Assumptions to Evidence: Evaluating Security Practices Adoption and Their Impact on Outcomes in the npm Ecosystem
Fuente:
arXiv
Saved in:
| Main Authors: | Zahan, Nusrat, Rahman, Imranur, Williams, Laurie |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Relative Positioning Based Code Chunking Method For Rich Context Retrieval In Repository Level Code Completion Task With Code Language Model
by: Rahman, Imranur, et al.
Published: (2025)
by: Rahman, Imranur, et al.
Published: (2025)
Comparing Effectiveness and Efficiency of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) Tools in a Large Java-based System
by: Seth, Aishwarya, et al.
Published: (2023)
by: Seth, Aishwarya, et al.
Published: (2023)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
by: Rahman, Imranur, et al.
Published: (2024)
by: Rahman, Imranur, et al.
Published: (2024)
Understanding npm Developers' Practices, Challenges, and Recommendations for Secure Package Development
by: Peruma, Anthony, et al.
Published: (2026)
by: Peruma, Anthony, et al.
Published: (2026)
How Quickly Do Development Teams Update Their Vulnerable Dependencies?
by: Rahman, Imranur, et al.
Published: (2024)
by: Rahman, Imranur, et al.
Published: (2024)
Understanding and Detecting Peer Dependency Resolving Loop in npm Ecosystem
by: Wang, Xingyu, et al.
Published: (2025)
by: Wang, Xingyu, et al.
Published: (2025)
Structural Coupling for Microservices
by: Panichella, Sebastiano, et al.
Published: (2021)
by: Panichella, Sebastiano, et al.
Published: (2021)
An Exploratory Study on Automatic Identification of Assumptions in the Development of Deep Learning Frameworks
by: Yang, Chen, et al.
Published: (2024)
by: Yang, Chen, et al.
Published: (2024)
CWEval: Outcome-driven Evaluation on Functionality and Security of LLM Code Generation
by: Peng, Jinjun, et al.
Published: (2025)
by: Peng, Jinjun, et al.
Published: (2025)
Mining Temporal Attack Patterns from Cyberthreat Intelligence Reports
by: Rahman, Md Rayhanur, et al.
Published: (2024)
by: Rahman, Md Rayhanur, et al.
Published: (2024)
Can LLMs Find Bugs in Code? An Evaluation from Beginner Errors to Security Vulnerabilities in Python and C++
by: Mhatre, Akshay, et al.
Published: (2025)
by: Mhatre, Akshay, et al.
Published: (2025)
Cuvis.Ai: An Open-Source, Low-Code Software Ecosystem for Hyperspectral Processing and Classification
by: Hanson, Nathaniel, et al.
Published: (2024)
by: Hanson, Nathaniel, et al.
Published: (2024)
Analysis of Failures and Risks in Deep Learning Model Converters: A Case Study in the ONNX Ecosystem
by: Jajal, Purvish, et al.
Published: (2023)
by: Jajal, Purvish, et al.
Published: (2023)
Rethinking the Evaluation of Secure Code Generation
by: Dai, Shih-Chieh, et al.
Published: (2025)
by: Dai, Shih-Chieh, et al.
Published: (2025)
Can Hessian-Based Insights Support Fault Diagnosis in Attention-based Models?
by: Jahan, Sigma, et al.
Published: (2025)
by: Jahan, Sigma, et al.
Published: (2025)
Learning-Based Testing for Deep Learning: Enhancing Model Robustness with Adversarial Input Prioritization
by: Rahman, Sheikh Md Mushfiqur, et al.
Published: (2025)
by: Rahman, Sheikh Md Mushfiqur, et al.
Published: (2025)
Bridging the Language Gap: An Empirical Study of Bindings for Open Source Machine Learning Libraries Across Software Package Ecosystems
by: Li, Hao, et al.
Published: (2022)
by: Li, Hao, et al.
Published: (2022)
RBT4DNN: Requirements-based Testing of Neural Networks
by: Mozumder, Nusrat Jahan, et al.
Published: (2025)
by: Mozumder, Nusrat Jahan, et al.
Published: (2025)
On The Impact of Merge Request Deviations on Code Review Practices
by: Kansab, Samah, et al.
Published: (2025)
by: Kansab, Samah, et al.
Published: (2025)
Towards Enhancing the Reproducibility of Deep Learning Bugs: An Empirical Study
by: Shah, Mehil B., et al.
Published: (2024)
by: Shah, Mehil B., et al.
Published: (2024)
The Impact of Environment Configurations on the Stability of AI-Enabled Systems
by: Rahman, Musfiqur, et al.
Published: (2024)
by: Rahman, Musfiqur, et al.
Published: (2024)
Intuition to Evidence: Measuring AI's True Impact on Developer Productivity
by: Kumar, Anand, et al.
