{"id":"W3036270494","doi":"10.1007/s10664-021-09951-x","title":"Lags in the release, adoption, and propagation of npm vulnerability fixes","year":2021,"lang":"en","type":"article","venue":"Empirical Software Engineering","topic":"Information and Cyber Security","field":"Computer Science","cited_by":56,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"Japan Society for the Promotion of Science","keywords":"Vulnerability (computing); Empirical research; Vulnerability assessment; Software release life cycle; Software","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.00612719,0.0003371657,0.0002385902,0.00279905,0.0005388293,0.001793185,0.0006785518,0.0005433052,0.002502946],"category_scores_gemma":[0.080709,0.0004327946,0.0002745829,0.00214561,0.0008582196,0.002252925,0.001250449,0.001850798,0.0005273364],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0008803575,"about_ca_system_score_gemma":0.0007297366,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.00480011,"about_ca_topic_score_gemma":0.006686732,"domain_scores_codex":[0.9950475,0.001005586,0.0005824761,0.001102434,0.001805046,0.0004571707],"domain_scores_gemma":[0.8436761,0.08021709,0.05020161,0.01010385,0.01242766,0.003373737],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"observational","study_design_gemma":"observational","study_design_scores_codex":[0.0001474889,0.0001184473,0.9603855,0.0001243574,0.00006503028,0.0004512684,0.003459939,0.002028776,0.003221608,0.0009985489,0.0008893016,0.02810967],"study_design_scores_gemma":[0.000007086343,0.0001572716,0.9901041,0.00006108201,0.0000220125,0.0003192835,0.002102026,0.003556782,0.001202645,0.0005091762,0.001924584,0.00003393351],"study_design_candidate":"observational","study_design_consensus":"observational","genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.9964606,0.0002135959,0.001449687,0.0001361261,0.0000127631,0.00002235655,0.0003027399,0.00009207933,0.001310155],"genre_scores_gemma":[0.9982824,0.00009381554,0.0008703715,0.00002282524,0.000009412539,0.00001531314,0.000309985,0.00002548443,0.0003703791],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.00612719,"threshold_uncertainty_score":0.03240407,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01449119628158609,"score_gpt":0.246677101234731,"score_spread":0.2321859049531449,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}