The move towards international harmonization of accounting standards has dominated the work program of International Accounting Standards Board (IASB) in the past years. This paper aims to verify the compliance of t...The move towards international harmonization of accounting standards has dominated the work program of International Accounting Standards Board (IASB) in the past years. This paper aims to verify the compliance of the comprehensive income (CI) statement format with International Accounting Standard (IAS) 1-presentation of financial statements, which was revised in 2007. The changes introduced by the 2011 revision are also taken into account. For this purpose, this study analyzes the final annual financial statements approved in 2011 by the Italian companies whose shares belonged to the Italia Star segment of Financial Times and Stock Exchange (FTSE). Given that IAS 1 provides little specific guidance about the presentation of line items and permits many alternative types of format, this paper focuses on information organization in the statement of CI in order to analyze the degree of heterogeneity of financial information. For achieving this goal, this study considers the following issues: (1) presentation of all items of income and expense in an overall statement or in two separate statements; (2) a detailed level of the content in terms of number of items between revenue and net income (NI); (3) classification of expenses either by nature or by function; (4) number and type of intermediate margins; and (5) presentation of items of other comprehensive income (OCI) either before tax or net of tax. The results show some clear evidences. On the one hand, there is a high diversity in accounting practices, which makes it difficult for users to compare financial information across entities, highlighting the need to complete the joint project of the standards setters (IASB and Financial Accounting Standards Board (FASB)) on financial statement presentation. On the other hand, some alternative types of presentation (e.g., the tendency to split the CI statement into two statements rather than using an integrated solution, the prevalence to disaggregate the expenses by nature, etc.) are used by most of the entities of the sample possibly because of the influence of Italian accounting culture.展开更多
GitHub Actions, a popular CI/CD platform, introduces significant security challenges due to its integration with GitHub’s open ecosystem and its use of flexible workflow configurations. This paper presents Sher, a Py...GitHub Actions, a popular CI/CD platform, introduces significant security challenges due to its integration with GitHub’s open ecosystem and its use of flexible workflow configurations. This paper presents Sher, a Python-based tool that enhances the security of GitHub Actions by automating the detection and remediation of security issues in workflows. Self-Hosted Ephemeral Runner, or Sher, acts as a broker between GitHub’s APIs and a customizable, isolated environment, analyzing workflows through a static rules engine and automatically fixing identified issues. By providing a secure, ephemeral runner environment and a dynamic analysis tool, Sher addresses common misconfigurations and vulnerabilities, contributing to the resilience and integrity of DevSecOps practices within software development pipelines.展开更多
文摘The move towards international harmonization of accounting standards has dominated the work program of International Accounting Standards Board (IASB) in the past years. This paper aims to verify the compliance of the comprehensive income (CI) statement format with International Accounting Standard (IAS) 1-presentation of financial statements, which was revised in 2007. The changes introduced by the 2011 revision are also taken into account. For this purpose, this study analyzes the final annual financial statements approved in 2011 by the Italian companies whose shares belonged to the Italia Star segment of Financial Times and Stock Exchange (FTSE). Given that IAS 1 provides little specific guidance about the presentation of line items and permits many alternative types of format, this paper focuses on information organization in the statement of CI in order to analyze the degree of heterogeneity of financial information. For achieving this goal, this study considers the following issues: (1) presentation of all items of income and expense in an overall statement or in two separate statements; (2) a detailed level of the content in terms of number of items between revenue and net income (NI); (3) classification of expenses either by nature or by function; (4) number and type of intermediate margins; and (5) presentation of items of other comprehensive income (OCI) either before tax or net of tax. The results show some clear evidences. On the one hand, there is a high diversity in accounting practices, which makes it difficult for users to compare financial information across entities, highlighting the need to complete the joint project of the standards setters (IASB and Financial Accounting Standards Board (FASB)) on financial statement presentation. On the other hand, some alternative types of presentation (e.g., the tendency to split the CI statement into two statements rather than using an integrated solution, the prevalence to disaggregate the expenses by nature, etc.) are used by most of the entities of the sample possibly because of the influence of Italian accounting culture.
文摘GitHub Actions, a popular CI/CD platform, introduces significant security challenges due to its integration with GitHub’s open ecosystem and its use of flexible workflow configurations. This paper presents Sher, a Python-based tool that enhances the security of GitHub Actions by automating the detection and remediation of security issues in workflows. Self-Hosted Ephemeral Runner, or Sher, acts as a broker between GitHub’s APIs and a customizable, isolated environment, analyzing workflows through a static rules engine and automatically fixing identified issues. By providing a secure, ephemeral runner environment and a dynamic analysis tool, Sher addresses common misconfigurations and vulnerabilities, contributing to the resilience and integrity of DevSecOps practices within software development pipelines.