{"title":"From Parallel Paths to Crossroads: A Study of DevOps and Low-Code Development Platforms Through Practitioner Insights","authors":"Saima Rafi, Muhammad Azeem Akbar","doi":"10.1002/smr.70163","DOIUrl":"https://doi.org/10.1002/smr.70163","url":null,"abstract":"<p>Low-Code Development Platforms (LCDPs) and DevOps share a common motive to increase agility during the software development process. DevOps focuses on automation, continuous delivery, and rapid response, whereas LCDPs support these practices by simplifying automation through visual programming and rapid prototyping, enabling teams to focus their expertise on decision-making and other strategic tasks. To investigate how the crossroads of LCDPs and DevOps are valuable in achieving better agility and efficiency, we have conducted interviews with 12 IT project team members who deal with LCDPs and the DevOps environment. The objective of this study is to understand the concept of DevOps with LCDPs and to explore how their integration can contribute to the software development process and organizational agility from practitioners' perspectives. To analyze the interview data, we employed a Grounded Theory (GT) approach to systematically code the data and identify emerging categories and themes. The findings suggested that the crossroads of DevOps and LCDPs serve as an effective channel to operationalize the concept of continuous everything in a more efficient manner. However, to achieve this integration successfully, organizations must consider factors such as bridging gaps between talent needs and the available employment pool, governance, scalability, and a collaborative culture. Finally, we discussed the implications of our findings for practitioners and researchers, as well as opportunities for future research.</p>","PeriodicalId":48898,"journal":{"name":"Journal of Software-Evolution and Process","volume":"38 9","pages":""},"PeriodicalIF":1.6,"publicationDate":"2026-08-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1002/smr.70163","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148816598","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Learning Developer-Code Contribution Relationship to Improve Code Readability Assessment","authors":"Qing Mi, Yinghui Wang, Jingyan Li","doi":"10.1002/smr.70168","DOIUrl":"https://doi.org/10.1002/smr.70168","url":null,"abstract":"<div>\u0000 \u0000 <p>Automated code readability assessment is essential for software maintenance and evolution. Current approaches mainly rely on structural, syntactic, and semantic features of individual code files to perform assessment, yet they ignore repository-level relational information. A critical missing dimension is the contribution relationships between developers and the code files they modify within a repository, which reflect individualized coding style consistency across files. To mitigate this research gap, we formally define and model the developer-code contribution relationships (DCR) for code readability assessment. We first build a heterogeneous graph, where nodes represent developers and code files, and weighted edges quantify developers' contribution ratios. On top of this graph, we adopt a heterogeneous graph attention network (HAN) to learn relational embeddings, which capture cross-file readability similarities caused by common developers. We then combine the learned relational embeddings with high-quality features from state-of-the-art pretrained code readability models to complete the readability assessment. Evaluated on a real GitHub repository dataset, our method delivers stable performance improvements over existing baselines. Extensive experiments also verify that the DCR feature maintains strong generalizability across various graph neural network architectures. This study demonstrates that exploiting repository-level developer-code relations is a promising direction to further boost the performance of automated code readability assessment.</p>\u0000 </div>","PeriodicalId":48898,"journal":{"name":"Journal of Software-Evolution and Process","volume":"38 9","pages":""},"PeriodicalIF":1.6,"publicationDate":"2026-08-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148816676","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Daria Levaniuk, Bilal Naqvi, Antti Knutas, Muhammad Azeem Akbar
