Caution: JavaScript execution is disabled in your browser or for this website. You may not be able to answer all questions in this survey. Please, verify your browser parameters.

Vulnerability Management of Hidden Dependencies

As part of my master's thesis at Paderborn University, I am analyzing developer's awareness, risk assessment, and patching motivation regarding vulnerabilities in re-bundled and re-packaged dependencies.

Participation is this survey is voluntary. The survey will take about 5-10 minutes to complete.

This survey is anonymous. The record of your survey responses does not contain any identifying information about you.

If you have any questions or concerns, please feel free to reach out at alinabr@mail.uni-paderborn.de.

Thank you!

There are 9 questions in this survey.
Awareness and Risk Assessment
(This question is mandatory)

Were you aware of the vulnerabilities in the re-bundled or re-packaged dependencies before receiving the notification?

What do you think are the reasons for not identifying vulnerable dependencies?

(This question is mandatory)
How risky do you think are re-bundled or re-packed vulnerable dependencies?

What are the main factors that influence your risk assessment?

Patching Motivation
(This question is mandatory)
Do you plan to fix the reported issues?
What motivates you to fix the vulnerable dependencies?
What are your main reasons for not fixing the vulnerable dependencies?
Additional Information
How many developers are actively working on the open source project?
Is there anything else you would like to share about managing vulnerabilities in hidden dependencies?