Security by documentation? characterizing GitHub SECURITY.md policy and their adoption in Python libraries

dc.contributor.authorChoetkiertikul M.
dc.contributor.authorKancharoendee S.
dc.contributor.authorJongyingyos C.
dc.contributor.authorPhichitphanphong T.
dc.contributor.authorRagkhitwetsagul C.
dc.contributor.authorReid B.
dc.contributor.authorKula R.G.
dc.contributor.authorSunetnanta T.
dc.contributor.correspondenceChoetkiertikul M.
dc.contributor.otherMahidol University
dc.date.accessioned2026-02-15T18:14:17Z
dc.date.available2026-02-15T18:14:17Z
dc.date.issued2026-05-01
dc.description.abstractWith security in open-source software development increasingly becoming crucial, security policies are one way to manage vulnerabilities and guide users toward safe practices. To support secure development, platforms like GitHub provide a dedicated section for security policies within repositories. Existing studies focus on the adoption of security policies. However, the detailed content of the security policies has not been examined. Our study aims to fill this gap by analyzing the security policies of 679 PyPI Python libraries hosted on GitHub. We examine the characteristics and content of existing policies and investigate the relationship with project characteristics and recommended security practices by comparing security practice assessments between projects with and without established security policies. The result indicates that projects with security.md shows stronger recommended security practices. This study highlights the importance of adopting a clear and comprehensive security policy to enhance the overall security practices of open-source projects.
dc.identifier.citationEmpirical Software Engineering Vol.31 No.3 (2026)
dc.identifier.doi10.1007/s10664-025-10794-z
dc.identifier.eissn15737616
dc.identifier.issn13823256
dc.identifier.scopus2-s2.0-105029557787
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/123456789/115060
dc.rights.holderSCOPUS
dc.subjectComputer Science
dc.titleSecurity by documentation? characterizing GitHub SECURITY.md policy and their adoption in Python libraries
dc.typeArticle
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=105029557787&origin=inward
oaire.citation.issue3
oaire.citation.titleEmpirical Software Engineering
oaire.citation.volume31
oairecerif.author.affiliationThe University of Osaka
oairecerif.author.affiliationMahidol University
oairecerif.author.affiliationNara Institute of Science and Technology

Files

Collections