{"title":"Toward a Persona-Driven Approach in Cybersecurity: Insights From a Systematic Literature Review","authors":"Daria Levaniuk, Bilal Naqvi, Antti Knutas, Muhammad Azeem Akbar","doi":"10.1002/smr.70165","DOIUrl":"https://doi.org/10.1002/smr.70165","url":null,"abstract":"<p>In recent years, developing secure yet usable systems has been one of the top concerns in cybersecurity research and practice. Research indicates that many data breaches and other cybercrimes directed toward exploiting human factors could be prevented by an inclusive and human-centered cybersecurity design. When it comes to human-centered design, the use of the persona approach can assist in considering the users' needs and aspirations while designing and developing cybersecurity systems and services. In addition, personas can be useful to mitigate the risks of several attacks, increase security awareness, and also enable a better understanding of hacker behavior by modeling different threat scenarios. We conducted a systematic literature review (SLR) of 63 research articles from 2013 to 2024 across three digital databases (ACM, Scopus, and Web of Science). The study focuses on (1) key persona types proposed in the cybersecurity domain; (2) the areas of cybersecurity in which these personas have been proposed; and (3) opportunities and future directions for utilizing the persona approach to address cybersecurity issues. The findings identified the following four types of security personas: attackers, end-users, security workers, and others. Further analysis revealed a distribution matrix and a taxonomy presenting security awareness and threat modeling and mitigation as future research directions and opportunities that exist for improvement of the state of the art of social-media security and privacy, and integrating AI to Cybersec areas. The findings also have implications for practice, including improvements in developmental approaches, training and awareness programs, and increased resilience to cyber-attacks.</p>","PeriodicalId":48898,"journal":{"name":"Journal of Software-Evolution and Process","volume":"38 8","pages":""},"PeriodicalIF":1.6,"publicationDate":"2026-08-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1002/smr.70165","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148784898","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Fazli Rabi, Muhammad Ilyas, Nasir Rashid, Abid Ghaffar
{"title":"Requirements Engineering Challenges and Solutions in Open-Source Software Development","authors":"Fazli Rabi, Muhammad Ilyas, Nasir Rashid, Abid Ghaffar","doi":"10.1002/smr.70166","DOIUrl":"https://doi.org/10.1002/smr.70166","url":null,"abstract":"<div>\u0000 \u0000 <p>In the rapidly evolving field of software development, open-source software (OSS) has gained significant momentum due to its collaborative nature and emphasis on knowledge sharing. OSS source code is available under a license that allows users to inspect, improve, and modify it. In OSS, requirements are often created through informal online discussions, developer brainstorming, feature requests, and user feedback. Ambiguous or conflicting requirements can harm the software development process. The requirements engineering (RE) process in OSS faces several challenges, such as incomplete and ambiguous requirements, poor requirements prioritization, and conflicts among stakeholders over requirements. This research aims to identify and validate key challenges and their solutions within the RE process for open-source software development (OSSD). A Multivocal Literature Review (MLR) was conducted using a customized search string aligned with our research questions (RQs). Following the MLR, an empirical study using a questionnaire survey (QS) was conducted to validate the findings. The results from the QS align with the conclusions drawn from the MLR. We identified a total of nine challenges across 47 selected articles (37 formal literature, 10 gray literature). To address these challenges, 66 practices/solutions are proposed. The best practices include involving developers and users in the RE process, along with formal requirements documentation and prioritization. The findings from this research will help OSS practitioners and academic researchers gain insights into the RE process, thereby improving it within OSS projects.</p>\u0000 </div>","PeriodicalId":48898,"journal":{"name":"Journal of Software-Evolution and Process","volume":"38 8","pages":""},"PeriodicalIF":1.6,"publicationDate":"2026-08-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148784897","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Guo Xuwei, Zulkefli Mansor, Zhao Xiaoyan, Li Liangyu
