VLDB 2026 Research / reviewers in the wild / expert
Vittunyuta Maeprasart
dblp:314/3554
· DBLP profile ↗
5ranked-venue papers
3as first author
4since 2021 · last 2024
0000-0002-6247-280XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Drop it All or Pick it Up? How Developers Responded to the Log4JShell VulnerabilityabstractAlthough using third-party libraries has become prevalent in contemporary software development, developers often struggle to update their dependencies. Prior works acknowledge that due to the migration effort, priority and other issues cause lags in the migration process. The common assumption is that developers should drop all other activities and prioritize fixing the vulnerability. Our objective is to understand developer behavior when facing high-risk vulnerabilities in their code. We explore the prolific, and possibly one of the cases of the Log4JShell, a vulnerability that has the highest severity rating ever, which received widespread media attention. Using a mixed-method approach, we analyze 219 GitHub Pull Requests (PR) and 354 issues belonging to 53 Maven projects affected by the Log4JShell vulnerability. Our study confirms that developers show a quick response taking from 5 to 6 days. However, instead of dropping everything, surprisingly developer activities tend to increase for all pending issues and PRs. Developer discussions in-volved either giving information (29.3%) and seeking information (20.6%), which is missing in existing support tools. Leveraging this possibly-one of a kind event, insights opens up a new line of research, causing us to rethink best practices and what developers need in order to efficiently fix vulnerabilities. Vittunyuta Maeprasart, Ali Ouni 0001, Raula Gaikovina Kula |
SERA | 1 |
| 2023 | Understanding the role of external pull requests in the NPM ecosystem
Vittunyuta Maeprasart, Supatsara Wattanakriengkrai, Raula Gaikovina Kula, Christoph Treude, Ken-ichi Matsumoto |
Empir. Softw. Eng. | 1 |
| 2022 | On the Use of Refactoring in Security Vulnerability Fixes: An Exploratory Study on Maven LibrariesabstractThird-party library dependencies are commonplace in today’s software development. With the growing threat of security vulnerabilities, applying security fixes in a timely manner is important to protect software systems. As such, the community developed a list of software and hardware weakness known as Common Weakness Enumeration (CWE) to assess vulnerabilities. Prior work has revealed that maintenance activities such as refactoring code potentially correlate with security-related aspects in the source code. In this work, we explore the relationship between refactoring and security by analyzing refactoring actions performed jointly with vulnerability fixes in practice. We conducted a case study to analyze 143 maven libraries in which 351 known vulnerabilities had been detected and fixed. Surprisingly, our exploratory results show that developers incorporate refactoring operations in their fixes, with 31.9% (112 out of 351) of the vulnerabilities paired with refactoring actions. We envision this short paper to open up potential new directions to motivate automated tool support, allowing developers to deliver fixes faster, while maintaining their code. Ayano Ikegami, Raula Gaikovina Kula, Bodin Chinthanet, Vittunyuta Maeprasart, Ali Ouni 0001, Takashi Ishio, Ken-ichi Matsumoto |
EASE | 4 |
| 2021 | Which Dependency was Updated? Exploring Who Changes Dependencies in npm packagesabstractNowadays, software development increasingly depends on third-party library packages to reuse functionality and save the costs of building themselves. Since dependency is constantly evolving, developers struggle to update dependencies. In this work, we take the first exploration into the responsibility of updating a dependency. Analyzing 89,393 npm packages, we mine the repositories to understand who is the person responsible (i.e., dependency author) for the library update and whether or not the spread of responsibility of updating has an impact on what libraries will get updated. Our results show that 64.24% packages have only one dependency author who is responsible for the dependency. Furthermore, the number of dependency authors correlates with dependency changes, hinting that updating dependencies correlates with having more responsible developers. Lastly, we find that npm packages with just a single dependency author update different libraries compared to those with more dependency authors. Vittunyuta Maeprasart, Ayano Ikegami, Raula Gaikovina Kula, Ken-ichi Matsumoto |
SNPD | 1 |
| 2016 | Enhancing Course Timetable Management in Science Classrooms with User-oriented Mobile Application: Analysis and Prototype Development on KMUTT-ESC Case StudyabstractIn Science schools, one of the challenging issues in learning management is course timetable for both learners and teachers. Unlike regular schools, most Science courses are provided in topic/module-based; that is the topics among courses are associated to each other, managed by several teachers simultaneously, learned by different groups of students, and altered frequently without notice. This causes a crisis for teachers who teach on the same topics being not aware of that changes leading to miss teaching management, while students could not prepare themselves for learning materials, reviews, assignments, etc. accordingly. As technology advances, mobile application has widely been accepted as an effective means to cope various management problems in the real time. Therefore, in this study, we proposed a design of mobile application prototype with user-oriented design to tackle such common problems in Science schools. A case of an Engineering Science School in central Bangkok, Thailand was studied for the actual problems and for the requirement analysis. The application was designed based on users’ UX/UI concepts and mobile platforms; whereas a prototype was developed with xCode based on MVC strategy. This application could help students and teachers to access the real-time changes of the timetable information, including notifications and history revisions; meanwhile, it helps them get ready for the class and finally would enhance more effective learning and teaching in science classrooms. In addition to that, an experiment has been conducted with users to examine the effectiveness of the application, while the feedback has been collected and analyzed for further development. The findings of this study not only showed that the proposed application was more effective than the conventional approach, but also provides any Science schools with similar contexts a practical guideline to cope with such complexity in timetable management ofscience classrooms. Jintana Wongta, Charoenchai Wongwatkit, Jarukit Boonkerd, Ratchapon Chaikajornwat, Vittunyuta Maeprasart, Chonlada Krutthakha |
ICCE | 5 |