{"id":"W4377100930","doi":"10.1016/j.jss.2023.111752","title":"Empirical analysis of security-related code reviews in npm packages","year":2023,"lang":"en","type":"article","venue":"Journal of Systems and Software","topic":"Software Engineering Research","field":"Computer Science","cited_by":7,"is_retracted":false,"has_abstract":false,"ca_institutions":"Université du Québec à Montréal; Concordia University; University of Waterloo","funders":"","keywords":"Computer science; Code review; Software security assurance; Identification (biology); Code (set theory); Relation (database); Quality (philosophy); Domain (mathematical analysis); Risk analysis (engineering); Software engineering; Software; Computer security; Static program analysis; Software development; Security service; Information security; Database; Business; Programming language","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":["metaresearch"],"consensus_categories":[],"category_scores_codex":[0.0115685,0.0002725441,0.0003562699,0.005039479,0.0009296533,0.00158116,0.001279063,0.001325971,0.004106306],"category_scores_gemma":[0.2597802,0.0003567504,0.0005522191,0.003330486,0.001301939,0.002110102,0.001426871,0.002003402,0.0008655071],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.002042593,"about_ca_system_score_gemma":0.002887141,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.007769111,"about_ca_topic_score_gemma":0.01279342,"domain_scores_codex":[0.9844828,0.006554992,0.001296395,0.001530117,0.00525953,0.000876162],"domain_scores_gemma":[0.4308068,0.3797252,0.1288755,0.00933326,0.04480056,0.006458571],"domain_codex":null,"domain_gemma":"evaluation","domain_candidate":"evaluation","domain_consensus":null,"study_design_codex":"observational","study_design_gemma":"observational","study_design_scores_codex":[0.0004652004,0.0004628998,0.9730144,0.000290072,0.0001426914,0.0002278183,0.003550278,0.0005166993,0.0006105484,0.0006527368,0.001974815,0.01809198],"study_design_scores_gemma":[0.00002093489,0.0003246995,0.9900048,0.0001673561,0.0001095523,0.0003592436,0.003562481,0.00233934,0.0006263873,0.0002401442,0.002220094,0.00002488054],"study_design_candidate":"observational","study_design_consensus":"observational","genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.9970201,0.000372801,0.0003609213,0.0002705587,0.00001327696,0.00004960825,0.000314528,0.00002176412,0.001576363],"genre_scores_gemma":[0.9985222,0.0001188322,0.0002856088,0.00007699985,0.00001638102,0.00004578919,0.000280415,0.0000209613,0.0006328261],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.9884315,"threshold_uncertainty_score":0.06118083,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.03924305586657146,"score_gpt":0.3280759501969659,"score_spread":0.2888328943303944,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}