{"title":"Agile Software Cost Estimation Model Based on Constricted Particle Swarm Optimization","authors":"Guo Xuwei, Zulkefli Mansor, Zhao Xiaoyan, Li Liangyu","doi":"10.1002/smr.70164","DOIUrl":"https://doi.org/10.1002/smr.70164","url":null,"abstract":"<div>\u0000 \u0000 <p>Cost estimation is a critical task in software engineering and is particularly challenging in Agile projects. Although various optimization methods have been proposed to improve estimation accuracy, estimates often still deviate from actual costs. This study proposes the use of Constricted Particle Swarm Optimization (CPSO) to tune an Agile cost estimation model. Based on data from 21 industrial Agile software development projects, the model uses historical story points, team velocity, team wages, and workdays as input features. The performance of the CPSO algorithm is then systematically evaluated on this small dataset. The model is reparameterized with four tunable parameters—<span></span><math>\u0000 <semantics>\u0000 <mrow>\u0000 <mi>α</mi>\u0000 <mo>,</mo>\u0000 <mspace></mspace>\u0000 <mi>C</mi>\u0000 <mo>,</mo>\u0000 <mspace></mspace>\u0000 <mi>D</mi>\u0000 </mrow>\u0000 <annotation>$$ alpha, kern0.3em C,kern0.3em D $$</annotation>\u0000 </semantics></math>, and <span></span><math>\u0000 <semantics>\u0000 <mrow>\u0000 <mi>E</mi>\u0000 </mrow>\u0000 <annotation>$$ E $$</annotation>\u0000 </semantics></math>—and CPSO is applied to minimize MMRE on the training folds to obtain optimal parameter sets. Evaluation is carried out using outer fivefold cross-validation, with hyperparameter tuning performed on the training data, and performance is compared with a standard PSO baseline and the results reported by Zia et al. The CPSO-optimized model achieves an MMRE of (4.74% <span></span><math>\u0000 <semantics>\u0000 <mrow>\u0000 <mo>±</mo>\u0000 </mrow>\u0000 <annotation>$$ pm $$</annotation>\u0000 </semantics></math> 1.89%) on test folds and a PRED (10%) of (96.00% <span></span><math>\u0000 <semantics>\u0000 <mrow>\u0000 <mo>±</mo>\u0000 </mrow>\u0000 <annotation>$$ pm $$</annotation>\u0000 </semantics></math> 8.94%). The MMRE represents a 9.71% relative reduction compared with the employed baseline and a 17.71% relative reduction compared with the result reported by Zia et al. The contribution of this study lies in systematically embedding CPSO into an identifiable agile cost estimation model and evaluating it within a rigorous outer-layer cross-validation and ensemble prediction framework. The results indicate that CPSO can effectively tune the Agile cost estimation model within the specific dataset and experimental setting considered in this study. The findings should be interpreted as an incremental contribution based on a small industrial dataset, and they provide parameter-level insights that may support future calibration of agile cost estimation models on larger and more heterogeneous datasets.</p>\u0000 </div>","PeriodicalId":48898,"journal":{"name":"Journal of Software-Evolution and Process","volume":"38 8","pages":""},"PeriodicalIF":1.6,"publicationDate":"2026-08-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148753653","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Motivation and Psychological Well-Being of Software Engineers in the Generative AI Era: An Analysis of the Online Discourse","authors":"Amir Altork, Igor Wiese, Jorge Melegati","doi":"10.1002/smr.70162","DOIUrl":"https://doi.org/10.1002/smr.70162","url":null,"abstract":"<div>\u0000 \u0000 <p>The increasing integration of artificial intelligence (AI) within software engineering is reshaping the profession, leading to opportunities for innovation and productivity. However, while its technical advantages are clear, it is essential to consider the psychological effects AI may have. As software engineers play a crucial role in software development, any impact on their mental well-being can profoundly affect the pace and quality of work. This study aims to investigate the psychological effects of AI adoption on software engineers, focusing on their emotional well-being, motivation, and the broader implications for their professional identity. We conducted a qualitative survey based on online documents, such as blog posts, to identify the diversity of software developers' impressions on using AI for software engineering. We analyzed the selected documents using thematic analysis. The analysis revealed that rather than a single and uniform perception, there is a duality of positive and negative affects towards AI, which could manifest even in the same individual. These affects are generally associated with experiences that also can be positive and negative. These affects can have a profound impact on the motivation and psychological well-being of software developers. Our results provide evidence that practitioners are excited about the increasing use of AI tools, but, at the same time, they fear the consequences of this change leading to negative feelings, such as sadness. These results indicate the need for further research on preparing practitioners for this new wave of changes.