| 2025 | ICSE | "Just Use Rust": A Best-Case Historical Study of Open Source Vulnerabilities in C. | Andrew Meneely, Aiden Green, Tyler Jaafari, Matthew Fluet, Brandon N. Keller |
| 2024 | FIE | WIP: ChatVis: Enhancing Academic Team Collaboration through WhatsApp Chat Analytics. | Hctor G. Prez-Gonzlez, Raymundo A. Gonzlez-Grimaldo, Joshua Chibuike Nwokeji, Mei-Huei Tang, Reyes Jurez-Ramrez, Davide Piovesan, Andrew Meneely, Csar Guerra-Garca |
| 2024 | SIGCSE | Taxonomy-Based Human Error Assessment for Senior Software Engineering Students. | Benjamin S. Meyers, Andrew Meneely |
| 2023 | MSR | What Happens When We Fuzz? Investigating OSS-Fuzz Bug History. | Brandon N. Keller, Benjamin S. Meyers, Andrew Meneely |
| 2021 | ANT | An Automated Post-Mortem Analysis of Vulnerability Relationships using Natural Language Word Embeddings. | Benjamin S. Meyers, Andrew Meneely |
| 2021 | ESEM | Who are Vulnerability Reporters?: A Large-scale Empirical Study on FLOSS. | Nikolaos Alexopoulos, Andrew Meneely, Dorian Arnouts, Max Mhlhuser |
| 2019 | ESEM | Characterizing Attacker Behavior in a Cybersecurity Penetration Testing Competition. | Nuthan Munaiah, Akond Rahman, Justin Pelletier, Laurie A. Williams, Andrew Meneely |
| 2019 | ICSE | Pragmatic characteristics of security conversations: an exploratory linguistic analysis. | Benjamin S. Meyers, Nuthan Munaiah, Andrew Meneely, Emily Prud'hommeaux |
| 2019 | ICSE | Data-driven insights from vulnerability discovery metrics. | Nuthan Munaiah, Andrew Meneely |
| 2018 | ACL | A dataset for identifying actionable feedback in collaborative software development. | Benjamin S. Meyers, Nuthan Munaiah, Emily Prud'hommeaux, Andrew Meneely, Josephine Wolff, Cecilia Ovesdotter Alm, Pradeep K. Murukannaiah |
| 2017 | RE | A Domain-Independent Model for Identifying Security Requirements. | Nuthan Munaiah, Andrew Meneely, Pradeep K. Murukannaiah |
| 2016 | CCS | Beyond the Attack Surface: Assessing Security Risk with Random Walks on Call Graphs. | Nuthan Munaiah, Andrew Meneely |
| 2015 | FIE | An insider threat activity in a software security course. | Daniel E. Krutz, Andrew Meneely, Samuel A. Malachowsky |
| 2015 | MSR | Do Bugs Foreshadow Vulnerabilities? A Study of the Chromium Project. | Felivel Camilo, Andrew Meneely, Meiyappan Nagappan |
| 2013 | ESEM | When a Patch Goes Bad: Exploring the Properties of Vulnerability-Contributing Commits. | Andrew Meneely, Harshavardhan Srinivasan, Ayemi Musa, Alberto Rodriguez Tejeda, Matthew Mokary, Brian Spates |
| 2013 | FIE | Teaching Web Engineering using a project component. | Daniel E. Krutz, Andrew Meneely |
| 2013 | ICSE | Vulnerability of the day: concrete demonstrations for software engineering undergraduates. | Andrew Meneely, Samuel Lucidi |
| 2011 | ICSE | Socio-technical developer networks: should we trust our measurements? | Andrew Meneely, Laurie A. Williams |
| 2010 | ESEM | Strengthening the empirical analysis of the relationship between Linus' Law and software security. | Andrew Meneely, Laurie A. Williams |
| 2010 | ICSE | Improving developer activity metrics with issue tracking annotations. | Andrew Meneely, Mackenzie Corcoran, Laurie A. Williams |
| 2009 | CCS | Secure open source collaboration: an empirical study of linus' law. | Andrew Meneely, Laurie A. Williams |
| 2009 | SIGCSE | On preparing students for distributed software development with a synchronous, collaborative development platform. | Andrew Meneely, Laurie A. Williams |
| 2008 | ITiCSE | ROSE: a repository of education-friendly open-source projects. | Andrew Meneely, Laurie A. Williams, Edward F. Gehringer |
| 2006 | SIGCSE | Fifteen compilers in fifteen days. | Jeremy D. Frens, Andrew Meneely |