OpenSSF Scorecard: On the Path Toward Ecosystem-wide Automated Security Metrics
arXiv:2208.03412 · doi:10.1109/MSEC.2023.3279773
Abstract
The OpenSSF Scorecard project is an automated tool to monitor the security health of open-source software. This study evaluates the applicability of the Scorecard tool and compares the security practices and gaps in the npm and PyPI ecosystems.
10 pages, 2 figures and 2 tables
References in corpus (1)
Cited by in corpus (4)
- Malicious Package Detection using Metadata Information
- Pinning Is Futile: You Need More Than Local Dependency Versioning to Defend against Supply Chain Attacks
- Trusting code in the wild: Exploring contributor reputation measures to review dependencies in the Rust ecosystem
- Six Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware