VLDB 2026 Research / reviewers in the wild / expert
Sivana Hamer
dblp:292/3179
· DBLP profile ↗
6ranked-venue papers
3as first author
5since 2021 · last 2025
0009-0001-8381-1436ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 5 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Research Directions in Software Supply Chain SecurityabstractReusable software libraries, frameworks, and components, such as those provided by open source ecosystems and third-party suppliers, accelerate digital innovation. However, recent years have shown almost exponential growth in attackers leveraging these software artifacts to launch software supply chain attacks. Past well-known software supply chain attacks include the SolarWinds, log4j, and xz utils incidents. Supply chain attacks are considered to have three major attack vectors: through vulnerabilities and malware accidentally or intentionally injected into open source and third-party dependencies/components/containers ; by infiltrating the build infrastructure during the build and deployment processes; and through targeted techniques aimed at the humans involved in software development, such as through social engineering. Plummeting trust in the software supply chain could decelerate digital innovation if the software industry reduces its use of open source and third-party artifacts to reduce risks. This article contains perspectives and knowledge obtained from intentional outreach with practitioners to understand their practical challenges and from extensive research efforts. We then provide an overview of current research efforts to secure the software supply chain. Finally, we propose a future research agenda to close software supply chain attack vectors and support the software industry. Laurie A. Williams, Giacomo Benedetti, Sivana Hamer, Ranindya Paramitha, Imranur Rahman, Mahzabin Tamanna, Greg Tystahl, Nusrat Zahan, Patrick Morrison, Yasemin Acar, Michel Cukier, Christian Kästner, Alexandros Kapravelos, Dominik Wermke, William Enck |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2025 | Trusting Code in the Wild: Exploring Contributor Reputation Measures to Review Dependencies in the Rust EcosystemabstractDevelopers rely on open-source packages and must review dependencies to safeguard against vulnerable or malicious upstream code. A careful review of all dependencies changes often does not occur in practice. Therefore, developers need signals to inform of dependency changes that require additional examination, particularly measures for contributor reputation. The goal of this study is to help developers prioritize dependency review efforts by analyzing contributor reputation measures as a signal in the Rust ecosystem. We use network centrality measures to proxy contributor reputation using collaboration activity. We employ a mixed method methodology from the top 1,644 packages in the Rust ecosystem to build a network of 6,949 developers, survey 285 developers, and model 5 centrality measures. Through our survey, we find that only 24% of respondents often review dependencies before adding or updating a package, mentioning difficulties in the review process and signals are therefore employed. Particularly, 51% of respondents often consider contributor reputation when reviewing dependencies. We further explore contributor reputation through network centrality measures employing multivariate mixed-effect linear regression models. We find that the closeness centrality measure is a significant factor in explaining how developers choose to review dependencies. Yet, centrality measures alone do not account for how developers choose to review dependencies. We recommend the Rust ecosystem implement a contributor reputation badge based on our modeled coefficients to complement developers’ dependency review efforts. Sivana Hamer, Nasif Imtiaz, Mahzabin Tamanna, Preya Shabrina, Laurie A. Williams |
IEEE Trans. Software Eng. | 1 |
| 2024 | Exploring Students' Behaviors and Perceptions in Continuous Measurement of Software ProjectsabstractContinuous software engineering is increasingly ingrained and widely adopted in development projects. These projects have extended their processes by utilizing software measurement tools with dashboards to monitor and understand development best practices, quality, and evolution. Exploring development perceptions and behaviors in software engineering education and training contexts is needed to better understand how tools could aid development processes. The goal is to explore students' perceptions and development behaviors in software engineering projects that continuously measure contributions. We conducted a case study, mainly focusing on agile software engineering and quality best practices, and gathered behaviors and perceptions through mining repositories and applying surveys. Our results show acceptance of continuous measurement, where most respondents agreed that it benefited their software development process. We found benefits in engineering and quality practices such as continuous integration and configuration management. Some of the perceived benefits related to agile practices did not always align with observed behaviors. Our results suggest that continuous measurement in software engineering education had mostly positive perceptions and outlooks on behaviors. These findings are encouraging for adopters of continuous measurement tools in education and training contexts. Christian Quesada-López, Sivana Hamer, Marcelo Jenkins |
CLEI | 2 |
| 2023 | Software Visualization using the City Metaphor: Students' Perceptions and ExperiencesabstractSoftware visualization is a program comprehension technique that can support activities such as the analysis of the quality during the evolution of development. The empirical evaluation of software visualizations is necessary to provide evidence of perceptions and experiences of use, and the benefits provided during software analysis. Empirical data can help evidence the advantages and limitations of software visualizations, improving their acceptance in academia and industry. This study presents an analysis of the perceptions of 16 participants using a 3D city metaphor visualization to understand the structure of a web application and identify aspects related to development and quality best practices in a software engineering university course. For this, we studied the user experience through the UE Questionnaire (UEQ) and the ease of use, the perceived usefulness, and the intention of future use through the Technology Acceptance Model (TAM). Finally, benefits and opportunities were identified based on the perceptions of the participants and the results of the activity. The results indicate that the visualization of the city can support comprehension activities and help identify improvements in development and quality practices. Furthermore, this tool was positively perceived in the context of software engineering courses. Most of the acceptance and experience constructs were evaluated positively, with some opportunities identified regarding ease of use and visualization comprehension. In general, the visualization helped identify possible opportunities required for software applications under review. Erik Kühlmann, Sivana Hamer, Christian Quesada-López |
CLEI | 2 |
| 2023 | Students' perceptions of integrating a contribution measurement tool in software engineering projectsabstractMeasuring developers’ and teams’ contributions in project-based software engineering courses is challenging. Instructors require measurement tools to identify early improvement opportunities and simplify the assessment of students’ contributions to projects. Besides, students could appreciate detailed, timely, and valuable feedback that encapsulates the multi-faceted nature of their contribution to improve their skills. With the rise of software repositories, data-driven tools that mine and visualize repository data have been proposed to help assess and improve software engineering courses. Still, little is known about students’ perceptions of integrating these tools to measure project contributions. This paper analyzes students’ perceptions of integrating a contribution measurement tool in agile software engineering projects. We collected the perceptions of 65 undergraduate students developing projects through a mixed-method approach. Our results show several benefits of using these tools in software engineering courses, providing valuable feedback, intending to use such tools in projects, and facilitating timely and helpful feedback. Additionally, students described the benefits of nine agile practices, including coding standards, reviews and inspections, and planning games. These tools were perceived as useful, easy to use, and intended to be used in future projects. Six challenges for integrating these tools in a course setting related to adoption, learning curves, configuration issues, measurement completeness, team dynamics, and Goodhart’s law were found. Our results showed the acceptance and utility of such tools to aid students in software engineering projects. Sivana Hamer, Christian Quesada-López, Marcelo Jenkins |
CSEE&T | 1 |
| 2020 | Measuring students' contributions in software development projects using Git metricsabstractMany courses in the software engineering area are centered around team-based project development. Evaluating these projects is a challenge due to the difficulty of measuring individual student contributions versus team contributions. The adoption of distributed version control systems like Git enables the measurement of students' and teams' contributions to the project. In this work, we analyze the contributions within five software development projects from undergraduate courses that used project-based learning. For this, we generate visualizations of aggregated Git metrics using inequality indexes and inter-decile ratios, which offer insights into the practices and processes followed by students and teams throughout the project development. This approach allowed us to identify both inequality among students' contributions and development processes with a non-steady pace, rendering a useful feedback tool for instructors and students during the development of the project. Further studies can be conducted to assess the complexity and value of students' contributions by analyzing their source code commits and other software artifacts. Sivana Hamer, Christian Quesada-López, Alexandra Martínez Porras, Marcelo Jenkins |
CLEI | 1 |