Go to main navigation Navigation menu Skip navigation Home page Search

Research seminar | The impact and limitations of automating software component quality management - 29 Apr 2026

Join us at the House of Innovation for a research seminar with Assistant Professor Seongkyoon Jeong from the University of Tennessee. Register now to secure your seat.

Paper title and abstract

The Impact and Limitations of Automating Software Component Quality Management

Abstract: Security vulnerabilities in external software components that provide pre-built functionality (i.e., dependencies) represent a major threat to software quality. When a vulnerable dependency is exploited, the resulting breach can cascade to all downstream software products that rely on it, causing widespread operational disruption. Consequently, developers must promptly remediate vulnerable dependencies. Automation has emerged as a promising approach to accelerating this process. We study whether adopting an automated dependency management tool, Dependabot, improves the speed at which vulnerable dependencies are resolved. Using data from open-source JavaScript packages, we identify instances of vulnerable dependencies. Our analysis shows that packages adopting Dependabot exhibit a 60% reduction in resolution time. However, automation is not a panacea. Even among adopters, vulnerabilities are not addressed immediately: the median resolution time is 82 days. We investigate the sources of these delays and find that, although Dependabot reduces attention-related frictions by re-engaging developers with inactive or low-maintenance packages, resolution is still constrained by human-driven factors, such as slow processing of automated code changes and the difficulty of verifying compatibility with other components.
 

About Seongkyoon Jeong

Seongkyoon Jeong is an assistant professor of supply chain management at the University of Tennessee, Knoxville’s Haslam College of Business. His research focuses on contemporary issues in supply chain management, such as digital supply chain, cybersecurity and sustainable operations. Before obtaining his doctorate from Arizona State University, Jeong worked at the Korea Institute of Machinery and Materials, a government-funded research institute specializing in interorganizational relationships and R&D strategy.

House of Innovation Gender Innovation Leadership Management Lunch seminar Research seminar