EDBT 2026 Demo / reviewers in the wild / expert
Morakot Choetkiertikul
dblp:20/9870
· DBLP profile ↗
36ranked-venue papers
11as first author
25since 2021 · last 2026
0000-0001-8188-4749ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 35 · 11 first-author · 24 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | When is Generated Code Difficult to Comprehend? Assessing AI Agent Python Code Proficiency in the WildabstractThe rapid adoption of AI coding agents is fundamentally shifting software developers’ roles from code authors to code reviewers. While developers spend a significant portion of their time reading and comprehending code, the linguistic proficiency and complexity of the Python code generated by these agents remain largely unexplored. This study investigates the code proficiency of AI agents to determine the skill level required for developers to maintain their code. Leveraging the AIDev dataset, we mined 591 pull requests containing 5,027 Python files generated by three distinct AI agents and employed pycefr, a static analysis tool that maps Python constructs to six proficiency levels, ranging from A1 (Basic) to C2 (Mastery), to analyze the code. Our results reveal that: AI agents predominantly generate Basic-level code, with over 90% of constructs falling into the A1 and A2 categories, and less than 1% classified as Mastery (C2); AI agents’ and humans’ pull requests share a broadly similar proficiency profile; High-proficiency code by AI agents are from feature addition and bug fixing tasks. These findings suggest that while AI-generated code is generally accessible to developers with basic Python skills, specific tasks may require advanced proficiency to review and maintain complex, agent-generated constructs. Nanthit Temkulkiat, Chaiyong Ragkhitwetsagul, Morakot Choetkiertikul, Ruksit Rojpaisarnkit, Raula Gaikovina Kula |
MSR | 3 |
| 2026 | Security by documentation? characterizing GitHub SECURITY.md policy and their adoption in Python librariesabstractWith security in open-source software development increasingly becoming crucial, security policies are one way to manage vulnerabilities and guide users toward safe practices. To support secure development, platforms like GitHub provide a dedicated section for security policies within repositories. Existing studies focus on the adoption of security policies. However, the detailed content of the security policies has not been examined. Our study aims to fill this gap by analyzing the security policies of 679 PyPI Python libraries hosted on GitHub. We examine the characteristics and content of existing policies and investigate the relationship with project characteristics and recommended security practices by comparing security practice assessments between projects with and without established security policies. The result indicates that projects with security.md shows stronger recommended security practices. This study highlights the importance of adopting a clear and comprehensive security policy to enhance the overall security practices of open-source projects. Morakot Choetkiertikul, Sushawapak Kancharoendee, Chanikarn Jongyingyos, Thanat Phichitphanphong, Chaiyong Ragkhitwetsagul, Brittany Reid, Raula Gaikovina Kula, Thanwadee Sunetnanta |
Empir. Softw. Eng. | 1 |
| 2026 | Automated software engineering knowledge transfer: A case study on small and medium-sized software enterprises in Thailandabstract• ASE knowledge transfer activities were somewhat successful in increasing the awareness and the adoption of ASE tools and techniques in four Thai SSMEs. • Knowledge transfer activities should be tailored to the needs of the SSMEs. • The support from researchers is crucial for the successful adoption of ASE tools and techniques in SSMEs. • The study involving SSMEs needs to be aware of their rapid changes of teams and projects. Knowledge transfer of ASE tools and techniques to Small and Medium-sized Software Enterprises (SSMEs) is a challenging task due to their limited resources. The presented case study performed knowledge transfer interventions within four SSMEs in Thailand, using multiple activities including training, online questionnaires, ASE tool adoption, retrospective meetings, and an overall project evaluation. We found that while the knowledge transfer activities were successful in increasing awareness, the degree of adoption success varied significantly. The companies successfully adopted SonarQube, a tool with a low adoption cost, but struggled to implement unit testing, which demands a high, distributed effort from the entire team. The key lessons learned from this project are that (1) knowledge transfer activities with SSMEs should begin with foundational practices over advanced ASE techniques, (2) ASE tools with low adoption cost and wide benefits (SonarQube) lead to more successful adoption than tools with high adoption cost (unit testing), (3) the researchers must overcome the knowing-doing gap by providing embedded support to the SSMEs, and (4) future knowledge transfer projects must include SSMEs as one of the main target groups. Chaiyong Ragkhitwetsagul, Jens Krinke, Morakot Choetkiertikul, Thanwadee Sunetnanta, Federica Sarro |
J. Syst. Softw. | 3 |
