EDBT 2026 Demo / reviewers in the wild / expert
Thanwadee Sunetnanta
dblp:05/6316
· DBLP profile ↗
31ranked-venue papers
0as first author
19since 2021 · last 2026
0000-0002-1436-0352ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 26 · 17 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Security by documentation? characterizing GitHub SECURITY.md policy and their adoption in Python librariesabstractWith security in open-source software development increasingly becoming crucial, security policies are one way to manage vulnerabilities and guide users toward safe practices. To support secure development, platforms like GitHub provide a dedicated section for security policies within repositories. Existing studies focus on the adoption of security policies. However, the detailed content of the security policies has not been examined. Our study aims to fill this gap by analyzing the security policies of 679 PyPI Python libraries hosted on GitHub. We examine the characteristics and content of existing policies and investigate the relationship with project characteristics and recommended security practices by comparing security practice assessments between projects with and without established security policies. The result indicates that projects with security.md shows stronger recommended security practices. This study highlights the importance of adopting a clear and comprehensive security policy to enhance the overall security practices of open-source projects. Morakot Choetkiertikul, Sushawapak Kancharoendee, Chanikarn Jongyingyos, Thanat Phichitphanphong, Chaiyong Ragkhitwetsagul, Brittany Reid, Raula Gaikovina Kula, Thanwadee Sunetnanta |
Empir. Softw. Eng. | 8 |
| 2026 | Automated software engineering knowledge transfer: A case study on small and medium-sized software enterprises in Thailandabstract• ASE knowledge transfer activities were somewhat successful in increasing the awareness and the adoption of ASE tools and techniques in four Thai SSMEs. • Knowledge transfer activities should be tailored to the needs of the SSMEs. • The support from researchers is crucial for the successful adoption of ASE tools and techniques in SSMEs. • The study involving SSMEs needs to be aware of their rapid changes of teams and projects. Knowledge transfer of ASE tools and techniques to Small and Medium-sized Software Enterprises (SSMEs) is a challenging task due to their limited resources. The presented case study performed knowledge transfer interventions within four SSMEs in Thailand, using multiple activities including training, online questionnaires, ASE tool adoption, retrospective meetings, and an overall project evaluation. We found that while the knowledge transfer activities were successful in increasing awareness, the degree of adoption success varied significantly. The companies successfully adopted SonarQube, a tool with a low adoption cost, but struggled to implement unit testing, which demands a high, distributed effort from the entire team. The key lessons learned from this project are that (1) knowledge transfer activities with SSMEs should begin with foundational practices over advanced ASE techniques, (2) ASE tools with low adoption cost and wide benefits (SonarQube) lead to more successful adoption than tools with high adoption cost (unit testing), (3) the researchers must overcome the knowing-doing gap by providing embedded support to the SSMEs, and (4) future knowledge transfer projects must include SSMEs as one of the main target groups. Chaiyong Ragkhitwetsagul, Jens Krinke, Morakot Choetkiertikul, Thanwadee Sunetnanta, Federica Sarro |
J. Syst. Softw. | 4 |
| 2025 | PromptOps: Automated Tool for Testing Trustworthiness of LLMsabstractLarge Language Models (LLMs) are increasingly utilized in a wide range of natural language processing tasks. Despite their growing adoption, concerns regarding their trustworthiness, i.e., reliability and validity across diverse applications, still remain. This paper introduces a novel visual-based LLM testing tool called PromptOps using the principles of metamorphic testing to assess LLMs beyond traditional accuracy metrics. The tool evaluates LLMs on critical properties such as robustness, fairness, and logical consistency. The tool enables users to design custom test cases via visual programming, define specific prompts, and automatically generate diverse test scenarios. PromptOps fosters greater transparency for model developers by identifying areas for improvement in both performance and fairness. The video demonstration of the PromptOps tool is available at https://youtu.be/M6TbvPIt9kE, and the tool is available at https://github.com/MUICT-SERU/PromptOps. Chommakorn Sontesadisai, Chalisa Sae-Ngow, Jirateep Rudeerudchanawong, Lapatrada Dangsungnoen, Chaiyong Ragkhitwetsagul, Teeradaj Racharak, Thanwadee Sunetnanta |
APSEC | 7 |
