4 papers
The Software Supply Chain as a Market for Lemons: A Multivocal Review of Trust Signal Collapse
Ranindya Paramitha, Christian Kästner, Laurie Williams
Practitioners evaluating open-source dependencies rely on cheap trust signals, e.g., stars, download counts, and contributor activity, as substitutes for direct code inspection, as…
The Rising Cost of Trust: Practitioners' Trust Signals, Controls, and Responses in the Software Supply Chain
Ranindya Paramitha, Siri Paidipalli, Laurie Williams +1
The software supply chain is becoming more complex, and AI is reshaping its threat landscape, e.g., raising concerns about the quality of AI-generated dependencies. Seen through th…
From Adoption to Deployment: A Qualitative Study on AI Integration in Software Development Practice
Mahzabin Tamanna, Elizabeth Lin, Sparsha Gowda +2
The increasing adoption of Large Language Models (LLMs) as AI components in modern software systems introduces distinct security risks to the software supply chain. While many cons…
S3C2 Summit 2024-09: Industry Secure Software Supply Chain Summit
Imranur Rahman, Yasemin Acar, Michel Cukier +5
While providing economic and software development value, software supply chains are only as strong as their weakest link. Over the past several years, there has been an exponential…