Open source software (OSS) supply chains have been attractive targets for attacks. One of the significant, popular attacks is realized by malicious packages on package registries. NPM, as the largest package registry, has been recently flooded with malicious packages. In response to this severe security risk, many detection tools have been proposed. However, these tools do not model malicious beha...Show More
In recent years, with the widespread attention of academia and industry on the application of large language models (LLMs) to code-related tasks, an increasing number of large code models (LCMs) have been proposed and corresponding evaluation benchmarks have continually emerged. Although existing evaluation benchmarks are helpful for comparing different LCMs, they may not reflect the performance o...Show More
API suggestion is a critical task in modern software development, assisting programmers by predicting and recommending third-party APIs based on the current context. Recent advancements in large code models (LCMs) have shown promise in the API suggestion task. However, they mainly focus on suggesting which APIs to use, ignoring that programmers may demand more assistance while using APIs in practi...Show More
Trustworthy Open Source Software (OSS) development processes are the basis that secures the long-term trustworthiness of soft-ware projects and products. With the aim to investigate the trust-worthiness of the Pull Request (PR) process, the common model of collaborative development in OSS community, we exploit process mining to identify and analyze the normal and anomalous patterns of PR processes...Show More
With the advent of energy crisis, solar energy has been taken seriously. This paper introduces the development status of solar cells, points out the main problems of Chinese photovoltaic industry and the causes of these problems, and finally puts forward related countermeasures to promote the development of PV industry in China.Show More