5 papers
Operationalizing Research Software for Supply Chain Security
Kelechi G. Kalu, Soham Rattan, Taylor R. Schorlemmer +3
Empirical studies of research software are hard to compare because the literature operationalizes ``research software'' inconsistently. Motivated by the research software supply ch…
Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
Taylor R. Schorlemmer, Ethan H. Burmane, Kelechi G. Kalu +2
Software engineers integrate third-party components into their applications. The resulting software supply chain is vulnerable. To reduce the attack surface, we can verify the orig…
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
Chinenye Okafor, Taylor R. Schorlemmer, Santiago Torres-Arias +1
This paper systematizes knowledge about secure software supply chain patterns. It identifies four stages of a software supply chain attack and proposes three security properties cr…
Reusing Deep Learning Models: Challenges and Directions in Software Engineering
James C. Davis, Purvish Jajal, Wenxin Jiang +3
Deep neural networks (DNNs) achieve state-of-the-art performance in many areas, including computer vision, system configuration, and question-answering. However, DNNs are expensive…
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
Taylor R Schorlemmer, Kelechi G Kalu, Luke Chigges +5
Many software applications incorporate open-source third-party packages distributed by public package registries. Guaranteeing authorship along this supply chain is a challenge. Pa…