EDBT 2026 Demo / reviewers in the wild / expert
Eleni Constantinou
dblp:73/10358
· DBLP profile ↗
30ranked-venue papers
7as first author
13since 2021 · last 2026
0000-0002-4242-2581ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 27 · 6 first-author · 13 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorSystems, architecture and hardware · 1Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An actionable framework to investigate and foster women inclusion in software development teams in proprietary software ecosystems
Juliana Carvalho Silva do Outão, Luiz Alexandre Martins Costa, Eleni Constantinou, Rodrigo Pereira dos Santos, Alexander Serebrenik |
J. Syst. Softw. | 3 |
| 2025 | Security Vulnerabilities in Docker Images: A Cross-Tag Study of Application DependenciesabstractDocker containers are widely used in modern enterprise applications and cloud environments for their efficiency, portability, and rapid deployment. As a leading containerization technology, Docker enables applications to be stored as images containing all required runtime dependencies. Nonetheless, the growing popularity of containers has also raised security concerns as the libraries and dependencies included in Docker images can contain security vulnerabilities. Previous research has predominantly focused on operating system vulnerabilities, with some investigations into application vulnerabilities originating from vulnerable dependencies. However, these studies have focused solely on the latest tag (version) of each Docker image repository, without offering insights into the prevalence and potential resolution of vulnerabilities across different releases. This limitation restricts our understanding of how effectively they are managed over time. In this study, we investigate the prevalence of vulnerable JavaScript packages within Docker containers across multiple release tags. Our time-based analysis enables us to assess the extent to which maintainers resolve these vulnerabilities in subsequent releases, as well as the time required to address them. We analyzed$\mathbf{6, 2 9 2}$unique images gathered from 1,573 active repositories. Our findings indicate that the majority of Docker images contain multiple vulnerabilities across various tags. Nearly 61 % of repositories have vulnerabilities in every examined tag. While some of these vulnerabilities are resolved by maintainers in subsequent releases, many remain unaddressed within our observation timeframe. Moreover, we found that only 10 % of vulnerabilities are typically addressed within the first 6 months, leaving many unattended for considerably longer durations. We also discovered that common repository attributes, including popularity, contributor count, and automation usage, have no significant effect on the timeliness of vulnerability resolution. Hamid Mohayeji, Eleni Constantinou, Alexander Serebrenik |
ICSME | 2 |
| 2025 | Securing dependencies: A comprehensive study of Dependabot's impact on vulnerability mitigationabstractAbstract The growing use of third-party libraries in software development poses a hidden security risk, as vulnerabilities in these libraries can easily spread to dependent applications. Project maintainers must remain vigilant regarding updates and patches for these external libraries, a responsibility that is facilitated by automated tools, also known as bots . This study centers on Dependabot, a widely adopted bot that offers security and version updates. We aim to scrutinize the impact of Dependabot on mitigating vulnerabilities arising from dependencies, preventing potential prolonged security issues in open-source software. We investigate how developers react to security updates provided by Dependabot within engineered and actively maintained JavaScript projects. We also delve into how project attributes, including the integration of tests and continuous integration (CI) tools, influence the acceptance rate of security updates. Additionally, we perform a detailed analysis of the lifespan of each vulnerability to demonstrate how they are dealt with when Dependabot is in use. Our findings reveal a significant reliance on Dependabot by developers for managing security vulnerabilities in dependencies, with most updates being merged swiftly within days. We find that projects equipped with tests and CI tools are more likely to merge security updates. Conversely, when developers opt not to merge a security update, they often manually address the identified vulnerability. This manual approach, however, could span over several months, potentially exposing projects to security risks. Crucially, in many instances, the manual fixes are potentially inspired by earlier security updates, underscoring Dependabot’s pivotal role in safeguarding dependencies. Hamid Mohayeji, Andrei Agaronian, Eleni Constantinou, Nicola Zannone, Alexander Serebrenik |
Empir. Softw. Eng. | 3 |
