<bibliography>
 <citation type="book" key="ahrendt2016deductive">
  <author>Wolfgang <surname>Ahrendt</surname></author>
  <author>Bernhard <surname>Beckert</surname></author>
  <author>Richard <surname>Bubel</surname></author>
  <author>Reiner <surname>H&#228;hnle</surname></author>
  <author>Peter H <surname>Schmitt</surname></author>
  <author>Mattias <surname>Ulbrich</surname></author>
  <year>2016</year>
  <title>Deductive Software Verification&#8211;The KeY Book: From Theory to Practice</title>
  <publisher>Springer</publisher>
  <doi>10.1007/978-3-319-49812-6</doi>
 </citation>
 <citation type="article" key="BFL+11">
  <author>Mike <surname>Barnett</surname></author>
  <author>Manuel <surname>F&#228;hndrich</surname></author>
  <author>K. Rustan M. <surname>Leino</surname></author>
  <author>Peter <surname>M&#252;ller</surname></author>
  <author>Wolfram <surname>Schulte</surname></author>
  <author>Herman <surname>Venter</surname></author>
  <year>2011</year>
  <title>Specification and Verification: The Spec&#35; Experience</title>
  <journal>Comm. ACM</journal>
  <volume>54</volume>
  <pages>81&#8211;91</pages>
  <doi>10.1145/1953122.1953145</doi>
 </citation>
 <citation type="article" key="baumann2012lessons">
  <author>Christoph <surname>Baumann</surname></author>
  <author>Bernhard <surname>Beckert</surname></author>
  <author>Holger <surname>Blasum</surname></author>
  <author>Thorsten <surname>Bormer</surname></author>
  <year>2012</year>
  <title>Lessons Learned from Microkernel Verification&#8211;Specification is the new Bottleneck</title>
  <journal>SSV</journal>
  <doi>10.4204/EPTCS.102.4</doi>
 </citation>
 <citation type="inproceedings" key="beckert2016deductive">
  <author>Bernhard <surname>Beckert</surname></author>
  <author>Thorsten <surname>Bormer</surname></author>
  <author>Daniel <surname>Grahl</surname></author>
  <year>2016</year>
  <title>Deductive Verification of Legacy Code</title>
  <booktitle>Proc. Int'l Symposium Leveraging Applications of Formal Methods, Verification and Validation (ISoLA)</booktitle>
  <organization>Springer</organization>
  <pages>749&#8211;765</pages>
  <doi>10.1007/978-3-319-47166-2_53</doi>
 </citation>
 <citation type="book" key="BHS07">
  <author>Bernhard <surname>Beckert</surname></author>
  <author>Reiner <surname>H&#228;hnle</surname></author>
  <author>Peter <surname>Schmitt</surname></author>
  <year>2007</year>
  <title>Verification of Object-Oriented Software: The KeY Approach</title>
  <publisher>Springer</publisher>
  <address>Berlin, Heidelberg</address>
 </citation>
 <citation type="inproceedings" key="beckert2017proving">
  <author>Bernhard <surname>Beckert</surname></author>
  <author>Jonas <surname>Schiffl</surname></author>
  <author>Peter H <surname>Schmitt</surname></author>
  <author>Mattias <surname>Ulbrich</surname></author>
  <year>2017</year>
  <title>Proving JDK’s Dual Pivot Quicksort Correct</title>
  <booktitle>Working Conference on Verified Software: Theories, Tools, and Experiments</booktitle>
  <organization>Springer</organization>
  <pages>35&#8211;48</pages>
  <doi>10.1007/978-3-319-47846-3_5</doi>
 </citation>
 <citation type="book" key="BC04">
  <author>Yves <surname>Bertot</surname></author>
  <author>Pierre <surname>Cast&#233;ran</surname></author>
  <year>2004</year>
  <title>Interactive Theorem Proving and Program Development - Coq'Art: The Calculus of Inductive Constructions</title>
  <publisher>Springer</publisher>
  <address>Berlin, Heidelberg</address>
  <doi>10.1007/978-3-662-07964-5</doi>