| 2025 | AILinkPreviewer: Enhancing Code Reviews with LLM-Powered Link PreviewsabstractCode review is a key practice in software engineering, where developers evaluate code changes to ensure quality and maintainability. Links to issues and external resources are often included in Pull Requests (PRs) to provide additional context, yet they are typically discarded in automated tasks such as PR summarization and code review comment generation. This limits the richness of information available to reviewers and increases cognitive load by forcing context-switching. To address this gap, we present AILinkPreviewer, a tool that leverages Large Language Models (LLMs) to generate previews of links in PRs using PR metadata, including titles, descriptions, comments, and link body content. We analyzed 50 engineered GitHub repositories and compared three approaches: Contextual LLM summaries, Non-Contextual LLM summaries, and Metadata-based previews. The results in metrics such as BLEU, BERTScore, and compression ratio show that contextual summaries consistently outperform other methods. However, in a user study with seven participants, most preferred non-contextual summaries, suggesting a trade-off between metric performance and perceived usability. These findings demonstrate the potential of LLM-powered link previews to enhance code review efficiency and to provide richer context for developers and automation in software engineering. The video demo is available at https://www.youtube.com/ watch?v $=h 2 q \mathrm{H} 4 \mathrm{R} t r B 3 \mathrm{E}$, and the tool and its source code can be found at https://github.com/c4rtune/AILinkPreviewer. Panya Trakoolgerntong, Tao Xiao 0001, Masanari Kondo, Chaiyong Ragkhitwetsagul, Morakot Choetkiertikul, Pattaraporn Sangaroonsilp, Yasutaka Kamei |
APSEC | 5 |
| 2025 | Social Media Reactions to Open Source Promotions: AI-Powered GitHub Projects on Hacker NewsabstractSocial media platforms have become more influential than traditional news sources, shaping public discourse and accelerating the spread of information. With the rapid advancement of artificial intelligence (AI), open-source software (OSS) projects can leverage these platforms to gain visibility and attract contributors. In this study, we investigate the relationship between Hacker News, a social news site focused on computer science and entrepreneurship, and the extent to which it influences developer activity on the promoted GitHub AI projects. We analyzed 2,195 Hacker News (HN) stories and their corresponding comments over a two-year period. Our findings reveal that at least 19 % of AI developers promoted their GitHub projects on Hacker News, often receiving positive engagement from the community. By tracking activity on the associated 1,814 GitHub repositories after they were shared on Hacker News, we observed a significant increase in forks, stars, and contributors. These results suggest that Hacker News serves as a viable platform for AI-powered OSS projects, with the potential to gain attention, foster community engagement, and accelerate software development. Prachnachai Meakpaiboonwattana, Warittha Tarntong, Thai Mekratanavorakul, Chaiyong Ragkhitwetsagul, Pattaraporn Sangaroonsilp, Raula Gaikovina Kula, Morakot Choetkiertikul, Ken-ichi Matsumoto, Thanwadee Sunetnanta |
ICSME | 7 |
| 2025 | PyGress: Tool for Analyzing the Progression of Code Proficiency in Python OSS ProjectsabstractAssessing developer proficiency in open-source software (OSS) projects is essential for understanding project dynamics, especially for expertise. This paper presents "PyGress", a web-based tool designed to automatically evaluate and visualize Python code proficiency using pycefr, a Python code proficiency analyzer. By submitting a GitHub repository link, the system extracts commit histories, analyzes source code proficiency across CEFR-aligned levels (A1-C2), and generates visual summaries of individual and project-wide proficiency. The PyGress tool visualizes per-contributor proficiency distribution and tracks project code proficiency progression over time. PyGress offers an interactive way to explore contributor coding levels in Python OSS repositories. The video demonstration of the PyGress tool can be found at https://youtu.be/hxoeK-ggcWk, and the source code of the tool is publicly available at https://github.com/MUICT-SERU/PyGress. Rujiphart Charatvaraphan, Bunradar Chatchaiyadech, Thitirat Sukijprasert, Chaiyong Ragkhitwetsagul, Morakot Choetkiertikul, Raula Gaikovina Kula, Thanwadee Sunetnanta, Ken-ichi Matsumoto |
ASE | 5 |
| 2025 | On Categorizing Open Source Software Security Vulnerability Reporting Mechanisms on GitHubabstractOpen-source projects are essential to software de-velopment, but publicly disclosing vulnerabilities without fixes increases the risk of exploitation. The Open Source Security Foundation (OpenS SF) addresses this issue by promoting robust security policies to enhance project security. Current research reveals that many projects perform poorly on OpenS SF criteria, indicating a need for stronger security practices and underscoring the value of SECURITY.md files for structured vulnerability re-porting. This study aims to provide recommendations for improving security policies. By examining 679 open-source projects, we find that email is still the main source of reporting. Furthermore, we find that projects without SECURITY.md files tend to be less secure (lower OpenSSF scores). Our analysis also indicates that, although many maintainers encourage private reporting methods, some contributors continue to disclose vulnerabilities publicly, bypassing established protocols. The results from this preliminary study pave the way for understanding how developers react and communicate a potential security threat. Future challenges include understanding the impact and effectiveness of these mechanisms and what factors may influence how the security threat is addressed. Sushawapak Kancharoendee, Thanat Phichitphanphong, Chanikarn Jongyingyos, Brittany Reid, Raula Gaikovina Kula, Morakot Choetkiertikul, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta |
SANER | 6 |
