VLDB 2026 Research / reviewers in the wild / expert
John Steinbacher
dblp:208/6960
· DBLP profile ↗
9ranked-venue papers
0as first author
8since 2021 · last 2025
0009-0001-6572-6326ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 6 · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Threat-Oriented Study of API Security Challenges in CI/CD PipelinesabstractAPls (Application Programming Interfaces) playa crucial role in modern software engineering, where CI/CD (Continuous Integration/Continuous Deployment) pipelines are closely aligned, enabling automated workflows across source control, builds, secrets management, and deployment. However, these same APls can expose serious security risks, especially when tokens are overprivileged, secrets are hardcoded, or configurations are left open. This paper reviews 33 studies to examine how such vulnerabilities appear across different pipeline stages. We identified recurring issues, including dependency confusion attacks, misconfigured Y AML files, and credential leaks caused by API misuse. Despite the availability of tools and best practices, most research focuses on static checks and overlooks runtime behaviours, multi-stage attack paths, and privilege escalation risks. Based on these patterns, we propose a practical threat taxonomy that connects API threats to specific CI/CD stages and attacker goals, aiming to support more grounded threat modelling in DevOps environments. Sabbir M. Saleh, Md Nafiz Al Ifat, Nazim H. Madhavji, John Steinbacher |
CloudCom | 4 |
| 2025 | Towards a Blockchain-Based CI/CD Framework to Enhance Security in Cloud EnvironmentsabstractSecurity is becoming a pivotal point in cloud platforms. Several divisions, such as business organisations, health care, government, etc., have experienced cyber-attacks on their infrastructures. This research focuses on security issues within Continuous Integration and Deployment (CI/CD) pipelines in a cloud platform as a reaction to recent cyber breaches. This research proposes a blockchain-based solution to enhance CI/CD pipeline security. This research aims to develop a framework that leverages blockchain's distributed ledger technology and tamper-resistant features to improve CI/CD pipeline security. The goal is to emphasise secure software deployment by integrating threat modelling frameworks and adherence to coding standards. It also aims to employ tools to automate security testing to detect publicly disclosed vulnerabilities and flaws, such as an outdated version of Java Spring Framework, a JavaScript library from an unverified source, or a database library that allows SQL injection attacks in the deployed software through the framework. Sabbir M. Saleh, Nazim H. Madhavji, John Steinbacher |
ENASE | 3 |
| 2025 | Understanding Everything as Code: A Taxonomy and Conceptual ModelabstractBackground: Everything as Code (EaC) is an emerging paradigm aiming to codify all aspects of modern software systems. Despite its growing popularity, comprehensive industry standards and peer-reviewed research clarifying its scope and guiding its adoption remain scarce. Aims: This study systematically analyzes existing knowledge and perceptions of EaC, clarifies its scope and boundaries, and provides structured guidance for researchers and practitioners. Method: We conducted a largescale multivocal literature review (MLR), synthesizing academic and grey literature sources. Findings were analyzed quantitatively and thematically. Based on this analysis, we developed a taxonomy and conceptual model of EaC, validated through collaboration with industry experts. Results: The resulting taxonomy comprises$\mathbf{2 5}$distinct EaC practices organized into six layers based on industry awareness and functional roles. The conceptual model illustrates focus areas, overlaps, and interactions among these EaC practices within the software delivery lifecycle. Additionally, practical code examples demonstrating the implementation of these practices were developed in collaboration with industry experts. Conclusions: This work addresses the current scarcity of academic discourse on EaC by providing the first comprehensive taxonomy and conceptual model. These contributions enhance conceptual clarity, offer actionable guidance to practitioners, and lay the groundwork for future research in this emerging domain. Nazim H. Madhavji, John Steinbacher |
ESEM | 3 |
| 2025 | A Map of Cloud-Native Practices and Tools to Achieve Desirable System Qualities
Nazim H. Madhavji, John Steinbacher |
ICSA | 3 |
| 2025 | A Framework for Reusable Infrastructure as Code Templates in Cloud-Native EnvironmentsabstractCloud-native technologies enable the development of scalable, secure, and resilient applications in diverse cloud environments. However, deploying and configuring these technologies can be complex and error-prone. Existing reusable Infrastructure as Code (IaC) solutions often suffer from inconsistent structures, limited customization, and potential vendor lock-in, hindering their effectiveness and usability. To mitigate this, this paper presents a framework for creating standardized and reusable IaC templates for deploying and configuring cloud-native infrastructure components. We conducted a needs analysis to identify key developer requirements and established ten design principles for creating reusable IaC templates. Additionally, we conducted a multivocal review of relevant literature to summarize best practices for implementing these principles. Leveraging these insights, we developed five IaC templates and evaluated their effectiveness and usability against existing solutions. This proposed framework integrates conceptual guidance with practical implementations of reusable templates to simplify cloud-native infrastructure setup and enhance developer productivity. Nazim H. Madhavji, John Steinbacher |
