<?xml version="1.0" encoding="UTF-8"?>
<doi_batch version="4.4.2" xmlns="http://www.crossref.org/schema/4.4.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:jats="http://www.ncbi.nlm.nih.gov/JATS1" xsi:schemaLocation="http://www.crossref.org/schema/4.4.2 http://www.crossref.org/schema/deposit/crossref4.4.2.xsd">
<head>
<doi_batch_id>1e416013186c20a17cb4d84</doi_batch_id>
<timestamp>20230720031158121</timestamp>
<depositor>
  <depositor_name>beie:beie</depositor_name> 
  <email_address>director@blueeyesintelligence.org</email_address>
</depositor>
<registrant>WEB-FORM</registrant> 
</head>
<body>
<journal>
<journal_metadata>   <full_title>International Journal of Recent Technology and Engineering (IJRTE)</full_title>   <abbrev_title>IJRTE</abbrev_title>   <issn media_type='electronic'>22773878</issn>   <doi_data>     <doi>10.35940/ijrte.2277-3878</doi>     <resource>https://www.ijrte.org/</resource>   </doi_data> </journal_metadata> <journal_issue>  <publication_date media_type='online'>     <month>07</month>     <day>30</day>     <year>2023</year>   </publication_date>   <journal_volume>     <volume>12</volume>   </journal_volume>   <issue>2</issue> </journal_issue><!-- ============== --> <journal_article publication_type='full_text'>   <titles>     <title>A Study of The Effectiveness of Code Review in Detecting Security Vulnerabilities</title>   </titles>   <contributors>      <organization sequence='first' contributor_role='author'>Faculty of Computing, Sri Lanka Institute of Information Technology, Malabe, Sri Lanka.</organization>    <person_name sequence='first' contributor_role='author'>      <given_name>G.H.N</given_name>      <surname>Anuththara</surname>      <ORCID>https://orcid.org/0009-0009-1634-694X</ORCID>    </person_name>    <person_name sequence='additional' contributor_role='author'>       <given_name>S.S.U</given_name>       <surname>Senadheera</surname>       <ORCID>https://orcid.org/0009-0003-6061-2906</ORCID>     </person_name>     <organization sequence='additional' contributor_role='author'>Faculty of Computing, Sri Lanka Institute of Information Technology, Malabe, Sri Lanka.</organization>     <person_name sequence='additional' contributor_role='author'>       <given_name>S.M.T.V</given_name>       <surname>Samarasekara</surname>       <ORCID>https://orcid.org/0009-0008-6784-0158</ORCID>     </person_name>     <organization sequence='additional' contributor_role='author'>Faculty of Computing, Sri Lanka Institute of Information Technology, Malabe, Sri Lanka.</organization>     <person_name sequence='additional' contributor_role='author'>       <given_name>K.M.G.T</given_name>       <surname>Herath</surname>       <ORCID>https://orcid.org/0009-0000-1224-959X</ORCID>     </person_name>     <organization sequence='additional' contributor_role='author'>Faculty of Computing, Sri Lanka Institute of Information Technology, Malabe, Sri Lanka.</organization>     <person_name sequence='additional' contributor_role='author'>       <given_name>M. V. N.</given_name>       <surname>Godapitiya</surname>       <ORCID>https://orcid.org/0009-0000-2529-3311</ORCID>     </person_name>     <organization sequence='additional' contributor_role='author'>Faculty of Computing, Sri Lanka Institute of Information Technology, Malabe, Sri Lanka.</organization>     <person_name sequence='additional' contributor_role='author'>       <given_name>Dr. D. I.</given_name>       <surname>De Silva</surname>       <ORCID>https://orcid.org/0000-0001-6821-488X</ORCID>     </person_name>     <organization sequence='additional' contributor_role='author'>Faculty of Computing, Sri Lanka Institute of Information Technology, Malabe, Sri Lanka.</organization>   </contributors>    <jats:abstract xml:lang='en'>         <jats:p>Software flaws pose a severe danger to the security and privacy of computer systems and the people who use them [1]. For software systems to be reliable and available, vulnerabilities must be found and fixed before they may be used against the system [2]. Two popular methods for finding weaknesses in software systems are code review and penetration testing [3]. Which method is better for identifying vulnerabilities, nevertheless, is not widely agreed upon [4]. The usefulness of code reviews and penetration tests in locating vulnerabilities is reviewed in detail in this study. We evaluate much empirical research [5] and contrast the benefits and drawbacks of each method. According to our research, both code reviews and penetration tests are useful for uncovering vulnerabilities [6], despite the fact that their effectiveness varies based on the kind of vulnerability, the complexity of the code, and the testers' or reviewers' experience [7][8]. Additionally, we discovered that doing both penetration testing and code review together may be more efficient than using each approach alone [9]. These results may help software engineers, security experts, and researchers choose and use the right approach for locating weaknesses in software systems.</jats:p>     </jats:abstract>  <publication_date media_type='online'>     <month>07</month>     <day>30</day>     <year>2023</year>   </publication_date>   <pages>     <first_page>11</first_page>     <last_page>19</last_page>   </pages>   <crossmark>     <crossmark_version>CC BY-NC-ND 4.0</crossmark_version>     <crossmark_policy>10.35940/BEIESP.CrossMarkPolicy</crossmark_policy>     <crossmark_domains>       <crossmark_domain>          <domain>www.ijrte.org</domain>       </crossmark_domain>     </crossmark_domains>     <crossmark_domain_exclusive>true</crossmark_domain_exclusive>     <custom_metadata>       <assertion explanation='Journal Name' group_label='Journal Name' group_name='Journal' name='Declaration' order='0'>International Journal of Recent Technology and Engineering (IJRTE)</assertion>       <assertion explanation='Funding' group_label='Funding' group_name='Funding' name='Declaration' order='1'>No, We did not receive.</assertion>       <assertion explanation='Conflicts of Interest' group_label='Conflicts of Interest' group_name='Conflicts-of-Interest' name='Declaration' order='2'>No conflicts of interest to the best of our knowledge.</assertion>       <assertion explanation='Ethical Approval and Consent to Participate' group_label='Ethical Approval and Consent to Participate' group_name='Ethical-Approval-and-Consent-to-Participate' name='Declaration' order='3'>No, the article does not require ethical approval and consent to participate with evidence.</assertion>       <assertion explanation='Availability of Data and Material' group_label='Availability of Data and Material' group_name='Availability-of-Data-and-Material' name='Declaration' order='4'>Not relevant</assertion>       <assertion explanation='Authors Contributions' group_label='Authors Contributions' group_name='Authors-Contributions' name='Declaration' order='5'>All authors having equal contribution for this article.</assertion>     </custom_metadata>   </crossmark>   <doi_data>     <doi>10.35940/ijrte.B7671.0712223</doi>     <resource>https://www.ijrte.org/portfolio-item/B76710712223/</resource>   </doi_data> </journal_article>
</journal>
</body>
</doi_batch>