| 2025 | Social Media Reactions to Open Source Promotions: AI-Powered GitHub Projects on Hacker NewsabstractSocial media platforms have become more influential than traditional news sources, shaping public discourse and accelerating the spread of information. With the rapid advancement of artificial intelligence (AI), open-source software (OSS) projects can leverage these platforms to gain visibility and attract contributors. In this study, we investigate the relationship between Hacker News, a social news site focused on computer science and entrepreneurship, and the extent to which it influences developer activity on the promoted GitHub AI projects. We analyzed 2,195 Hacker News (HN) stories and their corresponding comments over a two-year period. Our findings reveal that at least 19 % of AI developers promoted their GitHub projects on Hacker News, often receiving positive engagement from the community. By tracking activity on the associated 1,814 GitHub repositories after they were shared on Hacker News, we observed a significant increase in forks, stars, and contributors. These results suggest that Hacker News serves as a viable platform for AI-powered OSS projects, with the potential to gain attention, foster community engagement, and accelerate software development. Prachnachai Meakpaiboonwattana, Warittha Tarntong, Thai Mekratanavorakul, Chaiyong Ragkhitwetsagul, Pattaraporn Sangaroonsilp, Raula Gaikovina Kula, Morakot Choetkiertikul, Ken-ichi Matsumoto, Thanwadee Sunetnanta |
ICSME | 9 |
| 2025 | PyGress: Tool for Analyzing the Progression of Code Proficiency in Python OSS ProjectsabstractAssessing developer proficiency in open-source software (OSS) projects is essential for understanding project dynamics, especially for expertise. This paper presents "PyGress", a web-based tool designed to automatically evaluate and visualize Python code proficiency using pycefr, a Python code proficiency analyzer. By submitting a GitHub repository link, the system extracts commit histories, analyzes source code proficiency across CEFR-aligned levels (A1-C2), and generates visual summaries of individual and project-wide proficiency. The PyGress tool visualizes per-contributor proficiency distribution and tracks project code proficiency progression over time. PyGress offers an interactive way to explore contributor coding levels in Python OSS repositories. The video demonstration of the PyGress tool can be found at https://youtu.be/hxoeK-ggcWk, and the source code of the tool is publicly available at https://github.com/MUICT-SERU/PyGress. Rujiphart Charatvaraphan, Bunradar Chatchaiyadech, Thitirat Sukijprasert, Chaiyong Ragkhitwetsagul, Morakot Choetkiertikul, Raula Gaikovina Kula, Thanwadee Sunetnanta, Ken-ichi Matsumoto |
ASE | 7 |
| 2025 | Test It Before You Trust It: Applying Software Testing for Trustworthy In-Context Learning
Teeradaj Racharak, Chaiyong Ragkhitwetsagul, Chommakorn Sontesadisai, Thanwadee Sunetnanta |
NLDB (1) | 4 |
| 2025 | On Categorizing Open Source Software Security Vulnerability Reporting Mechanisms on GitHubabstractOpen-source projects are essential to software de-velopment, but publicly disclosing vulnerabilities without fixes increases the risk of exploitation. The Open Source Security Foundation (OpenS SF) addresses this issue by promoting robust security policies to enhance project security. Current research reveals that many projects perform poorly on OpenS SF criteria, indicating a need for stronger security practices and underscoring the value of SECURITY.md files for structured vulnerability re-porting. This study aims to provide recommendations for improving security policies. By examining 679 open-source projects, we find that email is still the main source of reporting. Furthermore, we find that projects without SECURITY.md files tend to be less secure (lower OpenSSF scores). Our analysis also indicates that, although many maintainers encourage private reporting methods, some contributors continue to disclose vulnerabilities publicly, bypassing established protocols. The results from this preliminary study pave the way for understanding how developers react and communicate a potential security threat. Future challenges include understanding the impact and effectiveness of these mechanisms and what factors may influence how the security threat is addressed. Sushawapak Kancharoendee, Thanat Phichitphanphong, Chanikarn Jongyingyos, Brittany Reid, Raula Gaikovina Kula, Morakot Choetkiertikul, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta |
SANER | 8 |
