Software security in open source development: A systematic literature review

Author(s):  
Shao-Fang Wen
IEEE Access ◽  
2020 ◽  
Vol 8 ◽  
pp. 94594-94609
Author(s):  
Victor Rea Sanchez ◽  
Pablo Neira Ayuso ◽  
Jose A. Galindo ◽  
David Benavides

SpringerPlus ◽  
2016 ◽  
Vol 5 (1) ◽  
Author(s):  
Adewole Adewumi ◽  
Sanjay Misra ◽  
Nicholas Omoregbe ◽  
Broderick Crawford ◽  
Ricardo Soto

2021 ◽  
Vol 11 (4) ◽  
pp. 4931-4945
Author(s):  
Dhaval Anjaria ◽  
Mugdha Kulkarni

Adopting DevOps means increased collaboration between development and operations teams and faster release cycles through a shift to automation. Using Dev Ops brings with it several advantages in the development of software. Security, however, is often neglected in DevOps due to the fast release cycle. Therefore Dev Sec Ops has emerged as an extension to DevOps that attempts to integrate security with Dev Ops practices, which is not without its challenges. DevOps, and by extension Dev Sec Ops, represents a significant change in the culture, tooling, and processes used in software development. Therefore, when implementing DevSecOps, teams and their organizations need to be aware of the challenges it brings and how to address those challenges for a DevSecOps implementation to be effective. Literature on DevSecOps exists that outlines practices and principles to do this. This paper uses a grounded theory approach to do a systematic literature review of academic literature to find the factors that contribute to an effective DevSecOps implementation. It attempts to reconcile the challenges of DevSecOps with ways of mitigating them and the advantages that a DevSecOps implementation can bring. The paper thus outlines methods of effectively implementing DevSecOps as described in academic literature.


Author(s):  
Mario Enrique Cueva Hurtado ◽  
Gabriela Gutierrez ◽  
Cristian Ramiro Narvaez Guillen ◽  
Francisco Javier Alvarez Pineda ◽  
Maria del Cisne Ruilova Sanchez

Author(s):  
Abdulkadir Seker ◽  
Banu Diri ◽  
Halil Arslan ◽  
Mehmet Fatih Amasyalı

GitHub is the most common code hosting and repository service for open-source software (OSS) projects. Thanks to the great variety of features, researchers benefit from GitHub to solve a wide range of OSS development challenges. In this context, the authors thought that was important to conduct a literature review on studies that used GitHub data. To reach these studies, they conducted this literature review based on a GitHub dataset source study instead of a keyword-based search in digital libraries. Since GHTorrent is the most widely known GitHub dataset according to the literature, they considered the studies that cite this dataset for the systematic literature review. In this study, they reviewed the selected 172 studies according to some criteria that used the dataset as a data source. They classified them within the scope of OSS development challenges thanks to the information they extract from the metadata of studies. They put forward some issues about the dataset and they offered the focused and attention-grabbing fields and open challenges that we encourage the researchers to study on them.


Sign in / Sign up

Export Citation Format

Share Document