Skip to content
Merged
Show file tree
Hide file tree
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Binary file added content/en/post/profes2025/IMG_Amy.jpg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added content/en/post/profes2025/IMG_Kanaji.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added content/en/post/profes2025/IMG_Tonnam.jpeg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
53 changes: 53 additions & 0 deletions content/en/post/profes2025/index.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
---
# Documentation: https://wowchemy.com/docs/managing-content/

title: "Kanaji, Amy, and Tonnam presented their research at PROFES 2025."
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ここも敬称つけた方が良さそう

subtitle: ""
summary: ""
authors: [rintaro-kanaji]
tags: ["Security","Agentic Coding","Software Libraries","Ecosystem"]
categories: []
date: 2025-12-10T14:32:55+09:00
lastmod: 2025-12-10T14:32:55+09:00
featured: false
draft: false

# Featured image
# To use, add an image named `featured.jpg/png` to your page's folder.
# Focal points: Smart, Center, TopLeft, Top, TopRight, Left, Right, BottomLeft, Bottom, BottomRight.
image:
caption: ""
focal_point: ""
preview_only: false

# Projects (optional).
# Associate this post with one or more of your projects.
# Simply enter your project's folder or file name without extension.
# E.g. `projects = ["internal-project"]` references `content/project/deep-learning/index.md`.
# Otherwise, set `projects = []`.
projects: []
---
![](IMG_Kanaji.png)
Kanaji from our laboratory, along with Amy and Tonnam from Kasetsart University, presented their research at the [26th International Conference on Product-Focused Software Process Improvement (PROFES 2025)](https://conf.researchr.org/home/profes-2025), which was held from December 1 to 3, 2025.


Kanaji presented his work titled “An Empirical Study of Security-Policy Related Issues in Open Source Projects.”
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mr. Kanajiとか敬称をつけていたはず (Amy, Tonnamも同じく

This study focuses on SECURITY.md, a file used to report vulnerabilities in GitHub repositories, and investigates the reasons behind its low adoption rate. Specifically, we analyzed Issues related to SECURITY.md and five other community health files to identify the factors that hinder its adoption. The results revealed that, in some cases, the introduction of SECURITY.md can instead cause confusion among contributors.
Copy link

Copilot AI Dec 10, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Inconsistent point of view: The text uses "we analyzed" (first person) while the rest of the article uses third person narrative (e.g., "This study focuses", "The results revealed"). Consider changing to "the study analyzed" or "this research analyzed" to maintain consistency with the third-person perspective used throughout the article.

Suggested change
This study focuses on SECURITY.md, a file used to report vulnerabilities in GitHub repositories, and investigates the reasons behind its low adoption rate. Specifically, we analyzed Issues related to SECURITY.md and five other community health files to identify the factors that hinder its adoption. The results revealed that, in some cases, the introduction of SECURITY.md can instead cause confusion among contributors.
This study focuses on SECURITY.md, a file used to report vulnerabilities in GitHub repositories, and investigates the reasons behind its low adoption rate. Specifically, the study analyzed Issues related to SECURITY.md and five other community health files to identify the factors that hinder its adoption. The results revealed that, in some cases, the introduction of SECURITY.md can instead cause confusion among contributors.

Copilot uses AI. Check for mistakes.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

これは文法とかの問題なので対応した方が良さそう



Amy presented her work titled "On the Use of Agentic Coding Manifests: An Empirical Study of Claude Code."
This study investigates the role and characteristics of agent manifests in agentic coding tools. In the presentation, she analyzed 253 Claude.md files collected from 242 repositories to identify structural features, content trends, and common patterns in these manifests.
The results revealed that manifests generally exhibit a shallow hierarchical structure consisting of one main heading and several subsections, with most content focusing on operational commands, technical implementation notes, and high-level architectural descriptions.

Tonnam presented a work titled "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem."
The study examines trivial packages, which offer minimal functionality, and data-only packages, which contain no executable logic. A rule-based static analysis method was developed to detect these packages and to assess their prevalence and associated security risks in the 2025 npm ecosystem.
The analysis showed that 17.92% of packages were trivial, with vulnerability levels similar to non-trivial ones, and that data-only packages, though less common, also pose risks. The proposed detection tool achieved 94% accuracy (macro-F1 0.87), demonstrating its usefulness for large-scale analysis and reducing security exposure.


![](IMG_Amy.jpg)

![](IMG_Tonnam.jpeg)




Binary file added content/ja/post/profes2025/IMG_Amy.jpg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added content/ja/post/profes2025/IMG_Kanaji.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added content/ja/post/profes2025/IMG_Tonnam.jpeg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
56 changes: 56 additions & 0 deletions content/ja/post/profes2025/index.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
---
# Documentation: https://wowchemy.com/docs/managing-content/

title: "金地君,Amyさん,TonnamさんがPROFES2025にて研究発表を行いました"
subtitle: ""
summary: ""
authors: [rintaro-kanaji]
tags: ["Security","Agentic Coding","Software Libraries","Ecosystem"]
categories: []
date: 2025-12-10T14:32:55+09:00
lastmod: 2025-12-10T14:32:55+09:00
featured: false
draft: false

# Featured image
# To use, add an image named `featured.jpg/png` to your page's folder.
# Focal points: Smart, Center, TopLeft, Top, TopRight, Left, Right, BottomLeft, Bottom, BottomRight.
image:
caption: ""
focal_point: ""
preview_only: false

