发表机构
University of Colorado Colorado Springs; Purdue University(科罗拉多大学科泉分校; 普渡大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究针对TianoCore核心项目EDK II,通过分析漏洞数据发现关键信息缺失问题,拟在GitHub Issues的漏洞报告模板中新增字段,计划经开发者反馈调整及A/B测试验证,以优化UEFI固件漏洞分类与解决流程。
AI 中文摘要
我们提出增强TianoCore开源社区使用的GitHub Issues问题跟踪系统中的漏洞报告模板,旨在改进漏洞分类与解决流程。我们分析漏洞仓库数据,发现对漏洞分类和修复有用的信息模式,但部分信息仅偶尔出现在漏洞报告的自由文本中。因此,我们提议在现有的TianoCore漏洞报告模板中添加几个新字段。本研究聚焦于TianoCore的核心项目EDK II,它构成了各固件厂商和原始设备制造商的UEFI固件核心。本研究目前处于进行中,迄今我们已采访部分开发者以获取反馈并调整所提方法,计划开展更多针对TianoCore社区的采访,以进行A/B测试并验证我们的方法,从而实现高效的漏洞分类与解决。
英文摘要
We propose enhancing the bug report templates in the GitHub Issues issue tracking system used by the TianoCore open-source community with the aim of improving the bug triage and resolution process. We analyze the bug repository data and find patterns of information that are useful for bug triage and fixing. However, some of them are only occasionally included in the free-form text of bug reports. Therefore, we propose adding a few new fields to the existing TianoCore bug report template. In this study, we focus on the key TianoCore project, EDK II, which constitutes the core of the UEFI firmware across various firmware vendors and original equipment manufacturers. This study is currently a work-in-progress. So far, we have interviewed a few developers to obtain their feedback and adjust the proposed approach. We are planning more interviews with the TianoCore community to conduct A/B tests and validate our approach to achieve effective and efficient bug triage and resolution.
CommentsThis work is accepted to be presented in the FTA 2026 workshop but is not published in the proceedings, according to the ACM SIGSOFT policy (https://www2.sigsoft.org/policies/pcpolicy/) that does not allow the work of organizers to be published in the workshop proceedings. This revision adds this acknowledgment and removes ACM proceedings publication metadata