{"id":"W4377100930","doi":"10.1016/j.jss.2023.111752","title":"Empirical analysis of security-related code reviews in npm packages","year":2023,"lang":"en","type":"article","venue":"Journal of Systems and Software","topic":"Software Engineering Research","field":"Computer Science","cited_by":7,"is_retracted":false,"has_abstract":false,"ca_institutions":"Université du Québec à Montréal; Concordia University; University of Waterloo","funders":"","keywords":"Computer science; Code review; Software security assurance; Identification (biology); Code (set theory); Relation (database); Quality (philosophy); Domain (mathematical analysis); Risk analysis (engineering); Software engineering; Software; Computer security; Static program analysis; Software development; Security service; Information security; Database; Business; Programming language","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"codex-gemma-dda1882f352a","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.002383728,0.00009922832,0.0006757294,0.001129555,0.00002806675,0.00006692981,0.0004276386,0.00008484159,0.000004064841],"category_scores_gemma":[0.001528899,0.0000750289,0.00016747,0.003192087,0.00002716032,0.0002221136,0.0001195649,0.0002781708,0.000005916706],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.00004636249,"about_ca_system_score_gemma":0.00005610199,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.00003013022,"about_ca_topic_score_gemma":0.000009598095,"domain_scores_codex":[0.9982021,0.0001851807,0.0008133334,0.0001569157,0.0004399517,0.0002024549],"domain_scores_gemma":[0.9982201,0.0008990452,0.0003040206,0.0002803037,0.0001779261,0.0001185705],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"observational","study_design_gemma":"observational","study_design_scores_codex":[0.000006990468,0.00005459882,0.9767995,0.000479665,0.0004514426,0.0003064917,0.005786889,0.00694095,0.00006975229,0.0001361347,0.004846252,0.004121283],"study_design_scores_gemma":[0.0008827203,0.0002963511,0.9317421,0.001497271,0.0001807353,0.0001798104,0.0004484103,0.05621204,0.00004042166,0.000423146,0.00777793,0.0003190159],"study_design_candidate":"observational","study_design_consensus":"observational","genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.957126,0.01123211,0.03076962,0.0002475861,0.0003877594,0.0001508131,0.000008735137,0.00007038822,0.000007015714],"genre_scores_gemma":[0.9973247,0.001371619,0.001169731,0.00001088468,0.00003412422,0.000003742708,0.000001369016,0.000007849012,0.00007598209],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.04927109,"threshold_uncertainty_score":0.305959,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.03924305586657146,"score_gpt":0.3280759501969659,"score_spread":0.2888328943303944,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}