9 papers
The Software Supply Chain as a Market for Lemons: A Multivocal Review of Trust Signal Collapse
Ranindya Paramitha, Christian Kästner, Laurie Williams
Practitioners evaluating open-source dependencies rely on cheap trust signals, e.g., stars, download counts, and contributor activity, as substitutes for direct code inspection, as…
The Rising Cost of Trust: Practitioners' Trust Signals, Controls, and Responses in the Software Supply Chain
Ranindya Paramitha, Siri Paidipalli, Laurie Williams +1
The software supply chain is becoming more complex, and AI is reshaping its threat landscape, e.g., raising concerns about the quality of AI-generated dependencies. Seen through th…
S3C2 Summit 2025-09: Industry Secure Supply Chain Summit
Md Atiqur Rahman, Yasemin Acar, Michel Cucker +5
Today's digital ecosystem relies heavily on software supply chains, which enable developers to reuse code and ship software at scale. However, a single vulnerable component can jeo…
S3C2 Summit 2025-07: Government Secure Supply Chain Summit
Sivana Hamer, Pat Morrison, William Enck +6
Software supply chains, while providing immense economic and software development value, are only as strong as their weakest link. Over the past several years, there has been an ex…
S3C2 SICP Summit 2025-06: Vulnerability Response Summit
Anna Lena Rotthaler, Simon Oberthür, Juraj Somorovsky +9
Recent years have shown increased cyber attacks targeting less secure elements in the software supply chain and causing significant damage to businesses and organizations. The US a…
S3C2 Summit 2025-03: Industry Secure Supply Chain Summit
Elizabeth Lin, Jonah Ghebremichael, William Enck +5
Software supply chains, while providing immense economic and software development value, are only as strong as their weakest link. Over the past several years, there has been an ex…