Published: (2025)
by: Kumar, Anand, et al.
Published: (2025)
Evaluating and Improving the Robustness of Security Attack Detectors Generated by LLMs
by: Pasini, Samuele, et al.
Published: (2024)
by: Pasini, Samuele, et al.
Published: (2024)
Assessing the Quality and Security of AI-Generated Code: A Quantitative Analysis
by: Sabra, Abbas, et al.
Published: (2025)
by: Sabra, Abbas, et al.
Published: (2025)
Beyond Synthetic Benchmarks: Evaluating LLM Performance on Real-World Class-Level Code Generation
by: Rahman, Musfiqur, et al.
Published: (2025)
by: Rahman, Musfiqur, et al.
Published: (2025)
Language Models for Code Completion: A Practical Evaluation
by: Izadi, Maliheh, et al.
Published: (2024)
by: Izadi, Maliheh, et al.
Published: (2024)
Fine Tuning LLM for Enterprise: Practical Guidelines and Recommendations
by: J, Mathav Raj, et al.
Published: (2024)
by: J, Mathav Raj, et al.
Published: (2024)
Whitespaces Don't Lie: Feature-Driven and Embedding-Based Approaches for Detecting Machine-Generated Code
by: Nirob, Syed Mehedi Hasan, et al.
Published: (2026)
by: Nirob, Syed Mehedi Hasan, et al.
Published: (2026)
Continuous Integration Practices in Machine Learning Projects: The Practitioners` Perspective
by: Bernardo, João Helis, et al.
Published: (2025)
by: Bernardo, João Helis, et al.
Published: (2025)
A Catalog of Fairness-Aware Practices in Machine Learning Engineering
by: Voria, Gianmario, et al.
Published: (2024)
by: Voria, Gianmario, et al.
Published: (2024)
The BrowserGym Ecosystem for Web Agent Research
by: De Chezelles, Thibault Le Sellier, et al.
Published: (2024)
by: De Chezelles, Thibault Le Sellier, et al.
Published: (2024)
Leveraging Large Language Models to Detect npm Malicious Packages
by: Zahan, Nusrat, et al.
Published: (2024)
by: Zahan, Nusrat, et al.
Published: (2024)
Applications and Challenges of Fairness APIs in Machine Learning Software
by: Das, Ajoy, et al.
Published: (2025)
by: Das, Ajoy, et al.
Published: (2025)
The State of Documentation Practices of Third-party Machine Learning Models and Datasets
by: Oreamuno, Ernesto Lang, et al.
Published: (2023)
by: Oreamuno, Ernesto Lang, et al.
Published: (2023)
PromSec: Prompt Optimization for Secure Generation of Functional Source Code with Large Language Models (LLMs)
by: Nazzal, Mahmoud, et al.
Published: (2024)
by: Nazzal, Mahmoud, et al.
Published: (2024)
Perspective of Software Engineering Researchers on Machine Learning Practices Regarding Research, Review, and Education
by: Mojica-Hanke, Anamaria, et al.
Published: (2024)
by: Mojica-Hanke, Anamaria, et al.
Published: (2024)
Practical programming research of Linear DML model based on the simplest Python code: From the standpoint of novice researchers
by: Yao, Shunxin
Published: (2025)
by: Yao, Shunxin
Published: (2025)
How do Machine Learning Projects use Continuous Integration Practices? An Empirical Study on GitHub Actions
by: Bernardo, João Helis, et al.
Published: (2024)
by: Bernardo, João Helis, et al.
Published: (2024)
Impact of ML Optimization Tactics on Greener Pre-Trained ML Models
by: Álvarez, Alexandra González, et al.
Published: (2024)
by: Álvarez, Alexandra González, et al.
Published: (2024)
Beyond Single Reports: Evaluating Automated ATT&CK Technique Extraction in Multi-Report Campaign Settings
by: Haque, Md Nazmul, et al.
Published: (2026)
by: Haque, Md Nazmul, et al.
Published: (2026)
Similar Items
-
Relative Positioning Based Code Chunking Method For Rich Context Retrieval In Repository Level Code Completion Task With Code Language Model
by: Rahman, Imranur, et al.
Published: (2025) -
Comparing Effectiveness and Efficiency of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) Tools in a Large Java-based System
by: Seth, Aishwarya, et al.
Published: (2023) -
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
by: Rahman, Imranur, et al.
Published: (2024) -
Understanding npm Developers' Practices, Challenges, and Recommendations for Secure Package Development
by: Peruma, Anthony, et al.
Published: (2026) -
How Quickly Do Development Teams Update Their Vulnerable Dependencies?
by: Rahman, Imranur, et al.
Published: (2024)