-
Notifications
You must be signed in to change notification settings - Fork 12
Add PROFES2025 article #270
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
content/ja/post/profes2025/index.md
Outdated
| その結果,マニフェストは1つの主要見出しと複数のサブセクションから成る浅い階層構造を持ち,内容の多くが運用コマンド,技術的な実装メモ,高レベルアーキテクチャの説明に集中していることが分かりました. | ||
|
|
||
|
|
||
| Tonnam さんは "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem" というタイトルで発表しました. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
ここだけ空白入ってる?
Tonnam さん
content/ja/post/profes2025/index.md
Outdated
|
|
||
|
|
||
| 金地くんは “An Empirical Study of Security-Policy Related Issues in Open Source Projects” というタイトルで発表しました. | ||
| 本研究では,GitHub リポジトリ内で脆弱性を報告するためのファイルである,SECURITY.mdに着目し,その普及率が低い理由を調査しました.具体的には,SECURITY.mdファイルと5種類のコミュニティヘルスファイルに関連するIssueを分析し,導入が進まない要因を明らかにしました.その結果、SECURITY.mdの導入がかえってコントリビューターを混乱させているケースが存在することが確認されました. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
ここも空白,意図して入れてるなら無視してオッケー
content/ja/post/profes2025/index.md
Outdated
|
|
||
|
|
||
| Tonnam さんは "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem" というタイトルで発表しました. | ||
| 本研究では,最小限の機能しか持たない trivial packages と,実行可能なロジックを含まない data-only packages を対象に,それらの普及状況とセキュリティリスクを調査しています.発表では,これらのパッケージを検出するための規則ベース静的解析手法を開発し,2025年時点の npm エコシステムにおけるリスク評価を行いました. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
英語の前と後ろには意図的に空白入れてる?
content/en/post/profes2025/index.md
Outdated
| Kanaji from our laboratory, along with Amy and Tonnam from Kasetsart University, presented their research at the [26th International Conference on Product-Focused Software Process Improvement (PROFES 2025)](https://conf.researchr.org/home/profes-2025), which was held from December 1 to 3, 2025. | ||
|
|
||
|
|
||
| Kanaji presented his work titled “An Empirical Study of Security-Policy Related Issues in Open Source Projects.” |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Mr. Kanajiとか敬称をつけていたはず (Amy, Tonnamも同じく
content/en/post/profes2025/index.md
Outdated
| --- | ||
| # Documentation: https://wowchemy.com/docs/managing-content/ | ||
|
|
||
| title: "Kanaji, Amy, and Tonnam presented their research at PROFES 2025." |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
ここも敬称つけた方が良さそう
content/ja/post/profes2025/index.md
Outdated
| --- | ||
|  | ||
|
|
||
| 本研究室の金地君と,Kasetsart UniversityのAmyさん,Tonnamさんが,2025年12月1日~3日にかけて行われた[26th International Conference on Product-Focused Software Process Improvement (PROFES 2025)](https://conf.researchr.org/home/profes-2025)で発表を行いました. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
どこで開催されたか,あとは採択率とかも情報があれば書いてもいいかも?これは必須じゃない
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
This PR adds a bilingual blog post (Japanese and English) announcing research presentations by three lab members at PROFES 2025, which took place December 1-3, 2025. The article follows the established structure for conference announcement posts in this academic website repository.
- Introduces presentations from Kanaji (lab member), Amy, and Tonnam (both from Kasetsart University)
- Covers three research topics: security policies in open source, agentic coding manifests, and low-functionality NPM packages
- Includes presentation photos for all three presenters
Reviewed changes
Copilot reviewed 2 out of 8 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| content/en/post/profes2025/index.md | English version of the PROFES 2025 conference announcement with detailed summaries of three research presentations |
| content/ja/post/profes2025/index.md | Japanese version of the same conference announcement, maintaining parallel structure and content |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
content/en/post/profes2025/index.md
Outdated
|
|
||
|
|
||
| Kanaji presented his work titled “An Empirical Study of Security-Policy Related Issues in Open Source Projects.” | ||
| This study focuses on SECURITY.md, a file used to report vulnerabilities in GitHub repositories, and investigates the reasons behind its low adoption rate. Specifically, we analyzed Issues related to SECURITY.md and five other community health files to identify the factors that hinder its adoption. The results revealed that, in some cases, the introduction of SECURITY.md can instead cause confusion among contributors. |
Copilot
AI
Dec 10, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Inconsistent point of view: The text uses "we analyzed" (first person) while the rest of the article uses third person narrative (e.g., "This study focuses", "The results revealed"). Consider changing to "the study analyzed" or "this research analyzed" to maintain consistency with the third-person perspective used throughout the article.