# Projects (optional).
# Associate this post with one or more of your projects.
# Simply enter your project's folder or file name without extension.
# E.g. `projects = ["internal-project"]` references `content/project/deep-learning/index.md`.
# Otherwise, set `projects = []`.
projects: []
---
![](IMG_Kanaji.png)

本研究室の金地君と,Kasetsart UniversityのAmyさん,Tonnamさんが,2025年12月1日~3日にかけて行われた[26th International Conference on Product-Focused Software Process Improvement (PROFES 2025)](https://conf.researchr.org/home/profes-2025)で発表を行いました.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

どこで開催されたか,あとは採択率とかも情報があれば書いてもいいかも?これは必須じゃない



金地くんは “An Empirical Study of Security-Policy Related Issues in Open Source Projects” というタイトルで発表しました.
本研究では,GitHub リポジトリ内で脆弱性を報告するためのファイルである,SECURITY.mdに着目し,その普及率が低い理由を調査しました.具体的には,SECURITY.mdファイルと5種類のコミュニティヘルスファイルに関連するIssueを分析し,導入が進まない要因を明らかにしました.その結果、SECURITY.mdの導入がかえってコントリビューターを混乱させているケースが存在することが確認されました.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ここも空白,意図して入れてるなら無視してオッケー



Amyさんは "On the Use of Agentic Coding Manifests: An Empirical Study of Claude Code" というタイトルで発表しました.
本研究では,エージェンティックコーディングツールにおけるエージェントマニフェストの役割と実態を調査しています.発表では,242のリポジトリから収集した253個のClaude.mdファイルを分析し,マニフェスト構造の特徴,記述内容の傾向,および共通パターンを明らかにしました.
その結果,マニフェストは1つの主要見出しと複数のサブセクションから成る浅い階層構造を持ち,内容の多くが運用コマンド,技術的な実装メモ,高レベルアーキテクチャの説明に集中していることが分かりました.


Tonnam さんは "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem" というタイトルで発表しました.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ここだけ空白入ってる?

Tonnam さん

本研究では,最小限の機能しか持たない trivial packages と,実行可能なロジックを含まない data-only packages を対象に,それらの普及状況とセキュリティリスクを調査しています.発表では,これらのパッケージを検出するための規則ベース静的解析手法を開発し,2025年時点の npm エコシステムにおけるリスク評価を行いました.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

英語の前と後ろには意図的に空白入れてる?

分析の結果,パッケージの 17.92%が trivial packages に分類され,その脆弱性レベルは非 trivial パッケージと同程度であることが示されました。また,data-only packages は頻度こそ低いものの,依然としてリスクを含むことも確認されました。提案手法による検出ツールは94%の精度(macro-F1 0.87)を達成し,大規模解析やセキュリティリスク低減に有用であることが示されました.
Copy link

Copilot AI Dec 10, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Inconsistent punctuation usage: The text mixes Japanese commas (、) and Western-style commas (,), as well as Japanese periods (。) and Western-style periods (.). For example, line 36 uses both "," and "、", while line 46 uses "。" instead of ".". Consider using consistent punctuation throughout the document - either all Japanese-style (、。) or all Western-style (,.) punctuation marks.

Suggested change
その結果マニフェストは1つの主要見出しと複数のサブセクションから成る浅い階層構造を持ち内容の多くが運用コマンド技術的な実装メモ高レベルアーキテクチャの説明に集中していることが分かりました
Tonnam さんは "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem" というタイトルで発表しました
本研究では最小限の機能しか持たない trivial packages と実行可能なロジックを含まない data-only packages を対象にそれらの普及状況とセキュリティリスクを調査しています発表ではこれらのパッケージを検出するための規則ベース静的解析手法を開発し2025年時点の npm エコシステムにおけるリスク評価を行いました
分析の結果パッケージの 17.92%が trivial packages に分類されその脆弱性レベルは非 trivial パッケージと同程度であることが示されました。またdata-only packages は頻度こそ低いものの依然としてリスクを含むことも確認されました。提案手法による検出ツールは94%の精度(macro-F1 0.87)を達成し大規模解析やセキュリティリスク低減に有用であることが示されました
その結果マニフェストは1つの主要見出しと複数のサブセクションから成る浅い階層構造を持ち内容の多くが運用コマンド技術的な実装メモ高レベルアーキテクチャの説明に集中していることが分かりました
Tonnam さんは "Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem" というタイトルで発表しました
本研究では最小限の機能しか持たない trivial packages と実行可能なロジックを含まない data-only packages を対象にそれらの普及状況とセキュリティリスクを調査しています発表ではこれらのパッケージを検出するための規則ベース静的解析手法を開発し2025年時点の npm エコシステムにおけるリスク評価を行いました
分析の結果パッケージの 17.92%が trivial packages に分類されその脆弱性レベルは非 trivial パッケージと同程度であることが示されました。またdata-only packages は頻度こそ低いものの依然としてリスクを含むことも確認されました。提案手法による検出ツールは94%の精度(macro-F1 0.87)を達成し大規模解析やセキュリティリスク低減に有用であることが示されました

Copilot uses AI. Check for mistakes.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

これは無視




![](IMG_Amy.jpg)

![](IMG_Tonnam.jpeg)