Skip to content

Commit

Permalink
Comment: Added report for September 2023.
Browse files Browse the repository at this point in the history
  • Loading branch information
openrefactory committed Sep 29, 2023
1 parent 2c8cc7d commit cec519f
Show file tree
Hide file tree
Showing 2 changed files with 33 additions and 0 deletions.
2 changes: 2 additions & 0 deletions alpha/engagements/2023/OpenRefactory/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,8 @@ This engagement started in July 2023. The metrics will be reviewed in December 2

* [July 2023](update-2023-07.md)
* [August 2023](update-2023-08.md)
* [September 2023](update-2023-09.md)


## Primary Contacts

Expand Down
31 changes: 31 additions & 0 deletions alpha/engagements/2023/OpenRefactory/update-2023-09.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# OpenRefactory Update: September 2023

## Scan Results

Link to results: https://docs.google.com/spreadsheets/d/1K8dc6SrSEoqqh46cFisZM1tiN4CigaXsqkCKfCM8UTs/edit#gid=228743971

In the month of September, the engineers at OpenRefactory focused on Python and Java projects.

The outcome of these efforts is in the following table. Note that the numbers are cumulative.

| | Aug 2023 | Sep 2023 |
|--|--|--|
| Projects analyzed | 132 | 458 |
| Projects with no bugs | 98 | 398 |
| Total bugs filed | 33 | 75 |
| Security/Reliability bugs filed | 12 | 23 |
| Bugs with a fix suggestion | 26 | 64 |
| Bugs with a PoC exploit | 6 | 13 |
| Fixes merged by maintainers | 15 (45%) | 38 (51%) |
| Fixes ignored by maintainers | Not measured | 8 (11%) |
| Reports still open | Not measured | 29 (39%) |

In September, 11 new security and reliability issues were identified, including cross-site request forgery, log injection, null dereference and unsafe library call (mktemp) issues.

## Improvement in Bug Acceptance Rate
At this point, over half of the reported bugs are accepted. This is imporvement upon the result from the last month.

The actual fixing rate may be even higher. Many bugs that were reported in August eventually got fixed in September. For example a security issue involving unsafe library call (mktemp) was reported on August 10, 2023. At the time of writing the report, the bug has been accepted but it will probably be added to the codebase sometime in October. Similarly, a bug reported in April 2023 during the second PoC has been accepted but the process of inclusion is still going on.

Over the course of time, we will see this happening in many of the bug reports that are still open.

0 comments on commit cec519f

Please sign in to comment.