Communicating on Security within Software Development Issue Tracking
L\'eon McGregor, Manuel Maarek, Hans-Wolfgang Loidl

TL;DR
This paper examines how software development issue trackers support security communication, revealing gaps in interface design and user understanding, and suggests improvements to enhance security awareness among non-security experts.
Contribution
It provides an analysis of issue tracker interfaces for security communication and presents findings from a user study on developer attitudes towards security scoring.
Findings
Projects reference CVSS and CVE reports but lack dedicated interfaces.
Developers are uncomfortable with CVSS analysis but can reason about security.
Explanations and advice improve security decision-making.
Abstract
During software development, balancing security and non security issues is challenging. We focus on security awareness and approaches taken by non-security experts using software development issue trackers when considering security. We first analyse interfaces from prominent issue trackers to see how they support security communication and how they integrate security scoring. Then, we investigate through a small scale user study what criteria developers take when prioritising issues, in particular observing their attitudes to security. We find projects make reference to CVSS summaries (Common Vulnerability Scoring System), often alongside CVE reports (Common Vulnerabilities and Exposures), but issue trackers do not often have interfaces designed for this. Users in our study were not comfortable with CVSS analysis, though were able to reason in a manner compatible with CVSS. Detailed…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Software Engineering Research · Software Engineering Techniques and Practices