| 2024 | Language usage analysis for EMF metamodels on GitHubabstractAbstract Context EMF metamodels lie at the heart of model-based approaches for a variety of tasks, notably for defining the abstract syntax of modeling languages. The language design of EMF metamodels itself is part of a design process, where the needs of its specific range of users should be satisfied. Studying how people actually use the language in the wild would enable empirical feedback for improving the design of the EMF metamodeling language. Objective Our goal is to study the language usage of EMF metamodels in public engineered projects on GitHub. We aim to reveal information about the usage of specific language constructs, whether they match the language design. Based on our findings, we plan to suggest improvements in the EMF metamodelling language. Method We adopt a sample study research strategy and collect data from the EMF metamodels on GitHub. After a series of preprocessing steps including filtering out non-engineered projects and deduplication, we employ an analytics workflow on top of a graph database to formulate generalizing statements about the artifacts under study. Based on the results, we also give actionable suggestions for the EMF metamodeling language design. Results We have conducted various analyses on metaclass, attribute, feature/relationship usage as well as specific parts of the language: annotations and generics. Our findings reveal that the most used metaclasses are not the main building blocks of the language, but rather auxiliary ones. Some of the metaclasses, metaclass features and relations are almost never used. There are a few attributes which are almost exclusively used with a single value or illegal values. Some of the language features such as special forms of generics are very rarely used. Based on our findings, we provide suggestions to improve the EMF language, e.g. removing a language element, restricting its values or refining the metaclass hierarchy. Conclusions In this paper, we present an extensive empirical study into the language usage of EMF metamodels on GitHub. We believe this study fills a gap in the literature of model analytics and will hopefully help future improvement of the EMF metamodeling language. Önder Babur, Eleni Constantinou, Alexander Serebrenik |
Empir. Softw. Eng. | 2 |
| 2024 | Transformers and meta-tokenization in sentiment analysis for software engineeringabstractAbstract Sentiment analysis has been used to study aspects of software engineering, such as issue resolution, toxicity, and self-admitted technical debt. To address the peculiarities of software engineering texts, sentiment analysis tools often consider the specific technical lingo practitioners use. To further improve the application of sentiment analysis, there have been two recommendations: Using pre-trained transformer models to classify sentiment and replacing non-natural language elements with meta-tokens. In this work, we benchmark five different sentiment analysis tools (two pre-trained transformer models and three machine learning tools) on 2 gold-standard sentiment analysis datasets. We find that pre-trained transformers outperform the best machine learning tool on only one of the two datasets, and that even on that dataset the performance difference is a few percentage points. Therefore, we recommend that software engineering researchers should not just consider predictive performance when selecting a sentiment analysis tool because the best-performing sentiment analysis tools perform very similarly to each other (within 4 percentage points). Meanwhile, we find that meta-tokenization does not improve the predictive performance of sentiment analysis tools. Both of our findings can be used by software engineering researchers who seek to apply sentiment analysis tools to software engineering data. Nathan Cassee, Andrei Agaronian, Eleni Constantinou, Nicole Novielli, Alexander Serebrenik |
Empir. Softw. Eng. | 3 |
| 2024 | Software Engineering for Systems-of-Systems and Software Ecosystems
Rodrigo Pereira dos Santos, Eleni Constantinou, Pablo Oliveira Antonino, Jan Bosch |
Inf. Softw. Technol. | 2 |
| 2023 | Investigating the Resolution of Vulnerable Dependencies with Dependabot Security UpdatesabstractModern software development practices increasingly rely on third-party libraries due to the inherent benefits of reuse. However, libraries may contain security vulnerabilities that can propagate to the dependent applications. To counter this, maintainers of dependent projects should monitor their dependencies and security reports to ensure that only patched releases of the upstream applications are in use. As manual maintenance of dependencies has shown to be ineffective, several automated tools (aka bots) have been proposed to assist developers in rapidly identifying and resolving vulnerable dependencies. In this work, we focus on Dependabot, a popular bot providing security and version updates, and study developers’ receptivity to its security updates in engineered and actively maintained JavaScript projects. Moreover, we carry out a fine-grained analysis of the lifecycle of every vulnerability to manifest how they are dealt with in the presence of Dependabot. Our findings show that the task of fixing vulnerable dependencies is, to a large extent, delegated to Dependabot and that developers merge the majority of security updates within several days. On the other hand, when developers do not merge a security update, they usually address the identified vulnerability manually. This approach, however, often takes up to several months which in turn could expose the projects to security issues. Hamid Mohayeji, Andrei Agaronian, Eleni Constantinou, Nicola Zannone, Alexander Serebrenik |