 </citation>
 <citation type="inproceedings" key="bhargavan2017everest">
  <author>Karthikeyan <surname>Bhargavan</surname></author>
  <author>Barry <surname>Bond</surname></author>
  <author>Antoine <surname>Delignat-Lavaud</surname></author>
  <author>C&#233;dric <surname>Fournet</surname></author>
  <author>Chris <surname>Hawblitzel</surname></author>
  <author>Catalin <surname>Hritcu</surname></author>
  <author>Samin <surname>Ishtiaq</surname></author>
  <author>Markulf <surname>Kohlweiss</surname></author>
  <author>Rustan <surname>Leino</surname></author>
  <author>Jay <surname>Lorch</surname></author>
  <year>2017</year>
  <title>Everest: Towards a Verified, Drop-in Replacement of HTTPS</title>
  <booktitle>Leibniz International Proceedings in Informatics (LIPIcs)</booktitle>
  <volume>71</volume>
  <organization>Schloss Dagstuhl-Leibniz-Zentrum fuer Informatik</organization>
  <doi>10.4230/LIPIcs.SNAPL.2017.1</doi>
 </citation>
 <citation type="article" key="BS:SEJ93">
  <author>Jonathan <surname>Bowen</surname></author>
  <author>Victoria <surname>Stavridou</surname></author>
  <year>1993</year>
  <title>Safety-critical Systems, Formal Methods and Standards</title>
  <journal>Software Engineering Journal</journal>
  <volume>8</volume>
  <number>4</number>
  <pages>189&#8211;209</pages>
  <doi>10.1049/sej.1993.0025</doi>
 </citation>
 <citation type="article" key="BM13">
  <author>Hagen <surname>Buchwald</surname></author>
  <author>Florian <surname>Meyerer</surname></author>
  <year>2013</year>
  <title>C4J: Contracts, Java und Eclipse</title>
  <journal>Eclipse Magazin</journal>
  <volume>13</volume>
  <number>3</number>
  <pages>64&#8211;69</pages>
 </citation>
 <citation type="article" key="BCC+05">
  <author>Lilian <surname>Burdy</surname></author>
  <author>Yoonsik <surname>Cheon</surname></author>
  <author>David R. <surname>Cok</surname></author>
  <author>Michael D. <surname>Ernst</surname></author>
  <author>Joseph <surname>Kiniry</surname></author>
  <author>Gary T. <surname>Leavens</surname></author>
  <author>K. Rustan M. <surname>Leino</surname></author>
  <author>Erik <surname>Poll</surname></author>
  <year>2005</year>
  <title>An Overview of JML Tools and Applications</title>
  <journal>Int'l J. Software Tools for Technology Transfer (STTT)</journal>
  <volume>7</volume>
  <number>3</number>
  <pages>212&#8211;232</pages>
  <doi>10.1007/s10009-004-0167-4</doi>
 </citation>
 <citation type="book" key="CGP99">
  <author>Edmund M. <surname>Clarke</surname></author>
  <author>Orna <surname>Grumberg</surname></author>
  <author>Doron A. <surname>Peled</surname></author>
  <year>1999</year>
  <title>Model Checking</title>
  <publisher>MIT Press</publisher>
  <address>Cambridge, Massachussetts</address>
 </citation>
 <citation type="article" key="CW:CSUR96">
  <author>Edmund M <surname>Clarke</surname></author>
  <author>Jeannette M <surname>Wing</surname></author>
  <year>1996</year>
  <title>Formal methods: State of the Art and Future Directions</title>
  <journal>ACM Computing Surveys (CSUR)</journal>
  <volume>28</volume>
  <number>4</number>
  <pages>626&#8211;643</pages>
  <doi>10.1145/242223.242257</doi>
 </citation>
 <citation type="inproceedings" key="cohen2009vcc">
  <author>Ernie <surname>Cohen</surname></author>
  <author>Markus <surname>Dahlweid</surname></author>
  <author>Mark <surname>Hillebrand</surname></author>
  <author>Dirk <surname>Leinenbach</surname></author>
  <author>Micha&#322;<surname>Moskal</surname></author>
  <author>Thomas <surname>Santen</surname></author>
