{"id":"W4408797770","doi":"10.1145/3716822","title":"An empirical study on vulnerability disclosure management of open source software systems","year":2025,"lang":"en","type":"article","venue":"ACM Transactions on Software Engineering and Methodology","topic":"Information and Cyber Security","field":"Computer Science","cited_by":2,"is_retracted":false,"has_abstract":true,"ca_institutions":"Huawei Technologies (Canada)","funders":"","keywords":"Computer science; Vulnerability (computing); Vulnerability management; Open source; Software; Open source software; Empirical research; Computer security; Vulnerability assessment; Operating system","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"codex-gemma-dda1882f352a","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001335537,0.0001689058,0.0003261808,0.0002110971,0.0001596279,0.0001014287,0.0009994031,0.00009813364,0.000004628365],"category_scores_gemma":[0.0001551906,0.0001528445,0.00005244028,0.0004013859,0.00002917341,0.0002935681,0.00007597117,0.0002803903,0.000002218662],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0000379745,"about_ca_system_score_gemma":0.00002774572,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.00005203111,"about_ca_topic_score_gemma":0.000004408938,"domain_scores_codex":[0.9985019,0.0004457389,0.0003366367,0.0003707227,0.0001524958,0.0001924855],"domain_scores_gemma":[0.9979211,0.0008732085,0.0000542399,0.001010604,0.00006216568,0.00007864483],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"observational","study_design_scores_codex":[0.0002787127,0.002908307,0.01327398,0.001101007,0.0009043629,0.00002266356,0.01592394,0.2886384,0.00004345812,0.0250324,0.0002040454,0.6516687],"study_design_scores_gemma":[0.01476391,0.009483884,0.7426924,0.001531546,0.0009305153,0.000144342,0.01938371,0.1530489,0.006062537,0.008170268,0.04005185,0.003736141],"study_design_candidate":"observational","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.06337076,0.00004724297,0.9351084,0.0001329744,0.0005755264,0.0004446426,0.000007745424,0.0002809531,0.00003178946],"genre_scores_gemma":[0.6259707,0.00000872191,0.3736303,0.0001263165,0.000007454936,0.0001070374,0.000002270043,0.000008108893,0.0001390666],"genre_candidate":"methods","genre_consensus":null,"teacher_disagreement_score":0.7294184,"threshold_uncertainty_score":0.6232816,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.07854885103263813,"score_gpt":0.3762078492482218,"score_spread":0.2976589982155836,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}