International …, 2022 - ieeexplore.ieee.org
GitHub Actions was introduced in 2019 and constitutes an integrated alternative to CI/CD
services for GitHub repositories. The deep integration with GitHub allows repositories to …

On the impact of security vulnerabilities in the npm and RubyGems dependency networks

A Zerouali, T Mens, A Decan, C De Roover - Empirical Software …, 2022 - Springer
The increasing interest in open source software has led to the emergence of large language-
specific package distributions of reusable software libraries, such as npm and RubyGems …

On the outdatedness of workflows in the GitHub Actions ecosystem

A Decan, T Mens, HO Delicheh - Journal of Systems and Software, 2023 - Elsevier
GitHub Actions was introduced as a way to automate CI/CD workflows in GitHub, the largest
social coding platform. Thanks to its deep integration into GitHub, GitHub Actions can be …

Chronos: Time-aware zero-shot identification of libraries from vulnerability reports

Y Lyu, T Le-Cong, HJ Kang, R Widyasari… - 2023 IEEE/ACM 45th …, 2023 - ieeexplore.ieee.org
Tools that alert developers about library vulnerabilities depend on accurate, up-to-date
vulnerability databases which are maintained by security researchers. These databases …

Modeling interconnected social and technical risks in open source software ecosystems

W Schueller, J Wachs - Collective Intelligence, 2024 - journals.sagepub.com
Open source software ecosystems consist of thousands of interdependent libraries, which
users can combine to great effect. Recent work has pointed out two kinds of risks in these …

Latency-Aware Container Scheduling in Edge Cluster Upgrades: A Deep Reinforcement Learning Approach

H Cui, Z Tang, J Lou, W Jia… - IEEE Transactions on …, 2024 - ieeexplore.ieee.org
In Mobile Edge Computing (MEC), Internet of Things (IoT) devices offload computationally-
intensive tasks to edge nodes, where they are executed within containers, reducing the …

[PDF][PDF] A Preliminary Study of GitHub Actions Dependencies.

HO Delicheh, A Decan, T Mens - SATToSE, 2023 - ceur-ws.org
GitHub Actions was introduced in 2019 as a software development workflow automation
tool, allowing to automate a wide range of social and technical activities in GitHub …

Where to Go Now? Finding Alternatives for Declining Packages in the npm Ecosystem

S Mujahid, DE Costa, R Abdalkareem… - 2023 38th IEEE/ACM …, 2023 - ieeexplore.ieee.org
Software ecosystems (eg, npm, PyPI) are the backbone of modern software developments.
Developers add new packages to ecosystems every day to solve new problems or provide …

Backports: Change types, challenges and strategies

D Chakroborti, KA Schneider, CK Roy - Proceedings of the 30th IEEE …, 2022 - dl.acm.org
Source code repositories allow developers to manage multiple versions (or branches) of a
software system. Pull-requests are used to modify a branch, and backporting is a regular …

Online container scheduling for low-latency iot services in edge cluster upgrade: A reinforcement learning approach

H Cui, Z Tang, J Lou, W Jia - 2023 IEEE/CIC International …, 2023 - ieeexplore.ieee.org
In Mobile Edge Computing (MEC), Internet of Things (IoT) devices offload computationally-
intensive tasks to edge nodes, where they are executed within containers, reducing the …