  <author>Wolfram <surname>Schulte</surname></author>
  <author>Stephan <surname>Tobies</surname></author>
  <year>2009</year>
  <title>VCC: A Practical System for Verifying Concurrent C</title>
  <booktitle>Proc. Int'l. Conf. Theorem Proving in Higher Order Logics (TPHOLs)</booktitle>
  <organization>Springer</organization>
  <pages>23&#8211;42</pages>
  <doi>10.1007/978-3-540-74591-4_15</doi>
 </citation>
 <citation type="inproceedings" key="C:NFM11">
  <author>David R. <surname>Cok</surname></author>
  <year>2011</year>
  <title>OpenJML: JML for Java 7 by Extending OpenJDK</title>
  <booktitle>Proc. Int'l Conf. NASA Formal Methods (NFM)</booktitle>
  <publisher>Springer</publisher>
  <address>Berlin, Heidelberg</address>
  <pages>472&#8211;479</pages>
  <doi>10.1007/978-3-642-18070-5_13</doi>
 </citation>
 <citation type="inproceedings" key="cok2004esc">
  <author>David R <surname>Cok</surname></author>
  <author>Joseph <surname>Kiniry</surname></author>
  <year>2004</year>
  <title>ESC/Java2: Uniting ESC/Java and JML</title>
  <booktitle>Proc. Int'l Conf. Construction and Analysis of Safe, Secure, and Interoperable Smart Devices (CASSIS)</booktitle>
  <volume>3362</volume>
  <organization>Springer</organization>
  <pages>108&#8211;128</pages>
  <doi>10.1007/978-3-540-30569-9_6</doi>
 </citation>
 <citation type="inproceedings" key="cuoq2012frama">
  <author>Pascal <surname>Cuoq</surname></author>
  <author>Florent <surname>Kirchner</surname></author>
  <author>Nikolai <surname>Kosmatov</surname></author>
  <author>Virgile <surname>Prevosto</surname></author>
  <author>Julien <surname>Signoles</surname></author>
  <author>Boris <surname>Yakobowski</surname></author>
  <year>2012</year>
  <title>Frama-C</title>
  <booktitle>Proc. Int'l. Conf. Software Engineering and Formal Methods (SEFM)</booktitle>
  <organization>Springer</organization>
  <pages>233&#8211;247</pages>
  <doi>10.1007/978-3-642-33826-7_16</doi>
 </citation>
 <citation type="inproceedings" key="de2015openjdk">
  <author>Stijn <surname>De Gouw</surname></author>
  <author>Jurriaan <surname>Rot</surname></author>
  <author>Frank S <surname>de Boer</surname></author>
  <author>Richard <surname>Bubel</surname></author>
  <author>Reiner <surname>H&#228;hnle</surname></author>
  <year>2015</year>
  <title>OpenJDK’s Java.utils.Collection.sort() is Broken: The Good, the Bad and the Worst Case</title>
  <booktitle>Proc. Int'l Conf. Computer Aided Verification (CAV)</booktitle>
  <organization>Springer</organization>
  <pages>273&#8211;289</pages>
  <doi>10.1007/978-3-319-21690-4_16</doi>
 </citation>
 <citation type="article" key="ernst2015kiv">
  <author>Gidon <surname>Ernst</surname></author>
  <author>J&#246;rg <surname>Pf&#228;hler</surname></author>
  <author>Gerhard <surname>Schellhorn</surname></author>
  <author>Dominik <surname>Haneberg</surname></author>
  <author>Wolfgang <surname>Reif</surname></author>
  <year>2015</year>
  <title>KIV: Overview and VerifyThis Competition</title>
  <journal>Int'l J. Software Tools for Technology Transfer (STTT)</journal>
  <volume>17</volume>
  <number>6</number>
  <pages>677&#8211;694</pages>
  <doi>10.1007/s10009-014-0308-3</doi>
 </citation>
 <citation type="inproceedings" key="estler2014contracts">
  <author>H-Christian <surname>Estler</surname></author>
  <author>Carlo A <surname>Furia</surname></author>
  <author>Martin <surname>Nordio</surname></author>
  <author>Marco <surname>Piccioni</surname></author>
  <author>Bertrand <surname>Meyer</surname></author>
  <year>2014</year>
