2023 IEEE Symposium on Security and Privacy (SP) 2023
DOI: 10.1109/sp46215.2023.10179378
|View full text |Cite
|
Sign up to set email alerts
|

"Always Contribute Back": A Qualitative Study on Security Challenges of the Open Source Supply Chain

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
3
1
1

Relationship

0
5

Authors

Journals

citations
Cited by 5 publications
(1 citation statement)
references
References 57 publications
0
1
0
Order By: Relevance
“…The first analysis findings indicate that unsafe dependency updates are prevalent across all tiers within the ecosystem. Thus, our aim is to establish a close connection between unsafe practises and their alternatives, based on existing research that has explored the exploitability of code [26] and how practitioners are using OSS libraries in their code [33].…”
Section: Placing Safeguardsmentioning
confidence: 99%
“…The first analysis findings indicate that unsafe dependency updates are prevalent across all tiers within the ecosystem. Thus, our aim is to establish a close connection between unsafe practises and their alternatives, based on existing research that has explored the exploitability of code [26] and how practitioners are using OSS libraries in their code [33].…”
Section: Placing Safeguardsmentioning
confidence: 99%