| 2025 | Sprint2Vec: A Deep Characterization of Sprints in Iterative Software DevelopmentabstractIterative approaches like Agile Scrum are commonly adopted to enhance the software development process. However, challenges such as schedule and budget overruns still persist in many software projects. Several approaches employ machine learning techniques, particularly classification, to facilitate decision-making in iterative software development. Existing approaches often concentrate on characterizing a sprint to predict solely productivity. We introduce Sprint2Vec, which leverages three aspects of sprint information – sprint attributes, issue attributes, and the developers involved in a sprint, to comprehensively characterize it for predicting both productivity and quality outcomes of the sprints. Our approach combines traditional feature extraction techniques with automated deep learning-based unsupervised feature learning techniques. We utilize methods like Long Short-Term Memory (LSTM) to enhance our feature learning process. This enables us to learn features from unstructured data, such as textual descriptions of issues and sequences of developer activities. We conducted an evaluation of our approach on two regression tasks: predicting the deliverability (i.e., the amount of work delivered from a sprint) and quality of a sprint (i.e., the amount of delivered work that requires rework). The evaluation results on five well-known open-source projects (Apache, Atlassian, Jenkins, Spring, and Talendforge) demonstrate our approach's superior performance compared to baseline and alternative approaches. Morakot Choetkiertikul, Peerachai Banyongrakkul, Chaiyong Ragkhitwetsagul, Suppawong Tuarob, Khanh Hoa Dam, Thanwadee Sunetnanta |
IEEE Trans. Software Eng. | 6 |
| 2024 | DEV-EYE: A Tool for Monitoring Bus Factor Using Commit HistoryabstractHigh turnover rates in software development present significant challenges, impacting project continuity, reliability, and quality. The bus factor metric helps quantify and indicate risks associated with key personnel dependencies. Existing tools are designed to calculate the bus factor using information from software project repositories and to determine code ownership. However, given that the bus factor should be monitored over time and the nature of projects varies, a bus factor tool must offer the capability to adjust timelines and customize analysis parameters to accommodate different project constraints. To address these gaps, we introduce DEV-EYE, a tool designed to compute and visualize the bus factor using git commit history. DEV-EYE identifies potential bus factors and offers flexible configuration options, allowing users to adjust parameters such as ownership thresholds and analysis timeframes. Additionally, DEV-EYE enables the comparison of current bus factors with historical data, providing a comprehensive view of project dy-namics. Preliminary evaluations indicate that DEV-EYE is highly promising for real-world applications, emphasizing its role in proactive risk management by identifying critical dependencies and promoting knowledge sharing within teams. Dan Muhindo Kazimoto, Morakot Choetkiertikul, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta |
APSEC | 4 |
| 2024 | Mastering basic Sorting Algorithms through Computational Thinking Activities for EveryoneabstractSorting is an algorithmic concept that is covered in every fundamental computer science and engineering course and included in most if not all programming competitions. It is an everyday task, self-taught and done naturally even by a small child. In spite of its ingenuousness, mastering sorting algorithms turns out to be not so simple for many first-time programmers. This happens because how humans perform sorting is far from being straightforwardly aligned with machine instructions. We have developed an unplugged game-based learning activity that aims not only to tackle this difficult dilemma but also to promote computational thinking practice. Our game robustly challenges audiences to complete a fun sorting task algorithmically and the building blocks of the exercise are methodologically grounded in the four cornerstones of computational thinking. Participants are gently guided through solving a problem by decomposing it, recognizing patterns, applying abstraction, writing step-by-step instructions, and finally arriving at a programmable solution. Our design is largely flexible. The game can be played in small groups or larger ones. It uses only common, readily accessible materials, and is easily adaptable to different levels of audiences, from the interested general public to secondary school students and teachers, to non-computer science undergraduates and those majoring in engineering or information technology related subjects. We have implemented this activity in our classrooms and conducted several workshops. Responses were markedly positive. Engaged from the beginning to the end, participants enjoyed the activity, having fun sorting. Appreciated the ideas, audiences were captivated by many surprising challenges. Most notably, they were able to comprehend the concepts of sorting algorithms and the computational steps behind them, and gain a better understanding of computational thinking. Piyanuch Silapachote, Ananta Srisuphab, Apirak Hoonlor, Thanwadee Sunetnanta |
EDUCON | 4 |
