Skip to content

Conversation

@kanaji2002
Copy link
Contributor

No description provided.

その結果,マニフェストは1つの主要見出しと複数のサブセクションから成る浅い階層構造を持ち,内容の多くが運用コマンド,技術的な実装メモ,高レベルアーキテクチャの説明に集中していることが分かりました.


Tonnam さんは "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem" というタイトルで発表しました.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ここだけ空白入ってる?

Tonnam さん



金地くんは “An Empirical Study of Security-Policy Related Issues in Open Source Projects” というタイトルで発表しました.
本研究では,GitHub リポジトリ内で脆弱性を報告するためのファイルである,SECURITY.mdに着目し,その普及率が低い理由を調査しました.具体的には,SECURITY.mdファイルと5種類のコミュニティヘルスファイルに関連するIssueを分析し,導入が進まない要因を明らかにしました.その結果、SECURITY.mdの導入がかえってコントリビューターを混乱させているケースが存在することが確認されました.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ここも空白,意図して入れてるなら無視してオッケー



Tonnam さんは "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem" というタイトルで発表しました.
本研究では,最小限の機能しか持たない trivial packages と,実行可能なロジックを含まない data-only packages を対象に,それらの普及状況とセキュリティリスクを調査しています.発表では,これらのパッケージを検出するための規則ベース静的解析手法を開発し,2025年時点の npm エコシステムにおけるリスク評価を行いました.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

英語の前と後ろには意図的に空白入れてる?

Kanaji from our laboratory, along with Amy and Tonnam from Kasetsart University, presented their research at the [26th International Conference on Product-Focused Software Process Improvement (PROFES 2025)](https://conf.researchr.org/home/profes-2025), which was held from December 1 to 3, 2025.


Kanaji presented his work titled “An Empirical Study of Security-Policy Related Issues in Open Source Projects.”
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mr. Kanajiとか敬称をつけていたはず (Amy, Tonnamも同じく

---
# Documentation: https://wowchemy.com/docs/managing-content/

title: "Kanaji, Amy, and Tonnam presented their research at PROFES 2025."
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ここも敬称つけた方が良さそう

---
![](IMG_Kanaji.png)

本研究室の金地君と,Kasetsart UniversityのAmyさん,Tonnamさんが,2025年12月1日~3日にかけて行われた[26th International Conference on Product-Focused Software Process Improvement (PROFES 2025)](https://conf.researchr.org/home/profes-2025)で発表を行いました.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

どこで開催されたか,あとは採択率とかも情報があれば書いてもいいかも?これは必須じゃない

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds a bilingual blog post (Japanese and English) announcing research presentations by three lab members at PROFES 2025, which took place December 1-3, 2025. The article follows the established structure for conference announcement posts in this academic website repository.

  • Introduces presentations from Kanaji (lab member), Amy, and Tonnam (both from Kasetsart University)
  • Covers three research topics: security policies in open source, agentic coding manifests, and low-functionality NPM packages
  • Includes presentation photos for all three presenters

Reviewed changes

Copilot reviewed 2 out of 8 changed files in this pull request and generated 2 comments.

File Description
content/en/post/profes2025/index.md English version of the PROFES 2025 conference announcement with detailed summaries of three research presentations
content/ja/post/profes2025/index.md Japanese version of the same conference announcement, maintaining parallel structure and content

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.



Kanaji presented his work titled “An Empirical Study of Security-Policy Related Issues in Open Source Projects.”
This study focuses on SECURITY.md, a file used to report vulnerabilities in GitHub repositories, and investigates the reasons behind its low adoption rate. Specifically, we analyzed Issues related to SECURITY.md and five other community health files to identify the factors that hinder its adoption. The results revealed that, in some cases, the introduction of SECURITY.md can instead cause confusion among contributors.
Copy link

Copilot AI Dec 10, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Inconsistent point of view: The text uses "we analyzed" (first person) while the rest of the article uses third person narrative (e.g., "This study focuses", "The results revealed"). Consider changing to "the study analyzed" or "this research analyzed" to maintain consistency with the third-person perspective used throughout the article.

Suggested change
This study focuses on SECURITY.md, a file used to report vulnerabilities in GitHub repositories, and investigates the reasons behind its low adoption rate. Specifically, we analyzed Issues related to SECURITY.md and five other community health files to identify the factors that hinder its adoption. The results revealed that, in some cases, the introduction of SECURITY.md can instead cause confusion among contributors.
This study focuses on SECURITY.md, a file used to report vulnerabilities in GitHub repositories, and investigates the reasons behind its low adoption rate. Specifically, the study analyzed Issues related to SECURITY.md and five other community health files to identify the factors that hinder its adoption. The results revealed that, in some cases, the introduction of SECURITY.md can instead cause confusion among contributors.

Copilot uses AI. Check for mistakes.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

これは文法とかの問題なので対応した方が良さそう

Comment on lines 41 to 46
その結果,マニフェストは1つの主要見出しと複数のサブセクションから成る浅い階層構造を持ち,内容の多くが運用コマンド,技術的な実装メモ,高レベルアーキテクチャの説明に集中していることが分かりました.


