4 papers
Unpacking Security Scanners for GitHub Actions Workflows
Madjda Fares, Yogya Gamage, Benoit Baudry
GitHub Actions is a widely used platform to automate the build and deployment of software projects through configurable workflows. As the platform's popularity grows, it also becom…
Maven-Lockfile: High Integrity Rebuild of Past Java Releases
Larissa Schmid, Elias Lundell, Yogya Gamage +2
Modern software projects depend on many third-party libraries, complicating reproducible and secure builds. Several package managers address this with the generation of a lockfile…
The Design Space of Lockfiles Across Package Managers
Yogya Gamage, Deepika Tiwari, Martin Monperrus +1
Software developers reuse third-party packages that are hosted in package registries. At build time, a package manager resolves and fetches the direct and indirect dependencies of…
Software Bills of Materials in Maven Central
Yogya Gamage, Nadia Gonzalez Fernandez, Martin Monperrus +1
Software Bills of Materials (SBOMs) are essential to ensure the transparency and integrity of the software supply chain. There is a growing body of work that investigates the accur…