| 2024 | jscefr: A Framework to Evaluate the Code Proficiency for JavaScriptabstractIn this paper, we present jscefr (pronounced jes-cee-fer), a tool that detects the use of different elements of the JavaScript (JS) language, effectively measuring the level of proficiency required to comprehend and deal with a fragment of JavaScript code in software maintenance tasks. Based on the pycefr tool, the tool incorporates JavaScript elements and the well-known Common European Framework of Reference for Languages (CEFR) and utilizes the official ECMAScript JavaScript documentation from the Mozilla Developer Network. jscefr categorizes JS code into six levels based on proficiency. jscefr can detect and classify 138 different JavaScript code constructs. To evaluate, we apply our tool to three JavaScript projects of the NPM ecosystem, with interesting results. A video demonstrating the tool's availability and usage is available at https://youtu.be/Ehh-Prq59Pc. Chaiyong Ragkhitwetsagul, Komsan Kongwongsupak, Thanakrit Maneesawas, Natpichsinee Puttiwarodom, Ruksit Rojpaisarnkit, Morakot Choetkiertikul, Raula Gaikovina Kula, Thanwadee Sunetnanta |
ICSME | 8 |
| 2024 | Adoption of automated software engineering tools and techniques in ThailandabstractAbstract Readiness for the adoption of Automated Software Engineering (ASE) tools and techniques can vary according to the size and maturity of software companies. ASE tools and techniques have been adopted by large or ultra-large software companies. However, little is known about the adoption of ASE tools and techniques in small and medium-sized software enterprises (SSMEs) in emerging countries, and the challenges faced by such companies. We study the adoption of ASE tools and techniques for software measurement, static code analysis, continuous integration, and software testing, and the respective challenges faced by software developers in Thailand, a developing country with a growing software economy which mainly consists of SSMEs (similar to other developing countries). Based on the answers from 103 Thai participants in an online survey, we found that Thai software developers are somewhat familiar with ASE tools and agree that adopting such tools would be beneficial. Most of the developers do not use software measurement or static code analysis tools due to a lack of knowledge or experience but agree that their use would be useful. Continuous integration tools have been used with some difficulties. Lastly, although automated testing tools are adopted despite several serious challenges, many developers are still testing the software manually. We call for improvements in ASE tools to be easier to use in order to lower the barrier to adoption in small and medium-sized software enterprises (SSMEs) in developing countries. Chaiyong Ragkhitwetsagul, Jens Krinke, Morakot Choetkiertikul, Thanwadee Sunetnanta, Federica Sarro |
Empir. Softw. Eng. | 4 |
| 2023 | Microusity: A testing tool for Backends for Frontends (BFF) Microservice SystemsabstractMicroservice software architecture is more scalable and efficient than its monolithic predecessor. Despite its increasing adoption, microservices might expose security concerns and issues that are distinct from those associated with monolithic designs. We propose Microusity, a tool that performs RESTful API testing on a specific type of microservice pattern called backends for frontends (BFF). We design a novel approach to trace BFF requests using the port mapping between requests to BFF and the sub-requests sent to backend microservices. Furthermore, our tool can pinpoint which of the backend service causing the internal server error, which may lead to unhandled errors or vulnerabilities. Microusity provides an error report and a graph visualization that reveal the source of the error and supports developers in comprehension and debugging of the errors. The evaluation of eight software practitioners shows that Microusity and its test reports are useful for investigating and understanding problems in BFF systems. The prototype tool and the video demo of the tool can be found at https://github.com/MUICT-SERU/MICROUSITY. Pattarakrit Rattanukul, Chansida Makaranond, Pumipat Watanakulcharus, Chaiyong Ragkhitwetsagul, Tanapol Nearunchorn, Vasaka Visoottiviseth, Morakot Choetkiertikul, Thanwadee Sunetnanta |
ICPC | 8 |
| 2023 | Studying the association between Gitcoin's issues and resolving outcomes
Morakot Choetkiertikul, Arada Puengmongkolchaikit, Pandaree Chandra, Chaiyong Ragkhitwetsagul, Rungroj Maipradit, Hideaki Hata, Thanwadee Sunetnanta, Ken-ichi Matsumoto |
J. Syst. Softw. | 7 |
