8 papers
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
Kelechi G. Kalu, Sofia Okorafor, Betül Durak +4
Many critical information technology and cyber-physical systems rely on a supply chain of open-source software projects. OSS project maintainers often integrate contributions from…
Measuring Delivery Consistency in Practice: A DORA Extension from a Multi-Platform Release Setting
Luiz Parente, James C. Davis
The DevOps Research and Assessment (DORA) framework is the most widely adopted measurement system for performance measurement across engineering teams. However, every DORA metric i…
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
Kelechi G. Kalu, Sofia Okorafor, Tanmay Singla +3
Software signing is the most robust method for ensuring the integrity and authenticity of components in a software supply chain. Legacy key-managed signing tools (e.g., OpenPGP) bu…
A Longitudinal Study of Usability in Identity-Based Software Signing
Kelechi G. Kalu, Hieu Tran, Santiago Torres-Arias +2
Identity-based software signing tools aim to make software artifact provenance verifiable while reducing the operational burden of long-lived key management. However, there is limi…
Operationalizing Research Software for Supply Chain Security
Kelechi G. Kalu, Soham Rattan, Taylor R. Schorlemmer +3
Empirical studies of research software are hard to compare because the literature operationalizes ``research software'' inconsistently. Motivated by the research software supply ch…
DiVerify: Hardening Identity-Based Software Signing with Diverse-Context Scopes
Chinenye Okafor, James C. Davis, Santiago Torres-Arias
Identity-based code signing enables software developers to digitally sign their code using cryptographic keys. This key is then linked to an identity (e.g., through an identity pro…