</p>\u0000 </div>","PeriodicalId":48898,"journal":{"name":"Journal of Software-Evolution and Process","volume":"38 8","pages":""},"PeriodicalIF":1.6,"publicationDate":"2026-08-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148753234","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Assessing the Impact of System Architecture on the Success of Project Management Methodologies in Software Engineering","authors":"Amany A. Slamaa","doi":"10.1002/smr.70160","DOIUrl":"https://doi.org/10.1002/smr.70160","url":null,"abstract":"<div>\u0000 \u0000 <p>Aligning business and IT is crucial in the software industry, where successful software projects depend not only on technology but also on management methodology. Software implementation involves development, migration, and tailoring across architecture-based systems. The previous studies care on measuring success or failure of project methodologies without interest in system architectures and their effect on project management phases. The wrong selection of management methodology means failure of IT firms, where there is a lack in studying the success factor of selecting suitable project management methodology. Furthermore, there is no study until now that cares on searching the relationship between system architectures and project management methodologies. This paper fills this gap by finding answers for the research question “is system architecture's type one of selection factor for methodology of software project management?” This study investigates different models that measured success of the most popular project management methodologies (waterfall, agile, scrum, Kanban, Scrumban, agile-waterfall, and DevOps) since 2019 until Jan 2026 through all three cases of software development (customization, ETO developing, migration) for three system architectures (MSA, SOA, Monolith). This study uses descriptive statistics to study the relation between system architectures and software project management. Pearson Correlation and Paired <i>t</i>-test are used to study the success of developing system architecture by management methodologies. Means and Cohen's <i>d</i> are also used to measure the degree of effect. The main result is that management methodology has variable significance in different cases of developing three architecture-based systems. Selecting a system architecture is correlated and one of project management's success factors.</p>\u0000 </div>","PeriodicalId":48898,"journal":{"name":"Journal of Software-Evolution and Process","volume":"38 8","pages":""},"PeriodicalIF":1.6,"publicationDate":"2026-08-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148753273","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Lucas Carvalho, João P. Biazotto, Daniel Feitosa, Rick Kazman, Elisa Y. Nakagawa
{"title":"Technical Debt Management in Continuous Software Engineering: State of the Art and Research Agenda","authors":"Lucas Carvalho, João P. Biazotto, Daniel Feitosa, Rick Kazman, Elisa Y. Nakagawa","doi":"10.1002/smr.70161","DOIUrl":"https://doi.org/10.1002/smr.70161","url":null,"abstract":"<p>Software companies have streamlined their engineering processes, and continuous development has been key to achieving flexible, market-driven software solutions. Continuous software engineering (CSE) emerged as an approach to iteratively develop and maintain software, integrating business strategy, development, and operations aligned with agile principles. CSE activities also lead to technical debt (TD) buildup, negatively impacting software quality over time, so technical debt management (TDM) in CSE is crucial. However, TD in CSE is still poorly understood, as well as its causes and consequences, and how to better manage it. In addition, to the best of our knowledge, no study has investigated TDM in CSE. This paper then presents the state of the art of TDM in CSE, focusing on TD causes and consequences and how to manage them continuously. For this, we carefully examined the literature and selected 56 relevant studies from an initial set of 1299. Our main findings indicate that the field is relatively young and has considerable industry involvement. While most studies reported an experience with TD in continuous and agile contexts or the use of systematic approaches for TDM (e.g., frameworks and processes), none investigated TD explicitly in CSE or tried to understand its causes and consequences in those contexts. Some CSE activities addressed TD, particularly those associated with development, such as continuous architecting, coding, verification/testing, and documentation. Other important activities at the business and operation levels were left aside. These findings supported us in defining a research agenda with important research opportunities that could contribute to maturing the field.</p>","PeriodicalId":48898,"journal":{"name":"Journal of Software-Evolution and Process","volume":"38 8","pages":""},"PeriodicalIF":1.6,"publicationDate":"2026-08-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1002/smr.70161","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148752447","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Michele Lizzit, Francesco Pinzauti, Marino Miculan, Vincenzo Riccio
