Skip to content
Book Open access

Towards Efficient and Secure Pull-Request-Based Software Development

Jul 2026 · SIGSOFT FSE Companion · pp. 5-8 · 0 citations · 18 references
Computer Science

TL;DR

This thesis provides actionable guidance for reducing PR delays by characterizing and improving key efficiency bottlenecks, and offers recommendations for improving vulnerability management by developing an LLM-based, low-noise, evidence-driven security alert system.

Abstract

Pull-request-based development (PBD) is the dominant workflow in modern open-source software (OSS), where pull requests (PRs) are the central coordination unit for review, CI/CD validation, and fixing security vulnerabilities. Existing research studies PR responsiveness, CI/CD performance, and vulnerability handling in isolation, even though delays and security risks accumulate through the same PR-mediated workflow. To address this gap, this thesis treats PBD as a unified workflow and investigates how suboptimal PR management creates avoidable PR delays and increased security risk. We provide empirical evidence and tools to address these coupled outcomes. Overall, the thesis connects efficiency and security through one PR-based workflow. It provides actionable guidance for reducing PR delays by characterizing and improving key efficiency bottlenecks, and offers recommendations for improving vulnerability management by developing an LLM-based, low-noise, evidence-driven security alert system.

Read PDF

Similar papers

Open access Jul 2026

Implementation of NFtables and Fail2ban on Linux Server for Adaptive Defense Firewall Development

Linux server security management today faces the challenges of command-line configuration complexity and slow response to automated attacks. This research aims to develop a prototype of an Adaptive Defense Firewall web application that integrates firewalld, nftables, and fail2ban centrally. The importance of this resea...

Prasetyo Purnomo, Juarisman, Irma Suwarning Widyastuty et al. · 0 citations
Review Open access Aug 2026

Securing CI/CD Pipelines: A DevSecOps Framework for Preventing Credential Leaks and Misconfigurations

This study investigates security risks in Dock-er-based GitHub Actions workflows and proposes a tailored, DevSecOps-aligned security checklist to mitigate these threats, offering practical protection against supply-chain threats while preserving delivery speed and scalability.

A. Amirova · 0 citations
#software testing Open access Aug 2026

HawkEye: Web Vulnerability Analysis and Security Audit Tool

HawkEye is introduced, a modular, web-based vulnerability auditing platform designed to streamline security analysis by integrating multiple scanning tools within a unified dashboard and illustrates how consolidated reporting improves vulnerability prioritization for development teams.

D. R. Patil, Varad Salgare, Devaj Arya et al. · 0 citations
Open access Jul 2026

Empirical Evaluation of a DevSecOps Proxy Pipeline for Multi-Tier Web Applications

This research proposes the evaluation of a “proxy” DevSecOps pipeline, defined as an automated intermediary architecture that decouples intensive security scanning from the primary build flow to prevent bottlenecks and demonstrates that security validation is the most time-intensive part of the automated proxy workflow...

Abderrahim Rida, A. Bakhil, Ayoub Ait Lahcen · 0 citations
Preprint Sep 2026

Measuring the Security of the Evolving Software Supply Chain: a Research Agenda

Software supply chain security has become increasingly critical due to the widespread reliance on third-party dependencies and the growing attack surface of modern software ecosystems. However, existing quantitative, measurement-based analysis and vulnerability management approaches remain largely fragmented and ecosys...

Sarah Meriem Ourari · 0 citations
Review Open access Jul 2026

Secure CI/CD Hardening with Jenkins, BitBucket and JFrog in Zero-Trust DevOps

The idea of secure environments of continuous integration and continuous delivery has emerged as an object of study due to the fact that current delivery pipelines concentrate privileged automation, dependency resolution, artifact handling, and release control within a small number of highly interconnected systems. Thi...

Ratan Raj Anandeshi · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.