When building software today, developers rarely start from zero. Instead, they assemble applications from dozens or even hundreds of external libraries and components. This makes development faster, but it also creates a hidden risk: if a library stops being maintained, or if its maintainers respond slowly to bugs and security issues, every application depending on it becomes vulnerable. The problem is that there is no reliable way to know how well a developer or team maintains their software over time. We can look at GitHub stars or download counts, but these numbers say nothing about whether bugs get fixed quickly or security patches arrive on time. Thesis proposes a solution: a system that automatically tracks and records maintenance quality metrics - things like how fast bugs are fixed, how often updates are released, and how quickly security issues are addressed. These measurements are stored on a blockchain, making them permanent and impossible to fake. Developers sign their submissions with legally recognized digital signatures, so everyone knows exactly who is responsible for what. The result is a transparent reputation system where developers can prove their reliability through real evidence, not just promises. Software teams choosing dependencies can finally make informed decisions based on facts rather than guesswork.
When building software today, developers rarely start from zero. Instead, they assemble applications from dozens or even hundreds of external libraries and components. This makes development faster, but it also creates a hidden risk: if a library stops being maintained, or if its maintainers respond slowly to bugs and security issues, every application depending on it becomes vulnerable. The problem is that there is no reliable way to know how well a developer or team maintains their software over time. We can look at GitHub stars or download counts, but these numbers say nothing about whether bugs get fixed quickly or security patches arrive on time. Thesis proposes a solution: a system that automatically tracks and records maintenance quality metrics - things like how fast bugs are fixed, how often updates are released, and how quickly security issues are addressed. These measurements are stored on a blockchain, making them permanent and impossible to fake. Developers sign their submissions with legally recognized digital signatures, so everyone knows exactly who is responsible for what. The result is a transparent reputation system where developers can prove their reliability through real evidence, not just promises. Software teams choosing dependencies can finally make informed decisions based on facts rather than guesswork.
Evidence based reputation system for developers: automating the evaluation of maintenance interventions quality metrics
AKYSH, AKAN
2025/2026
Abstract
When building software today, developers rarely start from zero. Instead, they assemble applications from dozens or even hundreds of external libraries and components. This makes development faster, but it also creates a hidden risk: if a library stops being maintained, or if its maintainers respond slowly to bugs and security issues, every application depending on it becomes vulnerable. The problem is that there is no reliable way to know how well a developer or team maintains their software over time. We can look at GitHub stars or download counts, but these numbers say nothing about whether bugs get fixed quickly or security patches arrive on time. Thesis proposes a solution: a system that automatically tracks and records maintenance quality metrics - things like how fast bugs are fixed, how often updates are released, and how quickly security issues are addressed. These measurements are stored on a blockchain, making them permanent and impossible to fake. Developers sign their submissions with legally recognized digital signatures, so everyone knows exactly who is responsible for what. The result is a transparent reputation system where developers can prove their reliability through real evidence, not just promises. Software teams choosing dependencies can finally make informed decisions based on facts rather than guesswork.| File | Dimensione | Formato | |
|---|---|---|---|
|
AKYSH_AKAN.pdf
accesso aperto
Dimensione
1.14 MB
Formato
Adobe PDF
|
1.14 MB | Adobe PDF | Visualizza/Apri |
The text of this website © Università degli studi di Padova. Full Text are published under a non-exclusive license. Metadata are under a CC0 License
https://hdl.handle.net/20.500.12608/110130