| 2022 | Reusing My Own Code: Preliminary Results for Competitive Coding in Jupyter NotebooksabstractThe reuse of already existing code is widely considered a popular software development practice, that provides both benefits and drawbacks for all stakeholders involved. Prior work reports on how code reuse is a common practice in software development projects and data science projects such as machine learning pipelines. Recently, there has been much code reuse work in the context of competitive programming. Although there is work such as detecting plagiarism, there is no work that studies how a competitor will reuse their own code. In this paper, we present a preliminary study on the code reuse behavior of three grandmasters’ Jupyter notebooks in the Kaggle Competitions, an online competition platform for data scientists, and report the types of code they often reuse. Grandmasters are the highest level reached in competitions (novice, expert, master, and grandmaster). We find that Grandmasters are less likely to reuse specialized code, but instead, tend to reuse common functions like importing packages (importing the pandas library). They are most likely to reuse common abstractions like importing packages, configurations, file IO operations, show data, plotting graphs, defining functions, and exploring files. The work opens up new research potential into recommending how developers can reuse their own code. Natanon Ritta, Tasha Settewong, Raula Gaikovina Kula, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta, Ken-ichi Matsumoto |
APSEC | 5 |
| 2022 | Why Visualize Data When Coding? Preliminary Categories for Coding in Jupyter NotebooksabstractData visualization becomes a crucial component in data analytics, especially data exploration, understanding, and analysis. Effective data visualization impacts decision-making and aids in discovering and understanding relationships. It leads to benefits in data-intensive software development tasks e.g., feature engineering in machine learning-based software projects. However, it is unknown how visualizations are used in competitive programming. The idea of this paper is to report early results on what visualizations are prevalent in competitive programming. Grandmasters are the highest level reached in competitions (novice, expert, master, and grandmaster). Analyzing the visualizations of 7 high-rank competitors (i.e., Grandmaster) in Kaggle, we identify and present a catalog of visualizations used to both tell a story from the data, as well as explain the process and pipelines involved to explain their coding solutions. Our taxonomy includes nine types from over 821 visualizations in 68 instances of Jupyter notebooks. Furthermore, most visualizations are for data analysis for distribution (DA Distribution), and frequency (DA Frequency) are most used. We envision that this catalog can be useful to better understand different situations in which to employ these visualizations. Tasha Settewong, Natanon Ritta, Raula Gaikovina Kula, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta, Ken-ichi Matsumoto |
APSEC | 5 |
| 2022 | V-Achilles: An Interactive Visualization of Transitive Security VulnerabilitiesabstractA key threat to the usage of third-party dependencies has been the threat of security vulnerabilities, which risks unwanted access to a user application. As part of an ecosystem of dependencies, users of a library are prone to both the direct and transitive dependencies adopted into their applications. Recent work involves tool supports for vulnerable dependency updates, rarely showing the complexity of the transitive updates. In this paper, we introduce our solution to support vulnerability updating in npm. V-Achilles is a prototype that shows a visualization (i.e., using dependency graphs) affected by vulnerability attacks. In addition to the tool overview, we highlight three use cases to demonstrate the usefulness and application of our prototype with real-world npm packages. The prototype is available at https://github.com/MUICT-SERU/V-Achilles, with an accompanying video demonstration at https://www.youtube.com/watch?v=tspiZfhMNcs. Vipawan Jarukitpipat, Klinton Chhun, Wachirayana Wanprasert, Chaiyong Ragkhitwetsagul, Morakot Choetkiertikul, Thanwadee Sunetnanta, Raula Gaikovina Kula, Bodin Chinthanet, Takashi Ishio, Ken-ichi Matsumoto |
ASE | 6 |
| 2022 | Identifying Software Engineering Challenges in Software SMEs: A Case Study in ThailandabstractSmall and medium-sized software enterprises (SSMEs) are a vital part of emerging markets. Due to their size, they are not capable of adopting advanced software engineering techniques or automated software engineering tools in the same way large and ultra-large companies are. We study the software engineering challenges in SSMEs in Thailand, an emerging market in software development, using semi-structured interviews with four SSMEs. After performing a thematic analysis of the interview transcripts, we found a number of common challenges such as lack of testing, code-related issues, and inaccurate effort estimation. We observed that in order to introduce advanced automated software engineering tools and techniques, SSMEs need to adopt contemporary best practices in software engineering like automated testing, continuous integration and automated code review. Moreover, we suggest that software engineering research engage with SSMEs to enable them to improve their knowledge and adopt more advanced software engineering practices. Chaiyong Ragkhitwetsagul, Jens Krinke, Morakot Choetkiertikul, Thanwadee Sunetnanta, Federica Sarro |
SANER | 4 |
