Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
Fuente:
arXiv
Saved in:
| Main Authors: | Schorlemmer, Taylor R., Burmane, Ethan H., Kalu, Kelechi G., Torres-Arias, Santiago, Davis, James C. |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
by: Schorlemmer, Taylor R, et al.
Published: (2024)
by: Schorlemmer, Taylor R, et al.
Published: (2024)
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024)
by: Kalu, Kelechi G., et al.
Published: (2024)
A Longitudinal Study of Usability in Identity-Based Software Signing
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
DiVerify: Hardening Identity-Based Software Signing with Diverse-Context Scopes
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
A Guide to Stakeholder Analysis for Cybersecurity Researchers
by: Davis, James C, et al.
Published: (2025)
by: Davis, James C, et al.
Published: (2025)
SoK: A Literature and Engineering Review of Regular Expression Denial of Service (ReDoS)
by: Bhuiyan, Masudul Hasan Masud, et al.
Published: (2024)
by: Bhuiyan, Masudul Hasan Masud, et al.
Published: (2024)
Why Software Signing (Still) Matters: Trust Boundaries in the Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
Verifiable Provenance of Software Artifacts with Zero-Knowledge Compilation
by: Ron, Javier, et al.
Published: (2026)
by: Ron, Javier, et al.
Published: (2026)
QUT-DV25: A Dataset for Dynamic Analysis of Next-Gen Software Supply Chain Attacks
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
Finding 709 Defects in 258 Projects: An Experience Report on Applying CodeQL to Open-Source Embedded Software (Experience Paper) -- Extended Report
by: Shen, Mingjie, et al.
Published: (2023)
by: Shen, Mingjie, et al.
Published: (2023)
Rust for Embedded Systems: Current State, Challenges and Open Problems (Extended Report)
by: Sharma, Ayushi, et al.
Published: (2023)
by: Sharma, Ayushi, et al.
Published: (2023)
Provenance of Adaptation in Scientific and Business Workflows -- Literature Review
by: Stage, Ludwig, et al.
Published: (2025)
by: Stage, Ludwig, et al.
Published: (2025)
AdProv: A Method for Provenance of Process Adaptations
by: Stage, Ludwig, et al.
Published: (2025)
by: Stage, Ludwig, et al.
Published: (2025)
GenSIaC: Toward Security-Aware Infrastructure-as-Code Generation with Large Language Models
by: Li, Yikun, et al.
Published: (2025)
by: Li, Yikun, et al.
Published: (2025)
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
by: Sharma, Aman, et al.
Published: (2024)
by: Sharma, Aman, et al.
Published: (2024)
Analysis of Commit Signing on Github
by: Shittu, Abubakar Sadiq, et al.
Published: (2026)
by: Shittu, Abubakar Sadiq, et al.
Published: (2026)
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
by: Ponta, Serena E., et al.
Published: (2018)
by: Ponta, Serena E., et al.
Published: (2018)
The Code the World Depends On: A First Look at Technology Makers' Open Source Software Dependencies
by: Patrick, Cadence, et al.
Published: (2024)
by: Patrick, Cadence, et al.
Published: (2024)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
by: Cusick, James J.
Published: (2025)
by: Cusick, James J.
Published: (2025)
Introducing Systems Thinking as a Framework for Teaching and Assessing Threat Modeling Competency
by: Joshi, Siddhant S., et al.
Published: (2024)
by: Joshi, Siddhant S., et al.
Published: (2024)
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025)
by: Hegewald, Richard, et al.
Published: (2025)
A Study of Malware Prevention in Linux Distributions
by: Vu, Duc-Ly, et al.
Published: (2024)
by: Vu, Duc-Ly, et al.
Published: (2024)
An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland Security
by: Maxam III, William P., et al.
Published: (2024)
by: Maxam III, William P., et al.
Published: (2024)
Towards the Systematic Testing of Regular Expression Engines
by: Çakar, Berk, et al.
Published: (2026)
by: Çakar, Berk, et al.
Published: (2026)
Software Security in Software-Defined Networking: A Systematic Literature Review
by: Diouf, Moustapha Awwalou, et al.
Published: (2025)
by: Diouf, Moustapha Awwalou, et al.
Published: (2025)
Challenges in Developing Secure Software -- Results of an Interview Study in the German Software Industry
by: Mattukat, Alex R., et al.
Published: (2025)
by: Mattukat, Alex R., et al.
Published: (2025)
A LINDDUN-based Privacy Threat Modeling Framework for GenAI
by: Liao, Qianying, et al.
Published: (2026)
by: Liao, Qianying, et al.
Published: (2026)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
by: O'Donoghue, Eric, et al.
Published: (2025)
by: O'Donoghue, Eric, et al.
Published: (2025)
An Introduction to Adaptive Software Security
by: Nia, Mehran Alidoost
Published: (2023)
by: Nia, Mehran Alidoost
Published: (2023)
Establishing Workload Identity for Zero Trust CI/CD: From Secrets to SPIFFE-Based Authentication
by: Avirneni, Surya Teja
Published: (2025)
by: Avirneni, Surya Teja
Published: (2025)
TREBLE: Fast Software Updates by Creating an Equilibrium in an Active Software Ecosystem of Globally Distributed Stakeholders
by: Yim, Keun Soo, et al.
Published: (2024)
by: Yim, Keun Soo, et al.
Published: (2024)
On the Prevalence and Usage of Commit Signing on GitHub: A Longitudinal and Cross-Domain Study
by: Sharma, Anupam, et al.
Published: (2025)
by: Sharma, Anupam, et al.
Published: (2025)
ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale
by: Jiang, Wenxin, et al.
Published: (2025)
by: Jiang, Wenxin, et al.
Published: (2025)
Vulnerability Patching Across Software Products and Software Components: A Case Study of Red Hat's Product Portfolio
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Towards a Benchmark for Dependency Decision-Making
by: Singla, Tanmay, et al.
Published: (2026)
by: Singla, Tanmay, et al.
Published: (2026)
GenDetect: Generalizing Reactive Detection for Resilience Against Imitative DeFi Attack Cascade
by: Cai, Bowen, et al.
Published: (2026)
by: Cai, Bowen, et al.
Published: (2026)
Similar Items
-
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
by: Schorlemmer, Taylor R, et al.
Published: (2024) -
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024) -
A Longitudinal Study of Usability in Identity-Based Software Signing
by: Kalu, Kelechi G., et al.
Published: (2026) -
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
by: Okafor, Chinenye, et al.
Published: (2024) -
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
by: Kalu, Kelechi G., et al.
Published: (2025)