Visible to the public SECOM: Towards a convention for security commit messages

TitleSECOM: Towards a convention for security commit messages
Publication TypeConference Paper
Year of Publication2022
AuthorsReis, Sofia, Abreu, Rui, Erdogmus, Hakan, Păsăreanu, Corina
Conference Name2022 IEEE/ACM 19th International Conference on Mining Software Repositories (MSR)
Keywordsbest practices, composability, convention, data mining, IDS, pubcrawl, resilience, Resiliency, security, security commit messages, Software, Standard
AbstractOne way to detect and assess software vulnerabilities is by extracting security-related information from commit messages. Automating the detection and assessment of vulnerabilities upon security commit messages is still challenging due to the lack of structured and clear messages. We created a convention, called SECOM, for security commit messages that structure and include bits of security-related information that are essential for detecting and assessing vulnerabilities for both humans and tools. The full convention and details are available here: https://tqrg.github.io/secom/.
DOI10.1145/3524842.3528513
Citation Keyreis_secom_2022