  <title>Contracts in Practice</title>
  <booktitle>International Symposium on Formal Methods</booktitle>
  <organization>Springer</organization>
  <pages>230&#8211;246</pages>
  <doi>10.1007/978-3-319-06410-9_17</doi>
 </citation>
 <citation type="inproceedings" key="FM07">
  <author>Jean-Christophe <surname>Filli&#226;tre</surname></author>
  <author>Claude <surname>March&#233;</surname></author>
  <year>2007</year>
  <title>The Why/Krakatoa/Caduceus Platform for Deductive Program Verification</title>
  <booktitle>Computer Aided Verification</booktitle>
  <publisher>Springer</publisher>
  <address>Berlin, Heidelberg</address>
  <pages>173&#8211;177</pages>
  <doi>10.1007/978-3-540-73368-3_21</doi>
 </citation>
 <citation type="article" key="F67">
  <author>Robert W. <surname>Floyd</surname></author>
  <year>1967</year>
  <title>Assigning Meanings to Programs</title>
  <journal>Mathematical Aspects of Computer Science</journal>
  <volume>19</volume>
  <pages>19&#8211;32</pages>
  <doi>10.1090/psapm/019/0235771</doi>
 </citation>
 <citation type="article" key="furia2017autoproof">
  <author>Carlo A <surname>Furia</surname></author>
  <author>Martin <surname>Nordio</surname></author>
  <author>Nadia <surname>Polikarpova</surname></author>
  <author>Julian <surname>Tschannen</surname></author>
  <year>2017</year>
  <title>AutoProof: Auto-Active Functional Verification of Object-Oriented Programs</title>
  <journal>Int'l J. Software Tools for Technology Transfer (STTT)</journal>
  <volume>19</volume>
  <number>6</number>
  <pages>697&#8211;716</pages>
  <doi>10.1007/s10009-016-0419-0</doi>
 </citation>
 <citation type="article" key="HLL+12">
  <author>John <surname>Hatcliff</surname></author>
  <author>Gary T. <surname>Leavens</surname></author>
  <author>K. Rustan M. <surname>Leino</surname></author>
  <author>Peter <surname>M&#252;ller</surname></author>
  <author>Matthew <surname>Parkinson</surname></author>
  <year>2012</year>
  <title>Behavioral Interface Specification Languages</title>
  <journal>ACM Computing Surveys</journal>
  <volume>44</volume>
  <number>3</number>
  <pages>16:1&#8211;16:58</pages>
  <doi>10.1145/2187671.2187678</doi>
 </citation>
 <citation type="inproceedings" key="hawblitzel2015ironfleet">
  <author>Chris <surname>Hawblitzel</surname></author>
  <author>Jon <surname>Howell</surname></author>
  <author>Manos <surname>Kapritsos</surname></author>
  <author>Jacob R <surname>Lorch</surname></author>
  <author>Bryan <surname>Parno</surname></author>
  <author>Michael L <surname>Roberts</surname></author>
  <author>Srinath <surname>Setty</surname></author>
  <author>Brian <surname>Zill</surname></author>
  <year>2015</year>
  <title>IronFleet: Proving Practical Distributed Systems Correct</title>
  <booktitle>Proc. Symposium on Operating Systems Principles (SOSP)</booktitle>
  <organization>ACM</organization>
  <pages>1&#8211;17</pages>
  <doi>10.1145/2815400.2815428</doi>
 </citation>
 <citation type="inproceedings" key="hawblitzel2014ironclad">
  <author>Chris <surname>Hawblitzel</surname></author>
  <author>Jon <surname>Howell</surname></author>
  <author>Jacob R <surname>Lorch</surname></author>
  <author>Arjun <surname>Narayan</surname></author>
  <author>Bryan <surname>Parno</surname></author>
  <author>Danfeng <surname>Zhang</surname></author>
  <author>Brian <surname>Zill</surname></author>
  <year>2014</year>
  <title>Ironclad Apps: End-to-End Security via Automated Full-System Verification</title>
  <booktitle>Proc. USENIX Symposium Operating Systems Design and Implementation (OSDI)</booktitle>