Tonnam さんは "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem" というタイトルで発表しました.
本研究では,最小限の機能しか持たない trivial packages と,実行可能なロジックを含まない data-only packages を対象に,それらの普及状況とセキュリティリスクを調査しています.発表では,これらのパッケージを検出するための規則ベース静的解析手法を開発し,2025年時点の npm エコシステムにおけるリスク評価を行いました.
分析の結果,パッケージの 17.92%が trivial packages に分類され,その脆弱性レベルは非 trivial パッケージと同程度であることが示されました。また,data-only packages は頻度こそ低いものの,依然としてリスクを含むことも確認されました。提案手法による検出ツールは94%の精度(macro-F1 0.87)を達成し,大規模解析やセキュリティリスク低減に有用であることが示されました.
Copy link

Copilot AI Dec 10, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Inconsistent punctuation usage: The text mixes Japanese commas (、) and Western-style commas (,), as well as Japanese periods (。) and Western-style periods (.). For example, line 36 uses both "," and "、", while line 46 uses "。" instead of ".". Consider using consistent punctuation throughout the document - either all Japanese-style (、。) or all Western-style (,.) punctuation marks.

Suggested change
その結果マニフェストは1つの主要見出しと複数のサブセクションから成る浅い階層構造を持ち内容の多くが運用コマンド技術的な実装メモ高レベルアーキテクチャの説明に集中していることが分かりました
Tonnam さんは "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem" というタイトルで発表しました
本研究では最小限の機能しか持たない trivial packages と実行可能なロジックを含まない data-only packages を対象にそれらの普及状況とセキュリティリスクを調査しています発表ではこれらのパッケージを検出するための規則ベース静的解析手法を開発し2025年時点の npm エコシステムにおけるリスク評価を行いました
分析の結果パッケージの 17.92%が trivial packages に分類されその脆弱性レベルは非 trivial パッケージと同程度であることが示されました。またdata-only packages は頻度こそ低いものの依然としてリスクを含むことも確認されました。提案手法による検出ツールは94%の精度(macro-F1 0.87)を達成し大規模解析やセキュリティリスク低減に有用であることが示されました
その結果マニフェストは1つの主要見出しと複数のサブセクションから成る浅い階層構造を持ち内容の多くが運用コマンド技術的な実装メモ高レベルアーキテクチャの説明に集中していることが分かりました
Tonnam さんは "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem" というタイトルで発表しました
本研究では最小限の機能しか持たない trivial packages と実行可能なロジックを含まない data-only packages を対象にそれらの普及状況とセキュリティリスクを調査しています発表ではこれらのパッケージを検出するための規則ベース静的解析手法を開発し2025年時点の npm エコシステムにおけるリスク評価を行いました
分析の結果パッケージの 17.92%が trivial packages に分類されその脆弱性レベルは非 trivial パッケージと同程度であることが示されました。またdata-only packages は頻度こそ低いものの依然としてリスクを含むことも確認されました。提案手法による検出ツールは94%の精度(macro-F1 0.87)を達成し大規模解析やセキュリティリスク低減に有用であることが示されました

Copilot uses AI. Check for mistakes.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

これは無視

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 8 changed files in this pull request and generated 6 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

This study focuses on SECURITY.md, a file used to report vulnerabilities in GitHub repositories, and investigates the reasons behind its low adoption rate. Specifically, the study analyzed Issues related to SECURITY.md and five other community health files to identify the factors that hinder its adoption. The results revealed that, in some cases, the introduction of SECURITY.md can instead cause confusion among contributors.


Ms.Amy presented her work titled "On the Use of Agentic Coding Manifests: An Empirical Study of Claude Code."
Copy link

Copilot AI Dec 12, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Inconsistent spacing: There should be a space after "Ms." in "Ms.Amy" for consistency with the formatting elsewhere in the document where "Ms.Tonnam" appears. This should be "Ms. Amy" to match standard English spacing conventions.

Suggested change
Ms.Amy presented her work titled "On the Use of Agentic Coding Manifests: An Empirical Study of Claude Code."
Ms. Amy presented her work titled "On the Use of Agentic Coding Manifests: An Empirical Study of Claude Code."

Copilot uses AI. Check for mistakes.
projects: []
---
![](IMG_Kanaji.png)
Mr.Kanaji from our laboratory, along with Amy and Tonnam from Kasetsart University, attended the [26th International Conference on Product-Focused Software Process Improvement (PROFES 2025)](https://conf.researchr.org/home/profes-2025), which was held in Salerno, Italy, from December 1 to 3, 2025. The three authors submitted their papers to the short paper track of PROFES, where their work was accepted and presented. The acceptance rate for the short papers was 68%.
Copy link

Copilot AI Dec 12, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Inconsistent spacing: "Mr.Kanaji" should have a space after the period to match standard English spacing conventions. This should be "Mr. Kanaji" for consistency with the title format.

Copilot uses AI. Check for mistakes.
Mr.Kanaji from our laboratory, along with Amy and Tonnam from Kasetsart University, attended the [26th International Conference on Product-Focused Software Process Improvement (PROFES 2025)](https://conf.researchr.org/home/profes-2025), which was held in Salerno, Italy, from December 1 to 3, 2025. The three authors submitted their papers to the short paper track of PROFES, where their work was accepted and presented. The acceptance rate for the short papers was 68%.


Mr.Kanaji presented his work titled “An Empirical Study of Security-Policy Related Issues in Open Source Projects.”
Copy link

Copilot AI Dec 12, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Inconsistent spacing: "Mr.Kanaji" should have a space after the period to match standard English spacing conventions. This should be "Mr. Kanaji".

Suggested change
Mr.Kanaji presented his work titled “An Empirical Study of Security-Policy Related Issues in Open Source Projects.”
Mr. Kanaji presented his work titled “An Empirical Study of Security-Policy Related Issues in Open Source Projects.”

Copilot uses AI. Check for mistakes.
@kanaji2002 kanaji2002 requested a review from Mont9165 December 12, 2025 09:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants