Dear Sir/Madam,
I hope you are doing well. My name is Md Niaz Morshed, and I am a Ph.D. student in the Department of Computer Science at the University of Alabama. I am currently conducting an IRB-approved research study titled “Understanding Information Needs When Looking for Security Issues During Code Review in Open-Source Software: A survey.”
The goal of this study is to gain a deeper understanding of the challenges developers face when reviewing code for potential security issues and to examine the types of information, tools, and practices that support their efforts. As part of this work, I am seeking input from contributors who participate in code review activities within open-source projects.
I am writing to respectfully request guidance on the appropriate way to share a short, anonymous survey with contributors to this project. In particular, I would appreciate your advice on the following:
Whether there is a formal process or preferred channel for contacting contributors or maintainers for research participation;
Whether a contributor mailing list or contact mechanism exists and may be used for this purpose;
Whether posting a survey link in a public discussion or issue would be appropriate under the project's community guidelines.
I am committed to conducting this research in a way that respects the norms, values, and privacy of the open-source community. Your feedback and recommendations would be greatly appreciated.
Thank you very much for your time and consideration.
Kind Regards
NiazMd Niaz Morshed
Graduate Research Assistant,
Department of Computer Science,
University of Alabama, Tuscaloosa,
USA.