{"id":"W4408797770","doi":"10.1145/3716822","title":"An empirical study on vulnerability disclosure management of open source software systems","year":2025,"lang":"en","type":"article","venue":"ACM Transactions on Software Engineering and Methodology","topic":"Information and Cyber Security","field":"Computer Science","cited_by":2,"is_retracted":false,"has_abstract":true,"ca_institutions":"Huawei Technologies (Canada)","funders":"","keywords":"Computer science; Vulnerability (computing); Vulnerability management; Open source; Software; Open source software; Empirical research; Computer security; Vulnerability assessment; Operating system","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.02123898,0.0002623886,0.0003001959,0.002910232,0.001942257,0.002712273,0.0009513494,0.001000097,0.001804868],"category_scores_gemma":[0.1436032,0.0003430175,0.0002699999,0.003371119,0.002263324,0.006742064,0.002685453,0.00212984,0.0002978593],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.00210982,"about_ca_system_score_gemma":0.003150239,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.002947019,"about_ca_topic_score_gemma":0.003414684,"domain_scores_codex":[0.9765667,0.01202835,0.00241249,0.001553616,0.00590408,0.001534922],"domain_scores_gemma":[0.6389281,0.2460632,0.07655386,0.008590672,0.02353736,0.006326784],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"observational","study_design_gemma":"observational","study_design_scores_codex":[0.0001478396,0.0008306828,0.8312342,0.0004399633,0.00004213132,0.0007450775,0.1109984,0.0004929186,0.001191545,0.002854449,0.001235697,0.04978724],"study_design_scores_gemma":[0.00003329927,0.0008858732,0.6985892,0.0007628491,0.00005525989,0.001384968,0.2740823,0.005299435,0.001724156,0.002372148,0.01471435,0.00009617608],"study_design_candidate":"observational","study_design_consensus":"observational","genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.9971205,0.0001466065,0.0006994014,0.0004449907,0.000004686894,0.00004708931,0.00004500502,0.000006227213,0.001485502],"genre_scores_gemma":[0.9985054,0.0001990951,0.0007567084,0.0001052222,0.000008354746,0.00004992447,0.00006649093,0.000005257005,0.0003036243],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.02123898,"threshold_uncertainty_score":0.1123238,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.07854885103263813,"score_gpt":0.3762078492482218,"score_spread":0.2976589982155836,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}