A Practical Approach to the Automatic Classification of Security-Relevant Commits oss machine-learning Related Secure Software Development in the Era of Fluid Multi-party Open Software and Services Project Kb The Used, the Bloated, and the Vulnerable: Reducing the Attack Surface of an Industrial Application LastPyMile: Identifying the Discrepancy between Sources and Packages Toward Automated Exploit Generation for Known Vulnerabilities in Open-Source Libraries