1 citations · 1 across the 2 of their papers we have counts for
5 papers
No Snake Oil: Verifying Python Package Builds
Jens Dietrich, Spencer Sun, Tim W. White +1
Python has become the default language for interacting with AI, with packages being distributed through registries like the Python Package Index (PyPI). This creates a need to anal…
Hidden Dependencies and Component Variants in SBOM-Based Software Composition Analysis
Shawn Rasheed, Max McPhee, Lisa Patterson +2
Software Bills of Material (SBOMs) have emerged as an important technology for vulnerability management amid rising supply-chain attacks. They represent component relationships wit…
On the Variability of Source Code in Maven Package Rebuilds
Jens Dietrich, Behnaz Hassanshahi
Rebuilding packages from open source is a common practice to improve the security of software supply chains, and is now done at an industrial scale. The basic principle is to acqui…
DALEQ -- Explainable Equivalence for Java Bytecode
Jens Dietrich, Behnaz Hassanshahi
The security of software builds has attracted increased attention in recent years in response to incidents like solarwinds and xz. Now, several companies including Oracle and Googl…
Levels of Binary Equivalence for the Comparison of Binaries from Alternative Builds
Jens Dietrich, Tim White, Behnaz Hassanshahi +1
In response to challenges in software supply chain security, several organisations have created infrastructures to independently build commodity open source projects and release th…