ICSR | 3 |
| 2025 | A Reference Architecture for Governance of Cloud Native ApplicationsabstractThe evolution of cloud computing has given rise to Cloud Native Applications (CNAs), presenting new challenges in governance, particularly when faced with strict compliance requirements. This work explores the unique characteristics of CNAs and their impact on governance. We introduce a comprehensive reference architecture designed to streamline governance across CNAs, along with a sample implementation, offering insights for both single and multi-cloud environments. Our architecture seamlessly integrates governance within the CNA framework, adhering to a “battery-included” philosophy. Tailored for both expansive and compact CNA deployments across various industries, this design enables cloud practitioners to prioritize product development by alleviating the complexities associated with governance. In addition, it provides a building block for academic exploration of generic CNA frameworks, highlighting their relevance in the evolving cloud computing landscape. William Pourmajidi, Lei Zhang 0078, John Steinbacher, Tony Erwin, Andriy V. Miranskyy |
IEEE Trans. Cloud Comput. | 3 |
| 2024 | A Systematic Literature Review on Continuous Integration and Deployment (CI/CD) for Secure Cloud ComputingabstractAs cloud environments become widespread, cybersecurity has emerged as a top priority across areas such as networks, communication, data privacy, response times, and availability. Various sectors, including industries, healthcare, and government, have recently faced cyberattacks targeting their computing systems. Ensuring secure app deployment in cloud environments requires substantial effort. With the growing interest in cloud security, conducting a systematic literature review (SLR) is critical to identifying research gaps. Continuous Software Engineering, which includes continuous integration (CI), delivery (CDE), and deployment (CD), is essential for software development and deployment. In our SLR, we reviewed 66 papers, summarising tools, approaches, and challenges related to the security of CI/CD in the cloud. We addressed key aspects of cloud security and CI/CD and reported on tools such as Harbor, SonarQube, and GitHub Actions. Challenges such as image manipulation, unauthorised access, and weak authentication were highlighted. The review also uncovered research gaps in how tools and practices address these security issues in CI/CD pipelines, revealing a need for further study to improve cloud-based security solutions. Sabbir M. Saleh, Nazim H. Madhavji, John Steinbacher |
WEBIST | 3 |
| 2023 | Immutable Log Storage as a Service on Private and Public BlockchainsabstractService Level Agreements (SLA) are employed to ensure the performance of Cloud solutions. When a component fails, the importance of logs increases significantly. All departments may turn to logs to determine the cause of the issue and find the party at fault. The party at fault may be motivated to tamper with the logs to hide their role. We argue that the critical nature of Cloud logs calls for immutability and verification mechanism without the presence of a single trusted party. This article proposes such a mechanism by describing a blockchain-based log storage system, called Logchain, which can be integrated with existing private and public blockchain solutions. Logchain uses the immutability feature of blockchain to provide a tamper-resistance platform for log storage. Additionally, we propose a hierarchical structure to address blockchains’ scalability issues. To validate the mechanism, we integrate Logchain into Ethereum and IBM Blockchain. We show that the solution is scalable and perform the analysis of the cost of ownership to help a reader select an implementation that would address their needs. The Logchain's scalability improvement on a blockchain is achieved without any alteration of blockchains’ fundamental architecture. As shown in this work, it can function on private and public blockchains and, therefore, can be a suitable alternative for organizations that need a secure, immutable log storage platform. William Pourmajidi, Lei Zhang 0078, John Steinbacher, Tony Erwin, Andriy V. Miranskyy |
IEEE Trans. Serv. Comput. | 3 |
| 2017 | Supporting Microservice EvolutionabstractMicroservices have become a popular pattern for deploying scale-out application logic and are used at companies like Netflix, IBM, and Google. An advantage of using microservices is their loose coupling, which leads to agile and rapid evolution, and continuous re-deployment. However, developers are tasked with managing this evolution and largely do so manually by continuously collecting and evaluating low-level service behaviors. This is tedious, error-prone, and slow. We argue for an approach based on service evolution modeling in which we combine static and dynamic information to generate an accurate representation of the evolving microservice-based system. We discuss how our approach can help engineers manage service upgrades, architectural evolution, and changing deployment trade-offs. Adalberto R. Sampaio, Harshavardhan Kadiyala, John Steinbacher, Tony Erwin, Nelson Souto Rosa, Ivan Beschastnikh, Julia Rubin |
ICSME | 4 |