MSR | 3 |
| 2022 | LiFUSO: A Tool for Library Feature Unveiling based on Stack Overflow PostsabstractSelecting a library from a vast ecosystem can be a daunting task. The libraries are not only numerous, but they also lack an enumeration of the features they offer. A feature enumeration for each library in an ecosystem would help developers select the most appropriate library for the task at hand. Within this enumeration, a library feature could take the form of a brief description together with the API references through which the feature can be reused. This paper presents LiFUSO, a tool that leverages Stack Overflow posts to compute a list of such features for a given library. Each feature corresponds to a cluster of related API references based on the similarity of the Stack Overflow posts in which they occur. Once LiFUSO has extracted such a cluster of posts, it applies natural language processing to describe the corresponding feature. We describe the engineering aspects of the tool, and illustrate its usage through a preliminary case study in which we compare the features uncovered for two competing libraries within the same domain. An executable version of the tool is available at https://github.com/softwarelanguageslab/lifuso and its demonstration video is accessible at https://youtu.be/tDE1LWa86cA. Camilo Velázquez-Rodríguez, Eleni Constantinou, Coen De Roover |
ICSME | 2 |
| 2022 | Uncovering Library Features from API Usage on Stack OverflowabstractSelecting an appropriate library for reuse within a vast software ecosystem can be a daunting task. A list of features for each library, i.e., a short description of the functionality that can be reused with code examples that illustrate its usage, may alleviate this problem. In this paper, we propose a data-driven approach that uses both the code snippets and the accompanying natural language descriptions from Stack Overflow posts to produce a list of features of a given library. Each extracted feature corresponds to a cluster of API classes and methods considered related based on attributes of the Stack Overflow posts in which they appear. We evaluated the approach considering seven Maven libraries and compared the resulting features against library descriptions from cookbook-like tutorials. The approach achieves an average accuracy of 67% across the seven libraries for the tutorial-like features. For at least 73% of the features extracted by the approach but missing from the documentation, we found a matching library usage in a corpus of GitHub projects. These results suggest that our clusters represent library features, which paves the way to better tool support for documenting software libraries and for selecting a library in an ecosystem. Camilo Velázquez-Rodríguez, Eleni Constantinou, Coen De Roover |
SANER | 2 |
| 2022 | A mixed-methods analysis of micro-collaborative coding practices in OpenStack
Armstrong Foundjem, Eleni Constantinou, Tom Mens, Bram Adams |
Empir. Softw. Eng. | 2 |
| 2022 | Special Issue on Software Health of Software Ecosystems
Eleni Constantinou, Dario Di Nucci, Raula Gaikovina Kula, Henrique Rocha |
Sci. Comput. Program. | 1 |
| 2021 | Human, bot or both? A study on the capabilities of classification models on mixed accountsabstractSeveral bot detection algorithms have recently been discussed in the literature, as software bots that perform maintenance tasks have become more popular in recent years. State-of-the-art techniques detect bots based on a binary classification, where a GitHub account is either a human or a bot. However, this conceptualisation of bot detection as an account-level binary classification problem fails to account for ‘mixed accounts’, accounts that are shared between a human and a bot, and that therefore exhibit both bot and human activity. By using binary classification models for bot detection, researchers might hence mischaracterize both human and bot behavior in software maintenance. This calls for conceptualisation of bot detection through a comment-level classification. However, the single such approach solely investigates a small number of mixed account comments. The nature of mixed accounts on GitHub is thus yet unknown, and the absence of appropriate datasets make this a difficult problem to study. In this paper, we investigate three comment-level classification models and we evaluate these classifiers on a manually labeled dataset of mixed accounts. We find that the best classifiers based on these classification models achieve a precision and recall between 88% and 96%. However, even the most accurate comment-level classifier cannot accurately detect mixed accounts; rather, we find that textual content alone, or textual content combined with templates used by bots, are very effective features for the detection of both bot and mixed accounts. Our study calls for more accurate bot detection techniques capable of identifying mixed accounts, and as such supporting more refined insights in software maintenance activities performed by humans and bots on social coding sites. Nathan Cassee, Christos Kitsanelis, Eleni Constantinou, Alexander Serebrenik |
