Dirty-Waters: Detecting Software Supply Chain Smells

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Liu, Raphina, Bobadilla, Sofia, Baudry, Benoit, Monperrus, Martin
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918136215764992
author Liu, Raphina
Bobadilla, Sofia
Baudry, Benoit
Monperrus, Martin
author_facet Liu, Raphina
Bobadilla, Sofia
Baudry, Benoit
Monperrus, Martin
contents Using open-source dependencies is essential in modern software development. However, this practice implies significant trust in third-party code, while there is little support for developers to assess this trust. As a consequence, attacks have been increasingly occurring through third-party dependencies. These are called software supply chain attacks. In this paper, we target the problem of projects that use dependencies while unaware of the potential risks posed by their software supply chain. We define the novel concept of software supply chain smell and present Dirty-Waters, a novel tool for detecting software supply chain smells. We evaluate Dirty-Waters on three JavaScript projects across nine versions and demonstrate the prevalence of all proposed software supply chain smells. Not only are there smells in all projects, but there are many of them, which immediately reveal potential risks and provide clear indicators for developers to act on the security of their supply chain.
format Preprint
id arxiv_https___arxiv_org_abs_2410_16049
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Dirty-Waters: Detecting Software Supply Chain Smells
Liu, Raphina
Bobadilla, Sofia
Baudry, Benoit
Monperrus, Martin
Software Engineering
Cryptography and Security
Using open-source dependencies is essential in modern software development. However, this practice implies significant trust in third-party code, while there is little support for developers to assess this trust. As a consequence, attacks have been increasingly occurring through third-party dependencies. These are called software supply chain attacks. In this paper, we target the problem of projects that use dependencies while unaware of the potential risks posed by their software supply chain. We define the novel concept of software supply chain smell and present Dirty-Waters, a novel tool for detecting software supply chain smells. We evaluate Dirty-Waters on three JavaScript projects across nine versions and demonstrate the prevalence of all proposed software supply chain smells. Not only are there smells in all projects, but there are many of them, which immediately reveal potential risks and provide clear indicators for developers to act on the security of their supply chain.
title Dirty-Waters: Detecting Software Supply Chain Smells
topic Software Engineering
Cryptography and Security
url https://arxiv.org/abs/2410.16049