Options
Akronym
DevSSATD
Projekt Titel
Developer-Centred Management of Self-Admitted Technical Debt for Security
Funding code
945.03-956
Startdatum
May 1, 2026
Enddatum
April 30, 2029
Loading...
Funder
Deutsche Forschungsgemeinschaft
Funding Program
Sachbeihilfen
Institut
E-22
Principal Investigator
Diaz Ferreyra, Nicolas E.
Software developers often face complex technical challenges that, for diverse reasons, they circumvent with spurious design workarounds and sub-optimal implementations. Such compromises are likely to result in a significant amount of Technical Debt (TD), namely low-quality artefacts that can impair the future maintenance and evolution of the system being developed. TD is a long-standing, paramount problem in modern software development and it is estimated to cost projects around USD 1.5 million on average to remediate (equivalent to 27,500 developer hours). Moreover, it can introduce exploitable flaws and vulnerabilities that can compromise, to a great extent, the security of software systems. A significant portion of TD research has been conducted thanks to the analysis of Self-Admitted Technical Debt (SATD) sources. That is, artefacts such as code comments and commit messages where developers often report the shortcomings of their solutions. The systematic study of SATD has helped to identify and characterise flaws at different levels, including code, design, requirements, and documentation. Still, the security implications of TD have received little attention from researchers, leaving many open questions about its role in the emergence of software vulnerabilities. This project seeks to be at the forefront of TD security research by shifting the focus towards developer-centred SATD management. Particularly, on how security weaknesses reported inside SATD artefacts can support the timely identification, prioritisation, and repayment of vulnerability-prone TD instances. For this, we will gather actionable information on the interplay between security-related SATD and software vulnerabilities by (i) mining Open Source Software (OSS) repositories and (ii) conducting empirical studies with developers. Such evidence will be translated into the design of novel, Artificial Intelligence-enhanced methods and tools for (i) the automatic identification of such SATD instances, (ii) their security assessment, and (iii) their seamless remediation.