ICSME | 3 |
| 2021 | On the impact of release policies on bug handling activity: A case study of Eclipse
Zeinab Abou Khalil, Eleni Constantinou, Tom Mens, Laurence Duchien |
J. Syst. Softw. | 2 |
| 2020 | GAP: Forecasting commit activity in git projects
Alexandre Decan, Eleni Constantinou, Tom Mens, Henrique Rocha |
J. Syst. Softw. | 2 |
| 2019 | On the abandonment and survival of open source projects: An empirical investigationabstractBackground: Evolution of open source projects frequently depends on a small number of core developers. The loss of such core developers might be detrimental for projects and even threaten their entire continuation. However, it is possible that new core developers assume the project maintenance and allow the project to survive. Aims: The objective of this paper is to provide empirical evidence on: 1) the frequency of project abandonment and survival, 2) the differences between abandoned and surviving projects, and 3) the motivation and difficulties faced when assuming an abandoned project. Method: We adopt a mixed-methods approach to investigate project abandonment and survival. We carefully select 1,932 popular GitHub projects and recover the abandoned and surviving projects, and conduct a survey with developers that have been instrumental in the survival of the projects. Results: We found that 315 projects (16%) were abandoned and 128 of these projects (41%) survived because of new core developers who assumed the project development. The survey indicates that (i) in most cases the new maintainers were aware of the project abandonment risks when they started to contribute; (ii) their own usage of the systems is the main motivation to contribute to such projects; (iii) human and social factors played a key role when making these contributions; and (iv) lack of time and the difficulty to obtain push access to the repositories are the main barriers faced by them. Conclusions: Project abandonment is a reality even in large open source projects and our work enables a better understanding of such risks, as well as highlights ways in avoiding them. Guilherme Avelino 0001, Eleni Constantinou, Marco Túlio Valente, Alexander Serebrenik |
ESEM | 2 |
| 2019 | A Longitudinal Analysis of Bug Handling Across Eclipse ReleasesabstractLarge open source software projects, like Eclipse, follow a continuous software development process, with a regular release cycle. During each release, new bugs are reported, triaged and resolved. Previous studies have focused on various aspects of bug fixing, such as bug triaging, bug prediction, and bug process analysis. Most studies, however, do not distinguish between what happens before and after each scheduled release. We are also unaware of studies that compare bug fixing activities across different project releases. This paper presents an empirical analysis of the bug handling process of Eclipse over a 15-year period, considering 138K bug reports from Bugzilla, including 16 annual Eclipse releases and two quarterly releases in 2018. We compare the bug resolution rate, the fixing rate, the bug triaging time and the fixing time before and after each release date, and we study the possible impact of "release pressure". Among others, our results reveal that Eclipse bug handling activity is improving over time, with an important decrease in the number of reported bugs before releases, an increase in the bug fixing rate and an increasingly balanced bug handling workload before and after releases. The recent transition from an annual to a quarterly release cycle continued to improve the bug handling process. Zeinab Abou Khalil, Eleni Constantinou, Tom Mens, Laurence Duchien, Clément Quinton |
ICSME | 2 |