  <volume>14</volume>
  <pages>165&#8211;181</pages>
 </citation>
 <citation type="inproceedings" key="H:JMLC03">
  <author>C. A. R. <surname>Hoare</surname></author>
  <year>2003</year>
  <title>The Verifying Compiler: A Grand Challenge for Computing Research</title>
  <booktitle>Proc. Joint Modular Languages Conference (JMLC)</booktitle>
  <publisher>Springer</publisher>
  <address>Berlin, Heidelberg</address>
  <pages>25&#8211;35</pages>
  <doi>10.1007/978-3-540-45213-3_4</doi>
 </citation>
 <citation type="inproceedings" key="kaiser2007evolution">
  <author>Robert <surname>Kaiser</surname></author>
  <author>Stephan <surname>Wagner</surname></author>
  <year>2007</year>
  <title>Evolution of the PikeOS Microkernel</title>
  <booktitle>Proc. Int'l. Workshop on Microkernels for Embedded Systems (MIKES)</booktitle>
  <pages>50</pages>
 </citation>
 <citation type="inproceedings" key="knight1997formal">
  <author>John C <surname>Knight</surname></author>
  <author>Colleen L <surname>DeJong</surname></author>
  <author>Matthew S <surname>Gibble</surname></author>
  <author>Luis G <surname>Nakano</surname></author>
  <year>1997</year>
  <title>Why are Formal Methods not used more Widely?</title>
  <booktitle>Fourth NASA Langley Formal Methods Workshop</booktitle>
  <organization>Citeseer</organization>
  <doi>10.1.1.2.3395</doi>
 </citation>
 <citation type="inproceedings" key="KTPS:ITP18">
  <author>Alexander <surname>Kn&#252;ppel</surname></author>
  <author>Thomas <surname>Th&#252;m</surname></author>
  <author>Carsten I. <surname>Pardylla</surname></author>
  <author>Ina <surname>Schaefer</surname></author>
  <year>2018</year>
  <title>Understanding Parameters of Deductive Verification: An Empirical Investigation of KeY</title>
  <booktitle>Proc. Int'l. Conf. Interactive Theorem Proving (ITP)</booktitle>
  <organization>Springer</organization>
  <doi>10.1007/978-3-642-29044-2</doi>
 </citation>
 <citation type="inproceedings" key="kuesters2011verifiability">
  <author>Ralf <surname>K&#252;esters</surname></author>
  <author>Tomasz <surname>Truderung</surname></author>
  <author>Andreas <surname>Vogt</surname></author>
  <year>2011</year>
  <title>Verifiability, Privacy, and Coercion-resistance: New Insights From a Case Study</title>
  <booktitle>Proc. Symposium on Security and Privacy (SP)</booktitle>
  <organization>IEEE</organization>
  <pages>538&#8211;553</pages>
  <doi>10.1109/SP.2011.21</doi>
 </citation>
 <citation type="misc" key="LC06">
  <author>Gary T. <surname>Leavens</surname></author>
  <author>Yoonsik <surname>Cheon</surname></author>
  <year>2006</year>
  <title>Design by Contract with JML</title>
  <url>http://www.jmlspecs.org/jmldbc.pdf</url>
 </citation>
 <citation type="inproceedings" key="LM:ICSE07">
  <author>Gary T. <surname>Leavens</surname></author>
  <author>Peter <surname>M&#252;ller</surname></author>
  <year>2007</year>
  <title>Information Hiding and Visibility in Interface Specifications</title>
  <booktitle>Proc. Int'l Conf. Software Engineering (ICSE)</booktitle>
  <publisher>IEEE</publisher>
  <address>Washington, DC, USA</address>
  <pages>385&#8211;395</pages>
  <doi>10.1109/ICSE.2007.44</doi>
 </citation>
 <citation type="article" key="leavens2006behavioral">
  <author>Gary T <surname>Leavens</surname></author>
  <author>David A <surname>Naumann</surname></author>
  <year>2006</year>
  <title>Behavioral Subtyping is Equivalent to Modular Reasoning for Object-oriented Programs</title>
 </citation>
 <citation type="book" key="LG86">