| 2021 | FixMe: A GitHub Bot for Detecting and Monitoring On-Hold Self-Admitted Technical DebtabstractSelf-Admitted Technical Debt (SATD) is a special form of technical debt in which developers intentionally record their hacks in the code by adding comments for attention. Here, we focus on issue-related "On-hold SATD", where developers suspend proper implementation due to issues reported inside or outside the project. When the referenced issues are resolved, the On-hold SATD also need to be addressed, but since monitoring these issue reports takes a lot of time and effort, developers may not be aware of the resolved issues and leave the On-hold SATD in the code. In this paper, we propose FixMe, a GitHub bot that helps developers detecting and monitoring On-hold SATD in their repositories and notify them whenever the On-hold SATDs are ready to be fixed (i.e. the referenced issues are resolved). The bot can automatically detect On-hold SATD comments from source code using machine learning techniques and discover referenced issues. When the referenced issues are resolved, developers will be notified by FixMe bot. The evaluation conducted with 11 participants shows that our FixMe bot can support them in dealing with On-hold SATD. FixMe is available at https://www.fixmebot.app/ and FixMe's VDO is at https://youtu.be/YSz9kFxN_YQ. Saranphon Phaithoon, Supakarn Wongnil, Patiphol Pussawong, Morakot Choetkiertikul, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta, Rungroj Maipradit, Hideaki Hata, Ken-ichi Matsumoto |
ASE | 6 |
| 2020 | Teddy: Automatic Recommendation of Pythonic Idiom Usage For Pull-Based Software ProjectsabstractPythonic code is idiomatic code that follows guiding principles and practices within the Python community. Offering performance and readability benefits, Pythonic code is claimed to be widely adopted by experienced Python developers, but can be a learning curve to novice programmers. To aid with Pythonic learning, we create an automated tool, called Teddy, that can help checking the Pythonic idiom usage. The tool offers a prevention mode with Just-In-Time analysis to recommend the use of Pythonic idiom during code review and a detection mode with historical analysis to run a thorough scan of idiomatic and non-idiomatic code. In this paper, we first describe our tool and an evaluation of its performance. Furthermore, we present a case study that demonstrates how to use Teddy in a real-life scenario on an Open Source project. An evaluation shows that Teddy has high precision for detecting Pythonic idiom and non-Pythonic code. Using interactive visualizations, we demonstrate how novice programmers can navigate and identify Pythonic idiom and non-Pythonic code in their projects. Our video demo with the full interactive visualizations is available at https://youtu.be/vOCQReSvBxA. Purit Phan-Udom, Naruedon Wattanakul, Tattiya Sakulniwat, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta, Morakot Choetkiertikul, Raula Gaikovina Kula |
ICSME | 5 |
| 2020 | JITBot: An Explainable Just-In-Time Defect Prediction BotabstractJust-In-Time (JIT) defect prediction is a classification model that is trained using historical data to predict bug-introducing changes. However, recent studies raised concerns related to the explainability of the predictions of many software analytics applications (i.e., practitioners do not understand why commits are risky and how to improve them). In addition, the adoption of Just-In-Time defect prediction is still limited due to a lack of integration into CI/CD pipelines and modern software development platforms (e.g., GitHub). In this paper, we present an explainable Just-In-Time defect prediction framework to automatically generate feedback to developers by providing the riskiness of each commit, explaining why such commit is risky, and suggesting risk mitigation plans. The proposed framework is integrated into the GitHub CI/CD pipeline as a GitHub application to continuously monitor and analyse a stream of commits in many GitHub repositories. Finally, we discuss the usage scenarios and their implications to practitioners. The VDO demonstration is available at https://jitbot-tool.github.io/ Chaiyakarn Khanan, Worawit Luewichana, Krissakorn Pruktharathikoon, Jirayus Jiarpakdee, Chakkrit Tantithamthavorn, Morakot Choetkiertikul, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta |
ASE | 8 |