| 2019 | A formal framework for measuring technical lag in component repositories - and its application to npmabstractAbstract Reusable Open Source Software (OSS) components for major programming languages are available in package repositories. Developers rely on package management tools to automate deployments, specifying which package releases satisfy the needs of their applications. However, these specifications may lead to deploying package releases that are outdated, or otherwise undesirable, because they do not include bug fixes, security fixes, or new functionality. In contrast, automatically updating to a more recent release may introduce incompatibility issues. To capture this delicate balance, we formalise a generic model of technical lag, a concept that quantifies to which extent a deployed collection of components is outdated, with respect to the ideal deployment. We operationalise this model for the npm package manager. We empirically analyze the history of package update practices and technical lag for more than 500K packages with about 4M package releases over a seven‐year period. We consider both development and runtime dependencies, and study both direct and transitive dependencies. We also analyze the technical lag of external GitHub applications depending on npm packages. We report our findings, suggesting the need for more awareness of, and integrated tool support for, controlling technical lag in software libraries. Ahmed Zerouali, Tom Mens, Jesús M. González-Barahona, Alexandre Decan, Eleni Constantinou, Gregorio Robles |
J. Softw. Evol. Process. | 5 |
| 2018 | On the Evolution of Technical Lag in the npm Package Dependency NetworkabstractSoftware packages developed and distributed through package managers extensively depend on other packages. These dependencies are regularly updated, for example to add new features, resolve bugs or fix security issues. In order to take full advantage of the benefits of this type of reuse, developers should keep their dependencies up to date by relying on the latest releases. In practice, however, this is not always possible, and packages lag behind with respect to the latest version of their dependencies. This phenomenon is described as technical lag in the literature. In this paper, we perform an empirical study of technical lag in the npm dependency network by investigating its evolution for over 1.4M releases of 120K packages and 8M dependencies between these releases. We explore how technical lag increases over time, taking into account the release type and the use of package dependency constraints. We also discuss how technical lag can be reduced by relying on the semantic versioning policy. Alexandre Decan, Tom Mens, Eleni Constantinou |
ICSME | 3 |
| 2018 | An Empirical Analysis of Technical Lag in npm Package Dependencies
Ahmed Zerouali, Eleni Constantinou, Tom Mens, Gregorio Robles, Jesús M. González-Barahona |
ICSR | 2 |
| 2018 | On the impact of security vulnerabilities in the npm package dependency networkabstractSecurity vulnerabilities are among the most pressing problems in open source software package libraries. It may take a long time to discover and fix vulnerabilities in packages. In addition, vulnerabilities may propagate to dependent packages, making them vulnerable too. This paper presents an empirical study of nearly 400 security reports over a 6-year period in the npm dependency network containing over 610k JavaScript packages. Taking into account the severity of vulnerabilities, we analyse how and when these vulnerabilities are discovered and fixed, and to which extent they affect other packages in the packaging ecosystem in presence of dependency constraints. We report our findings and provide guidelines for package maintainers and tool developers to improve the process of dealing with security issues. Alexandre Decan, Tom Mens, Eleni Constantinou |
MSR | 3 |
| 2017 | Socio-technical evolution of the Ruby ecosystem in GitHubabstractThe evolution dynamics of a software ecosystem depend on the activity of the developer community contributing to projects within it. Both social and technical changes affect an ecosystem's evolution and the research community has been investigating the impact of these modifications over the last few years. Existing studies mainly focus on temporary modifications, often ignoring the effect of permanent changes on the software ecosystem. We present an empirical study of the magnitude and effect of permanent modifications in both the social and technical parts of a software ecosystem. More precisely, we measure permanent changes with regard to the ecosystem's projects, contributors and source code files and present our findings concerning the effect of these modifications. We study the Ruby ecosystem in GitHub over a nine-year period by carrying out a socio-technical analysis of the co-evolution of a large number of base projects and their forks. This analysis involves both the source code developed for these projects as well as the developers having contributed to them. We discuss our findings with respect to the ecosystem evolution according to three different viewpoints: (1) the base projects, (2) the forks and (3) the entire ecosystem containing both the base projects and forks. Our findings show an increased growth in both the technical and social aspects of the Ruby ecosystem until early 2014, followed by an increased contributor and project abandonment rate. We show the effect of permanent modifications in the ecosystem evolution and provide preliminary evidence of contributors migrating to other ecosystems when leaving the Ruby ecosystem. Eleni Constantinou, Tom Mens |
SANER | 1 |
| 2017 | Landmark selection for spectral clustering based on Weighted PageRank
