Third-party libraries are often used in software development, but they may contain security vulnerabilities. Developers often lack clarity on whether their projects are affected and how to respond appropriately. This thesis presents ReachVis, an IDE plugin for analyzing and visualizing security vulnerabilities in software libraries, developed using a novel mixed-methods research approach. First, qualitative problem-centered interviews with developers identified expectations and wishes for such a tool. Based on these findings, we implemented the prototype ReachVis. To evaluate the effectiveness of the approach, a study was conducted using the NASA TLX metric. ReachVis was compared with Red Hat Dependency Analytics. ReachVis achieved an average TLX score of 11.33 and a median of 8.16,compared to 28.91 and 18.0 for the comparison tool. The results suggest that ReachVis facilitates the detection and assessment of security vulnerabilities in software libraries early in the development cycle and thus contributes to secure software development.
Ramon Jasari (Thu,) studied this question.