| 2020 | Illegal Logging Listeners Using IoT NetworksabstractProtecting and increasing worldwide green space have been an international effort. Individuals and organizations are encouraged to plant urban trees and to get involved in many reforestation and restoration projects. Offsetting these much needed plans to save the forests is illegal logging. Trees that have grown for many years, some are protected resources inside restricted areas, are felled and the wood is smuggled. Watching for these illegal activities is very difficult and also very dangerous. It is quite impossible for rangers to patrol every entry and exit point of forests that cover thousands of squared kilometers. Applying Internet of Things technology to ecological forestry, we are proposing integrating sound acquisition networks and acoustic signal analyzers to enhance the robustness of an already successful camera-based surveillance solution that is also equipped with a global positioning system tracker. Our listener devices record sounds of the forest and periodically send it to a cloud storage over cellular networks. The device is affordable, the system is small and portable, and the network is flexibly extensible. From the data, acoustic features are extracted and visualized. The Mel-frequency cepstral coefficients of the signals have exhibited promising distinctiveness for detection of illegal chainsaw activities in the wild. Ananta Srisuphab, Nopparat Kaakkurivaara, Piyanuch Silapachote, Kitipong Tangkit, Ponthep Meunpong, Thanwadee Sunetnanta |
TENCON | 6 |
| 2019 | Automatic Classifying Self-Admitted Technical Debt Using N-Gram IDFabstractTechnical Debt (TD) introduces a quality problem and increases maintenance cost since it may require improvements in the future. Several studies show that it is possible to automatically detect TD from source code comments that developers intentionally created, so-called self-admitted technical debt (SATD). Those studies proposed to use binary classification technique to predict whether a comment shows SATD. However, SATD has different types (e.g. design SATD and requirement SATD). In this paper, we therefore propose an approach using N-gram Inverse Document Frequency (IDF) and employ a multi-class classification technique to build a model that can identify different types of SATD. From the empirical evaluation on 10 open-source projects, our approach outperforms alternative methods (e.g. using BOW and TF-IDF). Our approach also improves the prediction performance over the baseline benchmark by 33%. Supatsara Wattanakriengkrai, Napat Srisermphoak, Sahawat Sintoplertchaikul, Morakot Choetkiertikul, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta, Hideaki Hata, Ken-ichi Matsumoto |
APSEC | 6 |
| 2017 | Structuring the Knowledge for Software Process Appraisal towards Semi-Automated SupportabstractA process of software process appraisal intensively requires tacit knowledge and expertise from appraisal team to collect data, review documents, interview appraisal participants, analyze, verify and validate objective evidence. In an attempt to automate such a process, the knowledge inherent in it must be made explicit and machine-processable. This paper explains how to structure the knowledge for software process appraisal in such a way that we can apply inference engine based on the formal concept analysis (FCA). Thus, we can use the engine to determine the relations between process activities and standard practices to which they pertain from the knowledge. The structured knowledge and its automated inference will help reduce the efforts in examining information about the practices implemented and relate the resultant data to the appraisal reference model. Suppasit Roongsangjan, Thanwadee Sunetnanta, Pattanasak Mongkolwat |
APSEC | 2 |
| 2014 | A CMMI-Based Automated Risk Assessment FrameworkabstractRisk assessment is crucial to the increase of software development project success. Current risk assessment approaches provide only a rough guide. Risk assessment experts and domain experts are required in conducting risk assessments in software projects. Therefore, traditional risk assessment approaches require extra activities besides development tasks, and possibly leading to extra costs. We believe that an effective risk assessment approach should be transparently embedded in software development process. This paper aims to present an automated risk assessment framework using CMMI and risk taxnomy as a guidance to develop a risk assessment model. A pragmatic approach will be applied as a basis in building this suggested risk prediction model and the case studies of our practice. These studies are considered as our proof of concept. Morakot Choetkiertikul, Khanh Hoa Dam, Aditya Ghose, Thanwadee Sunetnanta |
APSEC (2) | 4 |
| 2012 | Quality indicators on global software development projects: does 'getting to know you' really matter?abstractSUMMARY While the payback from technical training is largely undisputed, and a cost that many organizations are prepared to incur, the benefits of socialization training on global software development projects remains an area of debate. This paper begins to explore whether getting to know those you are working with really matters when it comes to the quality of the software that is produced in global settings. The paper describes how five student teams were put in competition to develop software for a Cambodian client. Each extended team comprised students distributed across a minimum of three locations, drawn from the US, India, Thailand, and Cambodia. Two exercises were conducted with these students during the project, to examine their awareness of the countries of their collaborators and competitors, and to assess their knowledge of their own extended team members. On a weekly basis, the stress levels of the students, along with the communication patterns of each development team, were also recorded. The quality of each team's eventual software product was measured through a final product selection process. The paper reports on the results of these two exercises, examined in conjunction with these additional data, and implications for practice and future studies are discussed. Copyright © 2010 John Wiley & Sons, Ltd. Olly Gotel, Vidya Kulkarni, Moniphal Say, Christelle Scharff, Thanwadee Sunetnanta |
