3 papers
cs.CR2026
Original Sin of npm: A Study on Vulnerability Propagation in JavaScript Dependency Networks
Michael Robinson, Sajal Halder, Muhammad Ejaz Ahmed +3
Understanding vulnerability propagation is essential for assessing how vulnerabilities spread across components of a software package. This supports more accurate impact analysis a…
cs.SE2025
The "4W+1H" of Software Supply Chain Security Checklist for Critical Infrastructure
Liming Dong, Sung Une Lee, Zhenchang Xing +2
The increasing frequency and sophistication of software supply chain attacks pose severe risks to critical infrastructure sectors, threatening national security, economic stability…
cs.SE2025
Software Security Mapping Framework: Operationalization of Security Requirements
Sung Une Lee, Liming Dong, Zhenchang Xing +2
The escalating complexity of modern software development environments has heightened concerns around supply chain security. However, existing frameworks often fall short in transla…