This thesis provides actionable guidance for reducing PR delays by characterizing and improving key efficiency bottlenecks, and offers recommendations for improving vulnerability management by developing an LLM-based, low-noise, evidence-driven security alert system.
Abstract
Pull-request-based development (PBD) is the dominant workflow in modern open-source software (OSS), where pull requests (PRs) are the central coordination unit for review, CI/CD validation, and fixing security vulnerabilities. Existing research studies PR responsiveness, CI/CD performance, and vulnerability handling in isolation, even though delays and security risks accumulate through the same PR-mediated workflow. To address this gap, this thesis treats PBD as a unified workflow and investigates how suboptimal PR management creates avoidable PR delays and increased security risk. We provide empirical evidence and tools to address these coupled outcomes. Overall, the thesis connects efficiency and security through one PR-based workflow. It provides actionable guidance for reducing PR delays by characterizing and improving key efficiency bottlenecks, and offers recommendations for improving vulnerability management by developing an LLM-based, low-noise, evidence-driven security alert system.
Linux server security management today faces the challenges of command-line configuration complexity and slow response to automated attacks. This research aims to develop a prototype of an Adaptive Defense Firewall web application that integrates firewalld, nftables, and fail2ban centrally. The importance of this resea...
Prasetyo Purnomo, Juarisman, Irma Suwarning Widyastuty et al.· The Indonesian Journal of Co...· 0 citations
This study investigates security risks in Dock-er-based GitHub Actions workflows and proposes a tailored, DevSecOps-aligned security checklist to mitigate these threats, offering practical protection against supply-chain threats while preserving delivery speed and scalability.
A. Amirova· International Journal of Wir...· 0 citations
HawkEye is introduced, a modular, web-based vulnerability auditing platform designed to streamline security analysis by integrating multiple scanning tools within a unified dashboard and illustrates how consolidated reporting improves vulnerability prioritization for development teams.
D. R. Patil, Varad Salgare, Devaj Arya et al.· International Journal for Re...· 0 citations
This research proposes the evaluation of a “proxy” DevSecOps pipeline, defined as an automated intermediary architecture that decouples intensive security scanning from the primary build flow to prevent bottlenecks and demonstrates that security validation is the most time-intensive part of the automated proxy workflow...
Abderrahim Rida, A. Bakhil, Ayoub Ait Lahcen· Future Internet· 0 citations
Software supply chain security has become increasingly critical due to the widespread reliance on third-party dependencies and the growing attack surface of modern software ecosystems. However, existing quantitative, measurement-based analysis and vulnerability management approaches remain largely fragmented and ecosys...
The idea of secure environments of continuous integration and continuous delivery has emerged as an object of study due to the fact that current delivery pipelines concentrate privileged automation, dependency resolution, artifact handling, and release control within a small number of highly interconnected systems. Thi...
Ratan Raj Anandeshi· International Journal of Sci...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.