Dirty-Waters: Detecting Software Supply Chain Smells
Fuente:
arXiv
Saved in:
| Main Authors: | Liu, Raphina, Bobadilla, Sofia, Baudry, Benoit, Monperrus, Martin |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
by: Schmid, Larissa, et al.
Published: (2026)
by: Schmid, Larissa, et al.
Published: (2026)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
by: Reyes, Frank, et al.
Published: (2024)
by: Reyes, Frank, et al.
Published: (2024)
On-Chain Analysis of Smart Contract Dependency Risks on Ethereum
by: Jin, Monica, et al.
Published: (2025)
by: Jin, Monica, et al.
Published: (2025)
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025)
by: Monperrus, Martin
Published: (2025)
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
by: Sharma, Aman, et al.
Published: (2024)
by: Sharma, Aman, et al.
Published: (2024)
GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
by: Cesarano, Carmine, et al.
Published: (2025)
by: Cesarano, Carmine, et al.
Published: (2025)
Maven-Lockfile: High Integrity Rebuild of Past Java Releases
by: Schmid, Larissa, et al.
Published: (2025)
by: Schmid, Larissa, et al.
Published: (2025)
Verifiable Provenance of Software Artifacts with Zero-Knowledge Compilation
by: Ron, Javier, et al.
Published: (2026)
by: Ron, Javier, et al.
Published: (2026)
PoCo: Agentic Proof-of-Concept Exploit Generation for Smart Contracts
by: Andersson, Vivi, et al.
Published: (2025)
by: Andersson, Vivi, et al.
Published: (2025)
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025)
by: Hegewald, Richard, et al.
Published: (2025)
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
Unpacking Security Scanners for GitHub Actions Workflows
by: Fares, Madjda, et al.
Published: (2026)
by: Fares, Madjda, et al.
Published: (2026)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
by: Ruan, Bonan, et al.
Published: (2025)
by: Ruan, Bonan, et al.
Published: (2025)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024)
by: Kalu, Kelechi G., et al.
Published: (2024)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
by: O'Donoghue, Eric, et al.
Published: (2025)
by: O'Donoghue, Eric, et al.
Published: (2025)
An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management
by: Tran, Nguyen Khoi, et al.
Published: (2023)
by: Tran, Nguyen Khoi, et al.
Published: (2023)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack
by: Przymus, Piotr, et al.
Published: (2025)
by: Przymus, Piotr, et al.
Published: (2025)
Proving and Rewarding Client Diversity to Strengthen Resilience of Blockchain Networks
by: Ron, Javier, et al.
Published: (2024)
by: Ron, Javier, et al.
Published: (2024)
OmniBOR: A System for Automatic, Verifiable Artifact Resolution across Software Supply Chains
by: Seshadri, Bharathi, et al.
Published: (2024)
by: Seshadri, Bharathi, et al.
Published: (2024)
Patch2QL: Discover Cognate Defects in Open Source Software Supply Chain With Auto-generated Static Analysis Rules
by: Wang, Fuwei, et al.
Published: (2024)
by: Wang, Fuwei, et al.
Published: (2024)
QUT-DV25: A Dataset for Dynamic Analysis of Next-Gen Software Supply Chain Attacks
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
Classport: Designing Runtime Dependency Introspection for Java
by: Cofano, Serena, et al.
Published: (2025)
by: Cofano, Serena, et al.
Published: (2025)
Towards Predicting Multi-Vulnerability Attack Chains in Software Supply Chains from Software Bill of Materials Graphs
by: Baird, Laura, et al.
Published: (2026)
by: Baird, Laura, et al.
Published: (2026)
Exploiting LLM Agent Supply Chains via Payload-less Skills
by: Liu, Xinyu, et al.
Published: (2026)
by: Liu, Xinyu, et al.
Published: (2026)
FLAMES: Fine-tuning LLMs to Synthesize Invariants for Smart Contract Security
by: Eshghie, Mojtaba, et al.
Published: (2025)
by: Eshghie, Mojtaba, et al.
Published: (2025)
Understanding the Supply Chain and Risks of Large Language Model Applications
by: Ma, Yujie, et al.
Published: (2025)
by: Ma, Yujie, et al.
Published: (2025)
zkSBOM: Privacy-Preserving SBOM Sharing with Zero-Knowledge Sets
by: Sorger, Tom, et al.
Published: (2026)
by: Sorger, Tom, et al.
Published: (2026)
SBOMproof: Beyond Alleged SBOM Compliance for Supply Chain Security of Container Images
by: Bufalino, Jacopo, et al.
Published: (2025)
by: Bufalino, Jacopo, et al.
Published: (2025)
How Can ChatGPT Support Human Security Testers to Help Mitigate Supply Chain Attacks?
by: Zhang, Ying, et al.
Published: (2023)
by: Zhang, Ying, et al.
Published: (2023)
Pinning Is Futile: You Need More Than Local Dependency Versioning to Defend against Supply Chain Attacks
by: He, Hao, et al.
Published: (2025)
by: He, Hao, et al.
Published: (2025)
Deep Learning Aided Software Vulnerability Detection: A Survey
by: Uddin, Md Nizam, et al.
Published: (2025)
by: Uddin, Md Nizam, et al.
Published: (2025)
SHERLOCK: A Deep Learning Approach To Detect Software Vulnerabilities
by: Jawwadh, Saadh, et al.
Published: (2025)
by: Jawwadh, Saadh, et al.
Published: (2025)
VulEval: Towards Repository-Level Evaluation of Software Vulnerability Detection
by: Wen, Xin-Cheng, et al.
Published: (2024)
by: Wen, Xin-Cheng, et al.
Published: (2024)
AI-Based Software Vulnerability Detection: A Systematic Literature Review
by: Shimmi, Samiha, et al.
Published: (2025)
by: Shimmi, Samiha, et al.
Published: (2025)
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
SCALE: Constructing Structured Natural Language Comment Trees for Software Vulnerability Detection
by: Wen, Xin-Cheng, et al.
Published: (2024)
by: Wen, Xin-Cheng, et al.
Published: (2024)
Similar Items
-
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
by: Schmid, Larissa, et al.
Published: (2026) -
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
by: Reyes, Frank, et al.
Published: (2024) -
On-Chain Analysis of Smart Contract Dependency Risks on Ethereum
by: Jin, Monica, et al.
Published: (2025) -
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025) -
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
by: Sharma, Aman, et al.
Published: (2024)