| 2025 | Sprint2Vec: A Deep Characterization of Sprints in Iterative Software DevelopmentabstractIterative approaches like Agile Scrum are commonly adopted to enhance the software development process. However, challenges such as schedule and budget overruns still persist in many software projects. Several approaches employ machine learning techniques, particularly classification, to facilitate decision-making in iterative software development. Existing approaches often concentrate on characterizing a sprint to predict solely productivity. We introduce Sprint2Vec, which leverages three aspects of sprint information – sprint attributes, issue attributes, and the developers involved in a sprint, to comprehensively characterize it for predicting both productivity and quality outcomes of the sprints. Our approach combines traditional feature extraction techniques with automated deep learning-based unsupervised feature learning techniques. We utilize methods like Long Short-Term Memory (LSTM) to enhance our feature learning process. This enables us to learn features from unstructured data, such as textual descriptions of issues and sequences of developer activities. We conducted an evaluation of our approach on two regression tasks: predicting the deliverability (i.e., the amount of work delivered from a sprint) and quality of a sprint (i.e., the amount of delivered work that requires rework). The evaluation results on five well-known open-source projects (Apache, Atlassian, Jenkins, Spring, and Talendforge) demonstrate our approach's superior performance compared to baseline and alternative approaches. Morakot Choetkiertikul, Peerachai Banyongrakkul, Chaiyong Ragkhitwetsagul, Suppawong Tuarob, Khanh Hoa Dam, Thanwadee Sunetnanta |
IEEE Trans. Software Eng. | 1 |
| 2024 | DEV-EYE: A Tool for Monitoring Bus Factor Using Commit HistoryabstractHigh turnover rates in software development present significant challenges, impacting project continuity, reliability, and quality. The bus factor metric helps quantify and indicate risks associated with key personnel dependencies. Existing tools are designed to calculate the bus factor using information from software project repositories and to determine code ownership. However, given that the bus factor should be monitored over time and the nature of projects varies, a bus factor tool must offer the capability to adjust timelines and customize analysis parameters to accommodate different project constraints. To address these gaps, we introduce DEV-EYE, a tool designed to compute and visualize the bus factor using git commit history. DEV-EYE identifies potential bus factors and offers flexible configuration options, allowing users to adjust parameters such as ownership thresholds and analysis timeframes. Additionally, DEV-EYE enables the comparison of current bus factors with historical data, providing a comprehensive view of project dy-namics. Preliminary evaluations indicate that DEV-EYE is highly promising for real-world applications, emphasizing its role in proactive risk management by identifying critical dependencies and promoting knowledge sharing within teams. Dan Muhindo Kazimoto, Morakot Choetkiertikul, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta |
APSEC | 2 |
| 2024 | Autorepairability of ChatGPT and Gemini: A Comparative StudyabstractIn recent years, Automated Program Repair (APR), which focuses on automatically fixing source code without human intervention, has become a hot topic in the field of software engineering, leading to the proposal of various automatic repair techniques. Additionally, Lapvikai et al. introduced a new software quality metric called “Autorepairability.” Autorepairability is a metric that indicates how easily bugs in the target source code can be fixed using APR techniques. By utilizing Autorepairability, it becomes possible to pre-check whether the program repair techniques will work effectively on the target software and to perform refactoring to improve Autorepairability. However, in the past two to three years, program repair using large language models (LLMs) has become more prevalent, and several studies have revealed that these models exhibit superior repair capabilities compared to traditional APR techniques. In this study, we applied Autorepairability to compare the performance of multiple APR techniques. Specifically, we measured and compared Autorepairability using ChatGPT and Gemini, which are representative large language models, as well as kGenProg, a traditional APR technique. The results demonstrated that Gemini exhibited higher repair capabilities compared to both ChatGPT and the traditional APR technique kGenProg. The five code functionalities that Gemini offers higher Autorepairability scores than ChatGPT include (1) geographic and mathematic operations, (2) validation, comparison, and searching operations, (3) data conversion operations, (4) data extraction and comparison operations, and (5) encoding operations. Chutweeraya Sriwilailak, Yoshiki Higo, Pongpop Lapvikai, Chaiyong Ragkhitwetsagul, Morakot Choetkiertikul |
APSEC | 5 |
| 2024 | jscefr: A Framework to Evaluate the Code Proficiency for JavaScriptabstractIn this paper, we present jscefr (pronounced jes-cee-fer), a tool that detects the use of different elements of the JavaScript (JS) language, effectively measuring the level of proficiency required to comprehend and deal with a fragment of JavaScript code in software maintenance tasks. Based on the pycefr tool, the tool incorporates JavaScript elements and the well-known Common European Framework of Reference for Languages (CEFR) and utilizes the official ECMAScript JavaScript documentation from the Mozilla Developer Network. jscefr categorizes JS code into six levels based on proficiency. jscefr can detect and classify 138 different JavaScript code constructs. To evaluate, we apply our tool to three JavaScript projects of the NPM ecosystem, with interesting results. A video demonstrating the tool's availability and usage is available at https://youtu.be/Ehh-Prq59Pc. Chaiyong Ragkhitwetsagul, Komsan Kongwongsupak, Thanakrit Maneesawas, Natpichsinee Puttiwarodom, Ruksit Rojpaisarnkit, Morakot Choetkiertikul, Raula Gaikovina Kula, Thanwadee Sunetnanta |
