A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features

Jessy Ayala, Yu-Jye Tung, Joshua Garcia, University of California

34th USENIX Security Symposium · Day 1

In the rapidly evolving landscape of modern software development, open-source software (**OSS**) forms the backbone of countless applications and services. However, this pervasive reliance on OSS has brought to the forefront a critical challenge: the escalating number of software vulnerabilities. While much research has focused on the perspectives of vulnerability reporters and the security practices of OSS contributors, the crucial viewpoint of **OSS maintainers**—especially those managing projects with a history of known vulnerabilities—has remained significantly understudied. This paper, "A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features," by Jessy Ayala, Yu-Jye Tung, and Joshua Garcia from the University of California, Irvine, addresses this critical gap.

AI review

Solid empirical work that actually talked to the people doing the work — 80 survey respondents and 22 interviews with maintainers of *previously vulnerable* projects. The findings aren't shocking but they're documented properly, and the CI-in-private-forks gap is a real operational pain point that GitHub should fix yesterday.