{"title":"Security Assessment of Private Package Repositories: An Experience on Acc-Py at CERN","authors":"Michele Lizzit, Francesco Pinzauti, Marino Miculan, Vincenzo Riccio","doi":"10.1002/smr.70159","DOIUrl":"https://doi.org/10.1002/smr.70159","url":null,"abstract":"<p>The introduction of package managers had a huge impact on software development, as they facilitate dependency management and the access to reusable code components. However, reliance on centralized repositories introduces security risks, as they are increasingly exploited in supply chain attacks. To reduce these risks, many companies rely on private package managers and repositories. Although public package repositories have been extensively studied, private ones remain underexplored. This paper presents a security comparison of private package repositories versus their public counterparts, through our experience on PyPI and CERN's Acc-Py. We perform a comprehensive security assessment of both repositories, complemented by discussions with the CERN development team. Using open-source static analyzers, we find that Acc-Py hosts packages with fewer potential security issues than those on the broad PyPI ecosystem. However, it remains susceptible to dependency confusion attacks due to namespace collisions with PyPI. Our dynamic analysis technique identifies telemetry collection as a privacy-monitoring trade-off. Our study provides valuable insights for analyzing and strengthening the security of private repositories, addressing their unique security challenges and attack surfaces.</p>","PeriodicalId":48898,"journal":{"name":"Journal of Software-Evolution and Process","volume":"38 8","pages":""},"PeriodicalIF":1.6,"publicationDate":"2026-07-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1002/smr.70159","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148616988","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Rodolfo Barbosa dos Santos, Luiz Eduardo Galvão Martins
{"title":"Artificial Intelligence Techniques to Enhance Cost, Effort, and Schedule Estimates in Software Development Projects: A Systematic Literature Review","authors":"Rodolfo Barbosa dos Santos, Luiz Eduardo Galvão Martins","doi":"10.1002/smr.70158","DOIUrl":"https://doi.org/10.1002/smr.70158","url":null,"abstract":"<p>The inaccuracy of cost, effort, and schedule estimates remains one of the primary factors associated with failures in software development projects, particularly in contexts characterized by high complexity and frequent changes in requirements. Given the well-documented limitations of traditional estimation methods, this study aims to systematically analyze how artificial intelligence (AI) techniques have been applied to improve the accuracy of such estimates in software projects. To this end, a rigorous systematic literature review (SLR) was conducted, structured according to the PICOC protocol and established guidelines for systematic reviews, encompassing searches in the IEEE Digital Library, ACM Digital Library, SpringerLink, and ScienceDirect. In total, 108 primary studies published between 2015 and 2025 were analyzed, selected based on predefined inclusion and exclusion criteria as well as methodological quality assessment. The findings indicate that techniques such as artificial neural networks, optimization algorithms, machine learning models, and hybrid approaches consistently yield improvements in estimation accuracy, with average error reductions reported in the literature ranging approximately from 15% to 30% when compared with traditional methods. The reviewed studies also highlight challenges related to data quality and availability, model reproducibility, and the feasibility of deploying these approaches in real-world environments. As a contribution, this SLR provides a structured synthesis of the state of the art, identifies research gaps, and offers valuable insights for both the academic community and industry practitioners in the development of more accurate and reliable estimation models and tools.</p>","PeriodicalId":48898,"journal":{"name":"Journal of Software-Evolution and Process","volume":"38 8","pages":""},"PeriodicalIF":1.6,"publicationDate":"2026-07-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1002/smr.70158","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148616696","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}