Stefano Zacchiroli
Full professor of computer science at Polytechnic Institute of Paris. Co-founder & CSO Software Heritage. Free Software activist. Previously: Debian leader, Open Source Initiative board.
Repeat after me: if #Firefox stops being maintained, #LibreWolf is not a viable long-term alternative (nor is any other Firefox-based web browser).
The « Software Source Code Exhbition », co-curated by Mathilde Fichen from @swheritage@mstdn.social, is now on display at Cité des Sciences et de l'Industrie, the most prominent science museum in #Paris, France.
It's until March 25th, 2026 and in the free part of the museum, no ticket needed.
If you are around and into software, I recommend visiting it, as it's super super fascinating.
I am recruiting a postdoctoral researcher to work at Polytechnic Institute of Paris for 30 months, in the fields of #SoftwareEngineering and #Cybersecurity The recruited person will work on leveraging @swheritage@mstdn.social as a knowledge base to improve the state of the art of (binary) software composition analysis (SCA), to detect the presence and details of #OpenSource software shipped within IT products. See https://institutminestelecom.recruitee.com/l/en/o/post-doctorante-ou-post-doctorant-en-genie-logiciel-et-cybersecurite-cdd-de-30-mois-2-5 for details and application instructions. #getfedihired
Welcoming @benhermann@mastodon.social at #SoftwareHeritage headquarters today, to talk about « What We Learned in 15 Years of #ArtifactEvaluation » #research #digitalpreservation #softwareEngineering
WOW! Full #security devroom at #FOSDEM, for the presentation of "ROSA: finding #backdoors with #fuzzing" by my fellow co-authors @plumtrie@mastodon.social and M. Marcozzi.
More about this work in the full paper at https://arxiv.org/abs/2505.08544 (#openaccess, of course)
In « Promises, Perils, and (Timely) Heuristics for Mining Coding Agent Activity » (#openaccess preprint at: https://hal.science/hal-05487636) we review the potential and risks of mining agent-based coding activities in empirical #SoftwareEngineering #research. To be presented at the #MSR2026 conference this summer.
Is there a good URL scheme to use as href link when publishing Matrix account info on the web?
Ideally it should be something that automatically open a chat to you if you are already on Matrix somehow, or explains how to create an account (on whatever server one likes) if not.
Congrats to my coauthors @plumtrie@mastodon.social, E. Decoux, and M. Marcozzi for the best artifact #award at #ICSE2025. 99% of the merit for this goes to Dimitri (in the picture), who did all the heavy lifting, chapeau.
The artifact itself is worth looking at as blueprint/example for students and colleagues working on replication packages in complex contexts (like ours here, having to replicate long running fuzzing experiments).
My colleagues at CEA in #Paris, France, are hiring a 2-year #postdoc to work on the joint research project #SECUBIC about #fuzzing binaries to identify #backdoors. (See this recently joint work at #ICSE2025 for previous results: https://upsilon.cc/~zack/research/publications/icse-2025-rosa-fuzzing.pdf )
If you're interested, or know interested candidates, head to: https://secubic-ptcc.github.io/jobs/open/2025/04/02/postdoc-supply-chain-binary-fuzzing.html for details.
Advice to young colleagues when preparing rebuttals for papers submitted to major academic conferences or journals. When there is a soft limit (e.g., 1000 words) it is in your best interest to make your key rebuttal arguments fit that limit. And only later, if you really have to, add additional arguments/details after that limit, clearly marking the separation between the two. What you should not do, is just ignore the limit and submit a free-flow long text. It will not serve your cause.