J. Softw. Maintenance Res. Pract. | 5 |
| 2010 | A Risk Assessment Model for Offshoring Using CMMI Quantitative ApproachabstractRisk analysis and assessment obviously provides valuable insights to offshoring projects to identify and evaluate the magnitude of risks associated with the activities and the work products being considered. In offshoring software industry, successful execution of risk analysis drastically relies on strong software process skills and management skills to resolve the differences in cultures, languages, time zones, and development which are used across distributed project teams. One way to ease such differences is to provide a model which offers a rational and automated basis for quantifying and monitoring risks and providing specific decision-making guidance while maintaining the nature of offshoring in a distributed manner. This paper presents an extension of our previous model of quantitative CMMI assessment. We further apply the best practices from the Capability Maturity Model Integration (CMMI) as a guideline for quantitative risk analysis in offshoring and using risk taxonomy from the Software Engineering Institute (SEI) Taxonomy-Based Risk Identification. This work aims to reduce the process overhead of risk assessment by automatically collecting data from the project management repository to adequately and appropriately determine the approximate level of risk in offshoring projects. Morakot Choetkiertikul, Thanwadee Sunetnanta |
ICSEA | 2 |
| 2010 | Ontology-based multiperspective requirements traceability framework
Namfon Assawamekin, Thanwadee Sunetnanta, Charnyote Pluempitiwiriyawej |
Knowl. Inf. Syst. | 2 |
| 2009 | A Global and Competition-Based Model for Fostering Technical and Soft Skills in Software Engineering EducationabstractThe project experience described in this paper builds upon three years of running global software development projects in an educational setting. It explicitly addresses some of the difficulties we have experienced in the past in getting students to deliver a quality software product at the end of a typical semester-long course in which software engineering is taught for the first time while a capstone project is concurrently undertaken. The initiative is unique in that it brings undergraduate, graduate and industry students together in a synergistic manner to capitalize upon individual learning needs and prior skill sets. To focus upon quality, coaches and auditors support traditional student teams with critical technical tasks. Working from identical requirements, a five-way competition affords multiple perspectives, improving the requirements, encouraging design diversity and so increasing the likelihood of the client receiving a deployable product. The fact that the development teams are in different geographic locations and that the software is required for a Cambodian client places soft skills entirely at the forefront. One of the software systems developed during this experience was selected by the client and is now successfully deployed in Cambodia. The paper reports on an educational model that has been seen to deliver results. Olly Gotel, Vidya Kulkarni, Moniphal Say, Christelle Scharff, Thanwadee Sunetnanta |
CSEE&T | 5 |
| 2009 | Quality Indicators on Global Software Development Projects: Does "Getting to Know You" Really Matter?abstractIn Spring 2008, five student teams were put into competition to develop software for a Cambodian client. Each extended team comprised students distributed across a minimum of three locations, drawn from the US, India, Thailand and Cambodia. This paper describes a couple of exercises conducted with students to examine their basic awareness of the countries of their collaborators and competitors, and to assess their knowledge of their own extended team members during the course of the project. The results from these exercises are examined in conjunction with the high-level communication patterns exhibited by the participating teams and provisional findings are drawn with respect to quality, as measured through a final product selection process. Initial implications for practice are discussed. Olly Gotel, Vidya Kulkarni, Moniphal Say, Christelle Scharff, Thanwadee Sunetnanta |
ICGSE | 5 |
| 2008 | Automated Multiperspective Requirements Traceability Using Ontology Matching Technique
Namfon Assawamekin, Thanwadee Sunetnanta, Charnyote Pluempitiwiriyawej |
SEKE | 2 |