| This study focuses on SECURITY.md, a file used to report vulnerabilities in GitHub repositories, and investigates the reasons behind its low adoption rate. Specifically, we analyzed Issues related to SECURITY.md and five other community health files to identify the factors that hinder its adoption. The results revealed that, in some cases, the introduction of SECURITY.md can instead cause confusion among contributors. | |
| This study focuses on SECURITY.md, a file used to report vulnerabilities in GitHub repositories, and investigates the reasons behind its low adoption rate. Specifically, the study analyzed Issues related to SECURITY.md and five other community health files to identify the factors that hinder its adoption. The results revealed that, in some cases, the introduction of SECURITY.md can instead cause confusion among contributors. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
これは文法とかの問題なので対応した方が良さそう
content/ja/post/profes2025/index.md
Outdated
| その結果,マニフェストは1つの主要見出しと複数のサブセクションから成る浅い階層構造を持ち,内容の多くが運用コマンド,技術的な実装メモ,高レベルアーキテクチャの説明に集中していることが分かりました. | ||
|
|
||
|
|
||
| Tonnam さんは "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem" というタイトルで発表しました. | ||
| 本研究では,最小限の機能しか持たない trivial packages と,実行可能なロジックを含まない data-only packages を対象に,それらの普及状況とセキュリティリスクを調査しています.発表では,これらのパッケージを検出するための規則ベース静的解析手法を開発し,2025年時点の npm エコシステムにおけるリスク評価を行いました. | ||
| 分析の結果,パッケージの 17.92%が trivial packages に分類され,その脆弱性レベルは非 trivial パッケージと同程度であることが示されました。また,data-only packages は頻度こそ低いものの,依然としてリスクを含むことも確認されました。提案手法による検出ツールは94%の精度(macro-F1 0.87)を達成し,大規模解析やセキュリティリスク低減に有用であることが示されました. |
Copilot
AI
Dec 10, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Inconsistent punctuation usage: The text mixes Japanese commas (、) and Western-style commas (,), as well as Japanese periods (。) and Western-style periods (.). For example, line 36 uses both "," and "、", while line 46 uses "。" instead of ".". Consider using consistent punctuation throughout the document - either all Japanese-style (、。) or all Western-style (,.) punctuation marks.