  <author>Barbara <surname>Liskov</surname></author>
  <author>John <surname>Guttag</surname></author>
  <year>1986</year>
  <title>Abstraction and Specification in Program Development</title>
  <publisher>MIT Press</publisher>
  <address>Cambridge, MA, USA</address>
 </citation>
 <citation type="article" key="LW:TOPLAS94">
  <author>Barbara H. <surname>Liskov</surname></author>
  <author>Jeannette M. <surname>Wing</surname></author>
  <year>1994</year>
  <title>A Behavioral Notion of Subtyping</title>
  <journal>ACM Trans. Programming Languages and Systems (TOPLAS)</journal>
  <volume>16</volume>
  <number>6</number>
  <pages>1811&#8211;1841</pages>
  <doi>10.1145/197320.197383</doi>
 </citation>
 <citation type="article" key="marche2012jessie">
  <author>Claude <surname>March&#233;</surname></author>
  <author>Yannick <surname>Moy</surname></author>
  <year>2012</year>
  <title>The Jessie Plugin for Deductive Verification in Frama-C</title>
  <journal>INRIA Saclay &#206;le-de-France and LRI, CNRS UMR</journal>
  <doi>10.1.1.229.3233</doi>
 </citation>
 <citation type="book" key="M88">
  <author>Bertrand <surname>Meyer</surname></author>
  <year>1988</year>
  <title>Object-Oriented Software Construction</title>
  <edition>1st</edition>
  <publisher>Prentice-Hall, Inc.</publisher>
  <address>Upper Saddle River, NJ, USA</address>
 </citation>
 <citation type="article" key="M92">
  <author>Bertrand <surname>Meyer</surname></author>
  <year>1992</year>
  <title>Applying Design by Contract</title>
  <journal>IEEE Computer</journal>
  <volume>25</volume>
  <number>10</number>
  <pages>40&#8211;51</pages>
  <doi>10.1109/2.161279</doi>
 </citation>
 <citation type="book" key="NWP02">
  <author>Tobias <surname>Nipkow</surname></author>
  <author>Markus <surname>Wenzel</surname></author>
  <author>Lawrence C. <surname>Paulson</surname></author>
  <year>2002</year>
  <title>Isabelle/HOL: A Proof Assistant for Higher-Order Logic</title>
  <publisher>Springer</publisher>
  <address>Berlin, Heidelberg</address>
  <doi>10.1007/3-540-45949-9</doi>
 </citation>
 <citation type="inproceedings" key="ORR+:CAV96">
  <author>Sam <surname>Owre</surname></author>
  <author>Sreeranga P. <surname>Rajan</surname></author>
  <author>John M. <surname>Rushby</surname></author>
  <author>Natarajan <surname>Shankar</surname></author>
  <author>Mandayam K. <surname>Srivas</surname></author>
  <year>1996</year>
  <title>PVS: Combining Specification, Proof Checking, and Model Checking</title>
  <booktitle>Proc. Int'l Conf. Computer Aided Verification (CAV)</booktitle>
  <publisher>Springer</publisher>
  <address>Berlin, Heidelberg</address>
  <pages>411&#8211;414</pages>
  <doi>10.1007/3-540-61474-5_91</doi>
 </citation>
 <citation type="article" key="pariente2010formal">
  <author>Dillon <surname>Pariente</surname></author>
  <author>Emmanuel <surname>Ledinot</surname></author>
  <year>2010</year>
  <title>Formal Verification of Industrial C Code using Frama-C: A Case Study</title>
  <journal>Proc. Int'l Conf. Formal Verification of Object-Oriented Software (FoVeOOS)</journal>
  <pages>205</pages>
 </citation>
 <citation type="inproceedings" key="polikarpova2015fully">
  <author>Nadia <surname>Polikarpova</surname></author>
  <author>Julian <surname>Tschannen</surname></author>
  <author>Carlo A <surname>Furia</surname></author>
  <year>2015</year>
  <title>A Fully Verified Container Library</title>
  <booktitle>Proc. Int'l Symposium Formal Methods (FM)</booktitle>
  <organization>Springer</organization>
