Publications

International Journals

[J1] Nocera, S., Romano, S., Francese, R., & Scanniello, G. (2025). Software engineering education: Results from a training intervention based on SonarCloud when developing web apps. Journal of Systems and Software, 222, 112308. Elsevier.

Conference Proceedings

[C11] Nocera, S., Vegas, S., Scanniello, G., & Juristo, N. (2025, April). Software Composition Analysis and Supply Chain Security in Apache Projects: an Empirical Study. In 2025 IEEE/ACM 22th International Conference on Mining Software Repositories (MSR) (to appear). IEEE.

[C10] Scanniello, G., Di Penta, M., Romano, S., Francese, R., Nocera, S., Cassieri, P., Bifolco, D., & Zampetti, F. (2024, October). MSR4SBOM: Mining software repositories for enhanced software bills of materials. In Proceedings of the 18th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM) (pp. 589-593). ACM.

[C9] Nocera, S., Di Penta, M., Francese, R., Romano, S., & Scanniello, G. (2024, October). If it’s not SBOM, then what? How Italian Practitioners Manage the Software Supply Chain. In 2024 IEEE International Conference on Software Maintenance and Evolution (ICSME) (pp. 730-740). IEEE.

[C8] Nocera, S., Romano, S., Di Nucci, D., Francese, R., Palomba, F., & Scanniello, G. (2024, September). Do Static Analysis Tools Improve Awareness and Attitude Toward Secure Software Development?. In International Conference on the Quality of Information and Communications Technology (QUATIC) (pp. 399-407). Springer.

[C7] Bifolco, D., Nocera, S., Romano, S., Di Penta, M., Francese, R., & Scanniello, G. (2024, June). On the Accuracy of GitHub’s Dependency Graph. In Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering (EASE) (pp. 242-251). ACM.

[C6] Nocera, S., Romano, S., Francese, R., & Scanniello, G. (2024, April). Training for Security: Results from Using a Static Analysis Tool in the Development Pipeline of Web Apps. In Proceedings of the 46th International Conference on Software Engineering: Software Engineering Education and Training (ICSE-SEET) (pp. 253-263). ACM.

[C5] Nocera, S., Romano, S., Di Penta, M., Francese, R., & Scanniello, G. (2023, October). Software bill of materials adoption: a mining study from GitHub. In 2023 IEEE International Conference on Software Maintenance and Evolution (ICSME) (pp. 39-49). IEEE.

[C4] Nocera, S., Romano, S., Francese, R., & Scanniello, G. (2023, September). A large-scale fine-grained empirical study on security concerns in open-source software. In 2023 49th Euromicro Conference on Software Engineering and Advanced Applications (SEAA) (pp. 418-425). IEEE.

[C3] Nocera, S., Romano, S., Francese, R., Burlon, R., & Scanniello, G. (2023, September). Managing Vulnerabilities in Software Projects: the Case of NTT Data. In 2023 49th Euromicro Conference on Software Engineering and Advanced Applications (SEAA) (pp. 247-253). IEEE.

[C2] Nocera, S., Francese, R., & Scanniello, G. (2023, June). Training Bachelor Students to Design Better Quality Web Apps: Preliminary Results from a Prospective Empirical Investigation. In Proceedings of the 27th International Conference on Evaluation and Assessment in Software Engineering (EASE) (pp. 465-469). ACM.

[C1] Nocera, S., Romano, S., Francese, R., & Scanniello, G. (2023, May). Training for security: planning the use of a SAT in the development pipeline of web Apps. In 2023 IEEE/ACM 45th International Conference on Software Engineering: Software Engineering Education and Training (ICSE-SEET) (pp. 40-45). IEEE.