ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
Fuente:
arXiv
Guardado en:
| Autores principales: | , , , , , , |
|---|---|
| Formato: | Preprint |
| Publicado: |
2025
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
| _version_ | 1866914288125345792 |
|---|---|
| author | Kalu, Kelechi G. Okorafor, Sofia Durak, Betül Laine, Kim Moreno, Radames C. Torres-Arias, Santiago Davis, James C. |
| author_facet | Kalu, Kelechi G. Okorafor, Sofia Durak, Betül Laine, Kim Moreno, Radames C. Torres-Arias, Santiago Davis, James C. |
| contents | Many critical information technology and cyber-physical systems rely on a supply chain of open-source software projects. OSS project maintainers often integrate contributions from external actors. While maintainers can assess the correctness of a pull request, assessing a pull request's cybersecurity implications is challenging. To help maintainers make this decision, we propose that the open-source ecosystem should incorporate Actor Reputation Metrics (ARMS). This capability would enable OSS maintainers to assess a prospective contributor's cybersecurity reputation. To support the future instantiation of ARMS, we identify seven generic security signals from industry standards; map concrete metrics from prior work and available security tools, describe study designs to refine and assess the utility of ARMS, and finally weigh its pros and cons. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2505_18760 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain Kalu, Kelechi G. Okorafor, Sofia Durak, Betül Laine, Kim Moreno, Radames C. Torres-Arias, Santiago Davis, James C. Cryptography and Security Software Engineering Many critical information technology and cyber-physical systems rely on a supply chain of open-source software projects. OSS project maintainers often integrate contributions from external actors. While maintainers can assess the correctness of a pull request, assessing a pull request's cybersecurity implications is challenging. To help maintainers make this decision, we propose that the open-source ecosystem should incorporate Actor Reputation Metrics (ARMS). This capability would enable OSS maintainers to assess a prospective contributor's cybersecurity reputation. To support the future instantiation of ARMS, we identify seven generic security signals from industry standards; map concrete metrics from prior work and available security tools, describe study designs to refine and assess the utility of ARMS, and finally weigh its pros and cons. |
| title | ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain |
| topic | Cryptography and Security Software Engineering |
| url | https://arxiv.org/abs/2505.18760 |