VLDB 2026 Research / reviewers in the wild / expert
Ann Marie Reinhold
dblp:236/9856
· DBLP profile ↗
3ranked-venue papers
0as first author
3since 2021 · last 2026
0000-0003-0411-3486ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Standards to Practice: A Position on Challenges in Operationalizing Software Quality-in-Use
Yvette D. Hastings, Ann Marie Reinhold |
ENASE (1) | 2 |
| 2026 | Barriers to Use: Perspectives on Environmental Research Software
Yvette D. Hastings, Jeffrey C. Carver, Clemente Izurieta, Ann Marie Reinhold |
ICSOFT | 4 |
| 2024 | Deciphering Discrepancies: A Comparative Analysis of Docker Image SecurityabstractAs the use of microservices continues to grow and become a foundational approach to architecting software solutions, ensuring the security of microservices is paramount. Docker images have emerged as the predominant solution to containerize microservices-and thus, Docker images are becoming a large attack surface. Thus, reducing vulnerabilities in Docker images will reduce microservice cyberattacks. A common way to find vulnerabilities in Docker images employs static analysis tools like Trivy and Grype. However, these tools frequently generate disparate vulnerability reports when analyzing the same Docker image, thus causing uncertainty in tool selection. We collected 927 Docker images, analyzed them with Trivy and Grype, and compared the vulnerabilities reported in each image. Among the 865 images found to have vulnerabilities, Trivy and Grype disagreed on both the number of vulnerabilities and the vulnerability IDs found therein. Since both tools interface with external vulnerability databases, some discrepancies can be attributed to how the tools interface with these external resources. The external vulnerability databases partially overlap and frequently contradict one another, thereby creating challenges for static analysis tool developers and end users alike. This New Ideas and Emerging Results (NIER) study contains new and critical information that practitioners need for selecting and using static analysis tools-given that increases in the use of Docker technologies means increases in the size of the attack surfaces. Brittany Boles, Eric O'Donoghue, Assoumer Redempta Manzi Muneza, Garrett Perkins, Clemente Izurieta, Ann Marie Reinhold |
SCAM | 6 |