ICSME | 6 |
| 2024 | Autorepairability: A New Software Quality CharacteristicabstractCurrently, research on automated program repair (in short, APR) is actively being conducted. APR techniques have been applied to many bugs in open-source software, but the probability of a successful fix is not very high. The authors consider that not only should APR techniques be developed, but software systems should be developed so that bugs can be easily fixed with APR techniques. In this paper, we propose autorepairability, a new characteristic of software quality, that shows how effective automated program repair techniques are for a specific code fragment, file, or project. We also show an approach to automatically measure autorepairability from the source code of a target project, and present experimental results on 1,282 Java method pairs. The use of autorepairability allows many studies to be conducted. For example, research on the development process for developing software systems with high autorepairability and research on refactoring, which transforms software with low autorepairability into software systems with high autorepairability, will be possible. Pongpop Lapvikai, Chaiyong Ragkhitwetsagul, Morakot Choetkiertikul, Yoshiki Higo |
SANER | 3 |
| 2024 | Adoption of automated software engineering tools and techniques in ThailandabstractAbstract Readiness for the adoption of Automated Software Engineering (ASE) tools and techniques can vary according to the size and maturity of software companies. ASE tools and techniques have been adopted by large or ultra-large software companies. However, little is known about the adoption of ASE tools and techniques in small and medium-sized software enterprises (SSMEs) in emerging countries, and the challenges faced by such companies. We study the adoption of ASE tools and techniques for software measurement, static code analysis, continuous integration, and software testing, and the respective challenges faced by software developers in Thailand, a developing country with a growing software economy which mainly consists of SSMEs (similar to other developing countries). Based on the answers from 103 Thai participants in an online survey, we found that Thai software developers are somewhat familiar with ASE tools and agree that adopting such tools would be beneficial. Most of the developers do not use software measurement or static code analysis tools due to a lack of knowledge or experience but agree that their use would be useful. Continuous integration tools have been used with some difficulties. Lastly, although automated testing tools are adopted despite several serious challenges, many developers are still testing the software manually. We call for improvements in ASE tools to be easier to use in order to lower the barrier to adoption in small and medium-sized software enterprises (SSMEs) in developing countries. Chaiyong Ragkhitwetsagul, Jens Krinke, Morakot Choetkiertikul, Thanwadee Sunetnanta, Federica Sarro |
Empir. Softw. Eng. | 3 |
| 2024 | TeReKG: A temporal collaborative knowledge graph framework for software team recommendationabstractSuccessful software development requires a cohesive team with the right mix of technical skills and the ability to collaborate effectively. However, forming a software team that can execute tasks with precision and efficiency requires a deep understanding of each member’s competence, experience, and cooperation history. Previously, automated software team selection has evaluated technical skills, cohesion, and cooperation history. However, the previous method had some limitations. Particularly, local features directly calculated from team members were subjective to the researchers’ views, and the method ignored the temporal aspect of open-source software development. To overcome these limitations, this paper proposes a knowledge-graph software team recommendation framework called TeReKG. This framework encapsulates temporal collaboration patterns and uses a temporal knowledge graph to encode software collaboration history, technical abilities, task dependencies, and project structure. TeReKG was against state-of-the-art team recommendation algorithms using three popular open-source software projects: Moodle, Apache, and Atlassian. The evaluation results show that TeReKG outperforms the state-of-the-art baselines in both single-role and team recommendation tasks. These findings demonstrate that knowledge graph embedding can be effectively utilized in automated recommendation tasks in software engineering. Additionally, this highlights the potential for knowledge graphs to capture global information that can benefit various software development applications, including impact prediction of software repositories, code clone detection, and source code retrieval. Pisol Ruenin, Morakot Choetkiertikul, Akara Supratak, Suppawong Tuarob |
Knowl. Based Syst. | 2 |
