Skip to main content
zenodoopen

Dataset for the Paper: "Security Defect Detection via Code Review: A Study of the OpenStack and Qt Communities"

<p>This is the dataset&nbsp;for the paper: &quot;Security Defect Detection via Code Review: A Study of the OpenStack and Qt Communities &quot;, including the extracted&nbsp;data and results.</p> <p>The dataset&nbsp;contains the following three folders:</p> <p><strong>1. RQ1</strong>:&nbsp;</p> <ul> <li><strong>Security defect in Nova.xlsx</strong></li> <li><strong>Security defect in Neutron.xlsx</strong></li> <li><strong>Security defect in Qt Base.xlsx</strong></li> <li><strong>Security defect in Qt Creator.xlsx;</strong></li> </ul> <p>The RQ1 folder contains four files corresponding to the four projects (i.e., Nova and Neutron from OpenStack, Qt Base and Qt Creator from Qt), including 539 security-related review comments, in which security defects were identified by the reviewers. These instances were obtained from manual labelling after keyword-based search. The security defect type of these&nbsp;instances are&nbsp; presented to answer RQ1.</p> <p><strong>How to Read the MS Excel&nbsp;files in RQ1:</strong></p> <p>Each of the four MS Excel files in this folder contains 6 sheets for six years from 2017 to 2022. Each sheet has 10 columns for recoding 10 data items, among which the last four data items are used in our study to answer the RQs. We list the data items in the following table.</p> <table> <tbody> <tr> <td><strong>Data Item</strong></td> <td><strong>Description</strong></td> <td><strong>Source</strong></td> </tr> <tr> <td>Keyword</td> <td>The corresponding keyword of the comment.</td> <td>Keyword-based Search</td> </tr> <tr> <td>Code_change_id</td> <td>The code_change_id of the comment.</td> <td>Gerrit</td> </tr> <tr> <td>File</td> <td>The file in which the comment is added.</td> <td>Gerrit</td> </tr> <tr> <td>Patchset</td> <td>The patchset of the comment within the code change.</td> <td>Gerrit</td> </tr> <tr> <td>Line</td> <td>The line number in the file at which the comment is added.</td> <td>Gerrit</td> </tr> <tr> <td>Message</td> <td>The text of the review comment.</td> <td>Gerrit</td> </tr> <tr> <td>Security-related</td> <td>Whether the review comment is security-related (i.e., Yes or No).</td> <td>Labelling</td> </tr> <tr> <td>Security defect type</td> <td>The type of the security defect identified in the comment.</td> <td>Labelling</td> </tr> <tr> <td>Consequence</td> <td>The Consequence of the security defect.</td> <td>Extraction</td> </tr> <tr> <td>Resolution Evidence</td> <td>The information about where the identified security defect was resolved in the code</td> <td>Extraction</td> </tr> </tbody> </table> <p><strong>2. RQ2</strong>:&nbsp;</p> <ul> <li><strong>Extracted data for RQ2.mx22</strong></li> </ul> <p>The RQ2 folder contains the extracted data of 539 security-related review comments in&nbsp;<strong>Extracted data for RQ2.mx22</strong>, which was encoded and&nbsp;analyzed&nbsp;by the MAXQDA tool, investigating&nbsp;the treatment of security defects by developers and reviewers&nbsp;to answer RQ2.</p> <p><strong>3. RQ3</strong>:&nbsp;</p> <ul> <li><strong>Extracted data for RQ3.mx22</strong></li> </ul> <p>The RQ3 folder contains the extracted data of 161 review comments in which identified security defects were not resolved by developers in <strong>Extracted data for RQ3.mx22</strong>. which was also encoded and analyzed by the MAXQDA tool, exploring the causes of not resolving security defects to answer RQ3.</p> <p><strong>Note</strong>: The mx22 can be opened by MAXQDA 22, which are available at&nbsp;<a href="https://www.maxqda.com/">https://www.maxqda.com/</a> for download. You may also use the free trial version of MAXQDA 2022, which is available at <a href="https://www.maxqda.com/trial">https://www.maxqda.com/trial</a> for download.</p>

ShareScore

32/100

Overall dataset sharing score

Score breakdown

These five areas show where the dataset supports — or may limit — practical reuse.

Stewardship
4
Harmonization
4
Access
16
Reuse readiness
8
Engagement
0