11 papers
Reproducibility is Not Enough: Artifact Verifiability in Decentralized-Build Package Ecosystems
Oreofe Solarin, Kelechi Kalu, James C. Davis +1
Reproducible and verifiable builds increase trust in distributed software artifacts by enabling independent parties to detect artifacts produced by compromised build or release pip…
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
Kelechi G. Kalu, Sofia Okorafor, Betül Durak +4
Many critical information technology and cyber-physical systems rely on a supply chain of open-source software projects. OSS project maintainers often integrate contributions from…
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
Kelechi G. Kalu, Sofia Okorafor, Tanmay Singla +3
Software signing is the most robust method for ensuring the integrity and authenticity of components in a software supply chain. Legacy key-managed signing tools (e.g., OpenPGP) bu…
A Longitudinal Study of Usability in Identity-Based Software Signing
Kelechi G. Kalu, Hieu Tran, Santiago Torres-Arias +2
Identity-based software signing tools aim to make software artifact provenance verifiable while reducing the operational burden of long-lived key management. However, there is limi…
Operationalizing Research Software for Supply Chain Security
Kelechi G. Kalu, Soham Rattan, Taylor R. Schorlemmer +3
Empirical studies of research software are hard to compare because the literature operationalizes ``research software'' inconsistently. Motivated by the research software supply ch…
How Do Agents Perform Code Optimization? An Empirical Study
Huiyun Peng, Antonio Zhong, Ricardo Andrés Calvo Méndez +2
Performance optimization is a critical yet challenging aspect of software development, often requiring a deep understanding of system behavior, algorithmic tradeoffs, and careful c…