| 2023 | Microusity: A testing tool for Backends for Frontends (BFF) Microservice SystemsabstractMicroservice software architecture is more scalable and efficient than its monolithic predecessor. Despite its increasing adoption, microservices might expose security concerns and issues that are distinct from those associated with monolithic designs. We propose Microusity, a tool that performs RESTful API testing on a specific type of microservice pattern called backends for frontends (BFF). We design a novel approach to trace BFF requests using the port mapping between requests to BFF and the sub-requests sent to backend microservices. Furthermore, our tool can pinpoint which of the backend service causing the internal server error, which may lead to unhandled errors or vulnerabilities. Microusity provides an error report and a graph visualization that reveal the source of the error and supports developers in comprehension and debugging of the errors. The evaluation of eight software practitioners shows that Microusity and its test reports are useful for investigating and understanding problems in BFF systems. The prototype tool and the video demo of the tool can be found at https://github.com/MUICT-SERU/MICROUSITY. Pattarakrit Rattanukul, Chansida Makaranond, Pumipat Watanakulcharus, Chaiyong Ragkhitwetsagul, Tanapol Nearunchorn, Vasaka Visoottiviseth, Morakot Choetkiertikul, Thanwadee Sunetnanta |
ICPC | 7 |
| 2023 | An empirical study of automated privacy requirements classification in issue reportsabstractAbstract The recent advent of data protection laws and regulations has emerged to protect privacy and personal information of individuals. As the cases of privacy breaches and vulnerabilities are rapidly increasing, people are aware and more concerned about their privacy. These bring a significant attention to software development teams to address privacy concerns in developing software applications. As today’s software development adopts an agile, issue-driven approach, issues in an issue tracking system become a centralised pool that gathers new requirements, requests for modification and all the tasks of the software project. Hence, establishing an alignment between those issues and privacy requirements is an important step in developing privacy-aware software systems. This alignment also facilitates privacy compliance checking which may be required as an underlying part of regulations for organisations. However, manually establishing those alignments is labour intensive and time consuming. In this paper, we explore a wide range of machine learning and natural language processing techniques which can automatically classify privacy requirements in issue reports. We employ six popular techniques namely Bag-of-Words (BoW), N-gram Inverse Document Frequency (N-gram IDF), Term Frequency-Inverse Document Frequency (TF-IDF), Word2Vec, Convolutional Neural Network (CNN) and Bidirectional Encoder Representations from Transformers (BERT) to perform the classification on privacy-related issue reports in Google Chrome and Moodle projects. The evaluation showed that BoW, N-gram IDF, TF-IDF and Word2Vec techniques are suitable for classifying privacy requirements in those issue reports. In addition, N-gram IDF is the best performer in both projects. Pattaraporn Sangaroonsilp, Morakot Choetkiertikul, Khanh Hoa Dam, Aditya Ghose |
Autom. Softw. Eng. | 2 |
| 2023 | A taxonomy for mining and classifying privacy requirements in issue reports
Pattaraporn Sangaroonsilp, Khanh Hoa Dam, Morakot Choetkiertikul, Chaiyong Ragkhitwetsagul, Aditya Ghose |
Inf. Softw. Technol. | 3 |
| 2023 | Studying the association between Gitcoin's issues and resolving outcomes
Morakot Choetkiertikul, Arada Puengmongkolchaikit, Pandaree Chandra, Chaiyong Ragkhitwetsagul, Rungroj Maipradit, Hideaki Hata, Thanwadee Sunetnanta, Ken-ichi Matsumoto |
J. Syst. Softw. | 1 |
| 2022 | Virtual Reality for Software Engineering PresentationsabstractDue to the impact of the pandemic situation, applying online learning methods become an immediate response to tackle the difficulties in teaching and learning, including software engineering courses. Online video meeting platforms (e.g., MS Teams, Webex) are popularly adopted as a medium between instructors and students to conduct online learning classes and they have been modified to provide functions supporting remote teaching and learning activities such as the breakout rooms for conducting group activities. However, maintaining student engagement is still a challenging problem in online learning. Especially, drawing students’ attention and enhancing their experience during in-class activities (e.g., project presentations, group discussions) is critical to achieving of activities’ objective. Virtual Reality (VR) has been considered to be a potential answer to this online teaching and learning enhancement. This study evaluates the benefit of adopting VR in software engineering class presentation activities. The evaluation result from 3 courses shows that VR improves the online learning and presentation experience by offering visual attractions and presence to students. Chaiyong Ragkhitwetsagul, Morakot Choetkiertikul, Apirak Hoonlor, Mores Prachyabrued |
APSEC | 2 |
| 2022 | V-Achilles: An Interactive Visualization of Transitive Security VulnerabilitiesabstractA key threat to the usage of third-party dependencies has been the threat of security vulnerabilities, which risks unwanted access to a user application. As part of an ecosystem of dependencies, users of a library are prone to both the direct and transitive dependencies adopted into their applications. Recent work involves tool supports for vulnerable dependency updates, rarely showing the complexity of the transitive updates. In this paper, we introduce our solution to support vulnerability updating in npm. V-Achilles is a prototype that shows a visualization (i.e., using dependency graphs) affected by vulnerability attacks. In addition to the tool overview, we highlight three use cases to demonstrate the usefulness and application of our prototype with real-world npm packages. The prototype is available at https://github.com/MUICT-SERU/V-Achilles, with an accompanying video demonstration at https://www.youtube.com/watch?v=tspiZfhMNcs. Vipawan Jarukitpipat, Klinton Chhun, Wachirayana Wanprasert, Chaiyong Ragkhitwetsagul, Morakot Choetkiertikul, Thanwadee Sunetnanta, Raula Gaikovina Kula, Bodin Chinthanet, Takashi Ishio, Ken-ichi Matsumoto |
ASE | 5 |
| 2022 | Identifying Software Engineering Challenges in Software SMEs: A Case Study in ThailandabstractSmall and medium-sized software enterprises (SSMEs) are a vital part of emerging markets. Due to their size, they are not capable of adopting advanced software engineering techniques or automated software engineering tools in the same way large and ultra-large companies are. We study the software engineering challenges in SSMEs in Thailand, an emerging market in software development, using semi-structured interviews with four SSMEs. After performing a thematic analysis of the interview transcripts, we found a number of common challenges such as lack of testing, code-related issues, and inaccurate effort estimation. We observed that in order to introduce advanced automated software engineering tools and techniques, SSMEs need to adopt contemporary best practices in software engineering like automated testing, continuous integration and automated code review. Moreover, we suggest that software engineering research engage with SSMEs to enable them to improve their knowledge and adopt more advanced software engineering practices. Chaiyong Ragkhitwetsagul, Jens Krinke, Morakot Choetkiertikul, Thanwadee Sunetnanta, Federica Sarro |
SANER | 3 |
| 2022 | Quantifying effectiveness of team recommendation for collaborative software development
Noppadol Assavakamhaenghan, Waralee Tanaphantaruk, Ponlakit Suwanworaboon, Morakot Choetkiertikul, Suppawong Tuarob |
Autom. Softw. Eng. | 4 |
| 2021 | FixMe: A GitHub Bot for Detecting and Monitoring On-Hold Self-Admitted Technical DebtabstractSelf-Admitted Technical Debt (SATD) is a special form of technical debt in which developers intentionally record their hacks in the code by adding comments for attention. Here, we focus on issue-related "On-hold SATD", where developers suspend proper implementation due to issues reported inside or outside the project. When the referenced issues are resolved, the On-hold SATD also need to be addressed, but since monitoring these issue reports takes a lot of time and effort, developers may not be aware of the resolved issues and leave the On-hold SATD in the code. In this paper, we propose FixMe, a GitHub bot that helps developers detecting and monitoring On-hold SATD in their repositories and notify them whenever the On-hold SATDs are ready to be fixed (i.e. the referenced issues are resolved). The bot can automatically detect On-hold SATD comments from source code using machine learning techniques and discover referenced issues. When the referenced issues are resolved, developers will be notified by FixMe bot. The evaluation conducted with 11 participants shows that our FixMe bot can support them in dealing with On-hold SATD. FixMe is available at https://www.fixmebot.app/ and FixMe's VDO is at https://youtu.be/YSz9kFxN_YQ. Saranphon Phaithoon, Supakarn Wongnil, Patiphol Pussawong, Morakot Choetkiertikul, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta, Rungroj Maipradit, Hideaki Hata, Ken-ichi Matsumoto |
ASE | 4 |
| 2021 | Automatically recommending components for issue reports using deep learning
Morakot Choetkiertikul, Khanh Hoa Dam, Truyen Tran 0001, Trang Pham, Chaiyong Ragkhitwetsagul, Aditya Ghose |
Empir. Softw. Eng. | 1 |
| 2021 | Automatic team recommendation for collaborative software development
Suppawong Tuarob, Noppadol Assavakamhaenghan, Waralee Tanaphantaruk, Ponlakit Suwanworaboon, Saeed-Ul Hassan, Morakot Choetkiertikul |
Empir. Softw. Eng. | 6 |
| 2020 | Teddy: Automatic Recommendation of Pythonic Idiom Usage For Pull-Based Software ProjectsabstractPythonic code is idiomatic code that follows guiding principles and practices within the Python community. Offering performance and readability benefits, Pythonic code is claimed to be widely adopted by experienced Python developers, but can be a learning curve to novice programmers. To aid with Pythonic learning, we create an automated tool, called Teddy, that can help checking the Pythonic idiom usage. The tool offers a prevention mode with Just-In-Time analysis to recommend the use of Pythonic idiom during code review and a detection mode with historical analysis to run a thorough scan of idiomatic and non-idiomatic code. In this paper, we first describe our tool and an evaluation of its performance. Furthermore, we present a case study that demonstrates how to use Teddy in a real-life scenario on an Open Source project. An evaluation shows that Teddy has high precision for detecting Pythonic idiom and non-Pythonic code. Using interactive visualizations, we demonstrate how novice programmers can navigate and identify Pythonic idiom and non-Pythonic code in their projects. Our video demo with the full interactive visualizations is available at https://youtu.be/vOCQReSvBxA. Purit Phan-Udom, Naruedon Wattanakul, Tattiya Sakulniwat, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta, Morakot Choetkiertikul, Raula Gaikovina Kula |
ICSME | 6 |