| その結果,マニフェストは1つの主要見出しと複数のサブセクションから成る浅い階層構造を持ち,内容の多くが運用コマンド,技術的な実装メモ,高レベルアーキテクチャの説明に集中していることが分かりました. | |
| Tonnam さんは "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem" というタイトルで発表しました. | |
| 本研究では,最小限の機能しか持たない trivial packages と,実行可能なロジックを含まない data-only packages を対象に,それらの普及状況とセキュリティリスクを調査しています.発表では,これらのパッケージを検出するための規則ベース静的解析手法を開発し,2025年時点の npm エコシステムにおけるリスク評価を行いました. | |
| 分析の結果,パッケージの 17.92%が trivial packages に分類され,その脆弱性レベルは非 trivial パッケージと同程度であることが示されました。また,data-only packages は頻度こそ低いものの,依然としてリスクを含むことも確認されました。提案手法による検出ツールは94%の精度(macro-F1 0.87)を達成し,大規模解析やセキュリティリスク低減に有用であることが示されました. | |
| その結果、マニフェストは1つの主要見出しと複数のサブセクションから成る浅い階層構造を持ち、内容の多くが運用コマンド、技術的な実装メモ、高レベルアーキテクチャの説明に集中していることが分かりました。 | |
| Tonnam さんは "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem" というタイトルで発表しました。 | |
| 本研究では、最小限の機能しか持たない trivial packages と、実行可能なロジックを含まない data-only packages を対象に、それらの普及状況とセキュリティリスクを調査しています。発表では、これらのパッケージを検出するための規則ベース静的解析手法を開発し、2025年時点の npm エコシステムにおけるリスク評価を行いました。 | |
| 分析の結果、パッケージの 17.92%が trivial packages に分類され、その脆弱性レベルは非 trivial パッケージと同程度であることが示されました。また、data-only packages は頻度こそ低いものの、依然としてリスクを含むことも確認されました。提案手法による検出ツールは94%の精度(macro-F1 0.87)を達成し、大規模解析やセキュリティリスク低減に有用であることが示されました。 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
これは無視
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
Copilot reviewed 2 out of 8 changed files in this pull request and generated 6 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
content/en/post/profes2025/index.md
Outdated
| This study focuses on SECURITY.md, a file used to report vulnerabilities in GitHub repositories, and investigates the reasons behind its low adoption rate. Specifically, the study analyzed Issues related to SECURITY.md and five other community health files to identify the factors that hinder its adoption. The results revealed that, in some cases, the introduction of SECURITY.md can instead cause confusion among contributors. | ||
|
|
||
|
|
||
| Ms.Amy presented her work titled "On the Use of Agentic Coding Manifests: An Empirical Study of Claude Code." |
Copilot
AI
Dec 12, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Inconsistent spacing: There should be a space after "Ms." in "Ms.Amy" for consistency with the formatting elsewhere in the document where "Ms.Tonnam" appears. This should be "Ms. Amy" to match standard English spacing conventions.
| Ms.Amy presented her work titled "On the Use of Agentic Coding Manifests: An Empirical Study of Claude Code." | |
| Ms. Amy presented her work titled "On the Use of Agentic Coding Manifests: An Empirical Study of Claude Code." |
content/en/post/profes2025/index.md
Outdated
| projects: [] | ||
| --- | ||
|  | ||
| Mr.Kanaji from our laboratory, along with Amy and Tonnam from Kasetsart University, attended the [26th International Conference on Product-Focused Software Process Improvement (PROFES 2025)](https://conf.researchr.org/home/profes-2025), which was held in Salerno, Italy, from December 1 to 3, 2025. The three authors submitted their papers to the short paper track of PROFES, where their work was accepted and presented. The acceptance rate for the short papers was 68%. |
Copilot
AI
Dec 12, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Inconsistent spacing: "Mr.Kanaji" should have a space after the period to match standard English spacing conventions. This should be "Mr. Kanaji" for consistency with the title format.
content/en/post/profes2025/index.md
Outdated
| Mr.Kanaji from our laboratory, along with Amy and Tonnam from Kasetsart University, attended the [26th International Conference on Product-Focused Software Process Improvement (PROFES 2025)](https://conf.researchr.org/home/profes-2025), which was held in Salerno, Italy, from December 1 to 3, 2025. The three authors submitted their papers to the short paper track of PROFES, where their work was accepted and presented. The acceptance rate for the short papers was 68%. | ||
|
|
||
|
|
||
| Mr.Kanaji presented his work titled “An Empirical Study of Security-Policy Related Issues in Open Source Projects.” |
Copilot
AI
Dec 12, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Inconsistent spacing: "Mr.Kanaji" should have a space after the period to match standard English spacing conventions. This should be "Mr. Kanaji".
| Mr.Kanaji presented his work titled “An Empirical Study of Security-Policy Related Issues in Open Source Projects.” | |
| Mr. Kanaji presented his work titled “An Empirical Study of Security-Policy Related Issues in Open Source Projects.” |
Co-authored-by: Copilot <[email protected]>
Co-authored-by: Copilot <[email protected]>
Co-authored-by: Copilot <[email protected]>
No description provided.