Dimitrios Rafailidis, Eleni Constantinou, Yannis Manolopoulos |
Future Gener. Comput. Syst. | 2 |
| 2017 | Identifying evolution patterns: a metrics-based approach for external library reuseabstractSummary Software development highly depends on using functionality of external libraries and frameworks because of the inherent benefits of software reuse. As projects evolve over time, it is a common and beneficial task to upgrade the external libraries to their latest versions because bugs are solved or new functionality is implemented. Nonetheless, external libraries evolve as well and undergo architectural and structural changes and therefore, impact the projects that use them in the case of library upgrades. In this paper, we propose a metrics‐based approach in order to identify evolution patterns of candidate reuse libraries and ultimately, assist in selecting new libraries for reuse or upgrading existing libraries. We propose a metrics suite that measures structural and behavioral attributes of software systems' evolution that affect their possible reuse by other projects. The proposed metrics measure the overall stability of software systems in terms of their structural consistency and resilience to introducing new bugs, maintainers' focus on resolving the existing bugs and their focus on preserving the system's structural complexity low. Next, we identify patterns in the metrics' behavior during projects' evolution in order to provide insight about the implications in the case of their reuse. We present our findings of a set of nine popular projects, six of which are maintained by the Apache Software Foundation, and report the results concerning the derived metrics' values and the studied library evolution patterns. Copyright © 2017 John Wiley & Sons, Ltd. Eleni Constantinou, Ioannis Stamelos |
Softw. Pract. Exp. | 1 |
| 2016 | Developers Expertise and Roles on Software TechnologiesabstractContributions to open source software provide evidence about developers' expertise and roles. Moreover, information about developers' activity can assist in identifying their competencies in software technologies. Existing project-centric approaches benefit the needs of expert identification within a project, but provide a limited view of developers' expertise. In this paper, we identify contributors' expertise and roles by considering their contribution history across multiple projects according to different technologies. Firstly, we identify terms related to software technologies and employ information from GitHub to extract contributors' activity on specific technologies. Secondly, we present four contributor roles: developer, technical leader, bug fixer and bug contributor. We study the contribution history of 2,973 users of GitHub and reveal trends in contributions in open source software that can be exploited by employers for identifying experts or by practitioners for showcasing their expertise in various technologies. Eleni Constantinou, Georgia M. Kapitsaki |
APSEC | 1 |
| 2016 | Identifying Developers' Expertise in Social Coding PlatformsabstractSocial coding platforms provide a means for software developers to acquire hands-on development experience. Their source code contributions can be used to showcase their expertise and skills in specific areas of software development to the community and potential employers. Therefore, quantifying developers' expertise based on their overall development activity can be used to provide a clear view of their experience and competencies, that is otherwise scattered across different software projects. In this paper we propose an approach that extracts developers' expertise in different programming languages. Our approach measures developers' commit activity on GitHub by considering both the quantity and the continuity of their contributions in isolated projects through time. We evaluate the generated developers' expertise profiles against recognized answering activity in Stack Overflow via a dataset of users that are active both in GitHub and Stack Overflow. Eleni Constantinou, Georgia M. Kapitsaki |
SEAA | 1 |
| 2015 | Extracting reusable components: A semi-automated approach for complex structures
Eleni Constantinou, Athanasios Naskos, George Kakarontzas, Ioannis Stamelos |
Inf. Process. Lett. | 1 |
| 2015 | An automated approach for noise identification to assist software architecture recovery techniques
Eleni Constantinou, George Kakarontzas, Ioannis Stamelos |
J. Syst. Softw. | 1 |
| 2014 | Scalable Spectral Clustering with Weighted PageRank
Dimitrios Rafailidis, Eleni Constantinou, Yannis Manolopoulos |
MEDI | 2 |
| 2014 | "With a little help from new friends": Boosting information cascades in social networks based on link injection
Dimitrios Rafailidis, Alexandros Nanopoulos, Eleni Constantinou |
J. Syst. Softw. | 3 |
| 2013 | Layer assessment of object-oriented software: A metric facilitating white-box reuse
George Kakarontzas, Eleni Constantinou, Apostolos Ampatzoglou, Ioannis Stamelos |
J. Syst. Softw. | 2 |