| 2020 | JITBot: An Explainable Just-In-Time Defect Prediction BotabstractJust-In-Time (JIT) defect prediction is a classification model that is trained using historical data to predict bug-introducing changes. However, recent studies raised concerns related to the explainability of the predictions of many software analytics applications (i.e., practitioners do not understand why commits are risky and how to improve them). In addition, the adoption of Just-In-Time defect prediction is still limited due to a lack of integration into CI/CD pipelines and modern software development platforms (e.g., GitHub). In this paper, we present an explainable Just-In-Time defect prediction framework to automatically generate feedback to developers by providing the riskiness of each commit, explaining why such commit is risky, and suggesting risk mitigation plans. The proposed framework is integrated into the GitHub CI/CD pipeline as a GitHub application to continuously monitor and analyse a stream of commits in many GitHub repositories. Finally, we discuss the usage scenarios and their implications to practitioners. The VDO demonstration is available at https://jitbot-tool.github.io/ Chaiyakarn Khanan, Worawit Luewichana, Krissakorn Pruktharathikoon, Jirayus Jiarpakdee, Chakkrit Tantithamthavorn, Morakot Choetkiertikul, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta |
ASE | 6 |
| 2019 | Automatic Classifying Self-Admitted Technical Debt Using N-Gram IDFabstractTechnical Debt (TD) introduces a quality problem and increases maintenance cost since it may require improvements in the future. Several studies show that it is possible to automatically detect TD from source code comments that developers intentionally created, so-called self-admitted technical debt (SATD). Those studies proposed to use binary classification technique to predict whether a comment shows SATD. However, SATD has different types (e.g. design SATD and requirement SATD). In this paper, we therefore propose an approach using N-gram Inverse Document Frequency (IDF) and employ a multi-class classification technique to build a model that can identify different types of SATD. From the empirical evaluation on 10 open-source projects, our approach outperforms alternative methods (e.g. using BOW and TF-IDF). Our approach also improves the prediction performance over the baseline benchmark by 33%. Supatsara Wattanakriengkrai, Napat Srisermphoak, Sahawat Sintoplertchaikul, Morakot Choetkiertikul, Chaiyong Ragkhitwetsagul, Thanwadee Sunetnanta, Hideaki Hata, Ken-ichi Matsumoto |
APSEC | 4 |
| 2019 | A Deep Learning Model for Estimating Story PointsabstractAlthough there has been substantial research in software analytics for effort estimation in traditional software projects, little work has been done for estimation in agile projects, especially estimating the effort required for completing user stories or issues. Story points are the most common unit of measure used for estimating the effort involved in completing a user story or resolving an issue. In this paper, we propose a prediction model for estimating story points based on a novel combination of two powerful deep learning architectures: long short-term memory and recurrent highway network. Our prediction system is end-to-end trainable from raw input data to prediction outcomes without any manual feature engineering. We offer a comprehensive dataset for story points-based estimation that contains 23,313 issues from 16 open source projects. An empirical evaluation demonstrates that our approach consistently outperforms three common baselines (Random Guessing, Mean, and Median methods) and six alternatives (e.g., using Doc2Vec and Random Forests) in Mean Absolute Error, Median Absolute Error, and the Standardized Accuracy. Morakot Choetkiertikul, Khanh Hoa Dam, Truyen Tran 0001, Trang Pham, Aditya Ghose, Tim Menzies |
IEEE Trans. Software Eng. | 1 |
| 2018 | Multi-Objective Iteration Planning in Agile DevelopmentabstractAn agile software project typically has a number of iterations (e.g. sprints in Scrum), in each of which the development team designs, implements, tests and delivers a distinct product increment. An important activity in agile development is iteration planning where the team needs to decide what should be done (in terms of issues or user stories) for the upcoming iteration. In this paper, we propose a multi-objective search-based approach to support the team in making such a decision. Our approach employs evolutionary techniques to iteratively generate candidate selections of issues for a given iteration, and search for the optimal selection(s). The search is guided simultaneously by two objectives: maximizing the business value which the team delivers in the iteration while maximizing the alignment with regard to the iteration's original goal. Our evaluation of 233 iterations from six large open source projects demonstrates the effectiveness of our approach. Wisam Haitham Abbood Al-Zubaidi, Khanh Hoa Dam, Morakot Choetkiertikul, Aditya Ghose |
APSEC | 3 |
| 2018 | Predicting Delivery Capability in Iterative Software DevelopmentabstractIterative software development has become widely practiced in industry. Since modern software projects require fast, incremental delivery for every iteration of software development, it is essential to monitor the execution of an iteration, and foresee a capability to deliver quality products as the iteration progresses. This paper presents a novel, data-driven approach to providing automated support for project managers and other decision makers in predicting delivery capability for an ongoing iteration. Our approach leverages a history of project iterations and associated issues, and in particular, we extract characteristics of previous iterations and their issues in the form of features. In addition, our approach characterizes an iteration using a novel combination of techniques including feature aggregation statistics, automatic feature learning using the Bag-of-Words approach, and graph-based complexity measures. An extensive evaluation of the technique on five large open source projects demonstrates that our predictive models outperform three common baseline methods in Normalized Mean Absolute Error and are highly accurate in predicting the outcome of an ongoing iteration. Morakot Choetkiertikul, Khanh Hoa Dam, Truyen Tran 0001, Aditya Ghose, John C. Grundy |