  <pages>414&#8211;434</pages>
  <doi>10.1007/978-3-319-19249-9_26</doi>
 </citation>
 <citation type="article" key="RRDH06">
  <author><surname>Robby</surname></author>
  <author>Edwin <surname>Rodr&#237;guez</surname></author>
  <author>Matthew B. <surname>Dwyer</surname></author>
  <author>John <surname>Hatcliff</surname></author>
  <year>2006</year>
  <title>Checking JML Specifications Using an Extensible Software Model Checking Framework</title>
  <journal>Int'l J. Software Tools for Technology Transfer (STTT)</journal>
  <volume>8</volume>
  <number>3</number>
  <pages>280&#8211;299</pages>
  <doi>10.1007/s10009-005-0218-5</doi>
 </citation>
 <citation type="book" key="rogers1967theory">
  <author>Hartley <surname>Rogers</surname></author>
  <author>H <surname>Rogers</surname></author>
  <year>1967</year>
  <title>Theory of Recursive Functions and Effective Computability</title>
  <volume>5</volume>
  <publisher>McGraw-Hill New York</publisher>
 </citation>
 <citation type="incollection" key="R97">
  <author>John <surname>Rushby</surname></author>
  <year>1997</year>
  <title>Formal Methods and their role in the Certification of Critical Systems</title>
  <booktitle>Safety and Reliability of Software Based Systems</booktitle>
  <publisher>Springer</publisher>
  <pages>1&#8211;42</pages>
  <doi>10.1007/978-1-4471-0921-1_1</doi>
 </citation>
 <citation type="book" key="SD88">
  <author>Donald <surname>Sannella</surname></author>
  <year>1988</year>
  <title>A Survey of Formal Software Development Methods</title>
  <publisher>University of Edinburgh, Department of Computer Science, Laboratory for Foundations of Computer Science</publisher>
 </citation>
 <citation type="book" key="Sch01">
  <author>Johann <surname>Schumann</surname></author>
  <year>2001</year>
  <title>Automated Theorem Proving in Software Engineering</title>
  <publisher>Springer</publisher>
  <address>Berlin, Heidelberg</address>
  <doi>10.1007/978-3-662-22646-9</doi>
 </citation>
 <citation type="book" key="schumann2001automated">
  <author>Johann M <surname>Schumann</surname></author>
  <year>2001</year>
  <title>Automated Theorem Proving in Software Engineering</title>
  <publisher>Springer Science &#38; Business Media</publisher>
  <doi>10.1007/978-3-662-22646-9</doi>
 </citation>
 <citation type="inproceedings" key="TSKA:VAST11">
  <author>Thomas <surname>Th&#252;m</surname></author>
  <author>Ina <surname>Schaefer</surname></author>
  <author>Martin <surname>Kuhlemann</surname></author>
  <author>Sven <surname>Apel</surname></author>
  <year>2011</year>
  <title>Proof Composition for Deductive Verification of Software Product Lines</title>
  <booktitle>Proc. Int'l Workshop Variability-intensive Systems Testing, Validation and Verification (VAST)</booktitle>
  <publisher>IEEE</publisher>
  <address>Washington, DC, USA</address>
  <pages>270&#8211;277</pages>
  <doi>10.1109/ICSTW.2011.48</doi>
 </citation>
 <citation type="inproceedings" key="wampler2006contract4j">
  <author>Dean <surname>Wampler</surname></author>
  <year>2006</year>
  <title>Contract4J for Design by Contract in Java: Design Pattern-like Protocols and Aspect Interfaces</title>
  <booktitle>Fifth AOSD Workshop on ACP4IS</booktitle>
  <pages>27&#8211;30</pages>
  <doi>10.1.1.115.2281</doi>
 </citation>
 <citation type="misc" key="why">
  <author><surname>Why Development Team</surname></author>
  <title>Why: A Software Verification Platform</title>
  <howpublished>Website</howpublished>
  <note>Available online at http://why.lri.fr/</note>
 </citation>
</bibliography>
