2022Unpublished venueRequires access

Security Versus Performance Bugs: How Bugs are Handled in the Chromium Project

Amrit Rajbhandari, Minhaz F. Zibran, Farjana Z. Eishita

Open publisher page 13 citations

Abstract

Bug fixing is a very important activity of software maintenance. Given the recent highlight on security and privacy, one may expect that the software vendors would give security bugs a higher priority in their bug fixing process. In this paper, we present an exploratory study of different categories (i.e., security, performance, and other) of bugs in the maintenance of the Chromium browser. In particular, we study the phenomena such as how much time is spent in bug triage, how fast different types of bugs are fixed, variations of developers' experiences who fix those bugs, and show often those fixed bugs are reopened. We find that the performance bugs are triaged and fixed faster. Security bugs, for fixing, are assigned to more experienced developers. All categories of bugs are almost equally reopened once closed.

About this research paper

What this paper is about

Bug fixing is a very important activity of software maintenance. Given the recent highlight on security and privacy, one may expect that the software vendors would give security bugs a higher priority in their bug fixing process. In this paper, we present an exploratory study of different categories (i.e., security, performance, and other) of bugs in the maintenance of the Chromium browser. In particular, we study the phenomena such as how much time is spent in bug triage, how fast different types of bugs are fixed, variations of developers' experiences who fix those bugs, and show often those fixed bugs are reopened. We find that the performance bugs are triaged and fixed faster. Security bugs, for fixing, are assigned to more experienced developers. All categories of bugs are almost equally reopened once closed.

Why it matters

OpenAlex reports 13 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Bug fixing is a very important activity of software maintenance. Given the recent highlight on security and privacy, one may expect that the software vendors would give security bugs a higher priority in their bug fixing process. In this paper, we present an exploratory study of different categories (i.e., security, performance, and other) of bugs in the maintenance of the Chromium browser. In particular, we study the phenomena such as how much time is spent in bug triage, how fast different types of bugs are fixed, variations of developers' experiences who fix those bugs, and show often those fixed bugs are reopened. We find that the performance bugs are triaged and fixed faster. Security bugs, for fixing, are assigned to more experienced developers. All categories of bugs are almost equally reopened once closed.

Key concepts: Security bug, Software bug, Computer science, Computer security, Software, Process (computing), Triage, Software security assurance

Related papers

Back to paper searchBrowse research topicsOriginal source
Security Versus Performance Bugs: How Bugs are Handled in the Chromium Project — Research Paper | ScholarLens