IEEE Trans. Software Eng. | 1 |
| 2017 | Predicting the delay of issues with due dates in software projects
Morakot Choetkiertikul, Khanh Hoa Dam, Truyen Tran 0001, Aditya Ghose |
Empir. Softw. Eng. | 1 |
| 2015 | Predicting Delays in Software Projects Using Networked Classification (T)abstractSoftware projects have a high risk of cost and schedule overruns, which has been a source of concern for the software engineering community for a long time. One of the challenges in software project management is to make reliable prediction of delays in the context of constant and rapid changes inherent in software projects. This paper presents a novel approach to providing automated support for project managers and other decision makers in predicting whether a subset of software tasks (among the hundreds to thousands of ongoing tasks) in a software project have a risk of being delayed. Our approach makes use of not only features specific to individual software tasks (i.e. local data) -- as done in previous work -- but also their relationships (i.e. networked data). In addition, using collective classification, our approach can simultaneously predict the degree of delay for a group of related tasks. Our evaluation results show a significant improvement over traditional approaches which perform classification on each task independently: achieving 46% -- 97% precision (49% improved), 46% -- 97% recall (28% improved), 56% -- 75% F-measure (39% improved), and 78% -- 95% Area Under the ROC Curve (16% improved). Morakot Choetkiertikul, Khanh Hoa Dam, Truyen Tran 0001, Aditya Ghose |
ASE | 1 |
| 2015 | Characterization and Prediction of Issue-Related Risks in Software ProjectsabstractIdentifying risks relevant to a software project and planning measures to deal with them are critical to the success of the project. Current practices in risk assessment mostly rely on high-level, generic guidance or the subjective judgements of experts. In this paper, we propose a novel approach to risk assessment using historical data associated with a software project. Specifically, our approach identifies patterns of past events that caused project delays, and uses this knowledge to identify risks in the current state of the project. A set of risk factors characterizing “risky” software tasks (in the form of issues) were extracted from five open source projects: Apache, Duraspace, JBoss, Moodle, and Spring. In addition, we performed feature selection using a sparse logistic regression model to select risk factors with good discriminative power. Based on these risk factors, we built predictive models to predict if an issue will cause a project delay. Our predictive models are able to predict both the risk impact (i.e. the extend of the delay) and the likelihood of a risk occurring. The evaluation results demonstrate the effectiveness of our predictive models, achieving on average 48%-81% precision, 23%-90% recall, 29%-71% F-measure, and 70%-92% Area Under the ROC Curve. Our predictive models also have low error rates: 0.39-0.75 for Macro-averaged Mean Cost-Error and 0.7-1.2 for Macro-averaged Mean Absolute Error. Morakot Choetkiertikul, Khanh Hoa Dam, Truyen Tran 0001, Aditya Ghose |
MSR | 1 |
| 2014 | A CMMI-Based Automated Risk Assessment FrameworkabstractRisk assessment is crucial to the increase of software development project success. Current risk assessment approaches provide only a rough guide. Risk assessment experts and domain experts are required in conducting risk assessments in software projects. Therefore, traditional risk assessment approaches require extra activities besides development tasks, and possibly leading to extra costs. We believe that an effective risk assessment approach should be transparently embedded in software development process. This paper aims to present an automated risk assessment framework using CMMI and risk taxnomy as a guidance to develop a risk assessment model. A pragmatic approach will be applied as a basis in building this suggested risk prediction model and the case studies of our practice. These studies are considered as our proof of concept. Morakot Choetkiertikul, Khanh Hoa Dam, Aditya Ghose, Thanwadee Sunetnanta |
APSEC (2) | 1 |
| 2010 | A Risk Assessment Model for Offshoring Using CMMI Quantitative ApproachabstractRisk analysis and assessment obviously provides valuable insights to offshoring projects to identify and evaluate the magnitude of risks associated with the activities and the work products being considered. In offshoring software industry, successful execution of risk analysis drastically relies on strong software process skills and management skills to resolve the differences in cultures, languages, time zones, and development which are used across distributed project teams. One way to ease such differences is to provide a model which offers a rational and automated basis for quantifying and monitoring risks and providing specific decision-making guidance while maintaining the nature of offshoring in a distributed manner. This paper presents an extension of our previous model of quantitative CMMI assessment. We further apply the best practices from the Capability Maturity Model Integration (CMMI) as a guideline for quantitative risk analysis in offshoring and using risk taxonomy from the Software Engineering Institute (SEI) Taxonomy-Based Risk Identification. This work aims to reduce the process overhead of risk assessment by automatically collecting data from the project management repository to adequately and appropriately determine the approximate level of risk in offshoring projects. Morakot Choetkiertikul, Thanwadee Sunetnanta |
ICSEA | 1 |