ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Kalu, Kelechi G., Okorafor, Sofia, Durak, Betül, Laine, Kim, Moreno, Radames C., Torres-Arias, Santiago, Davis, James C.
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866914288125345792
author Kalu, Kelechi G.
Okorafor, Sofia
Durak, Betül
Laine, Kim
Moreno, Radames C.
Torres-Arias, Santiago
Davis, James C.
author_facet Kalu, Kelechi G.
Okorafor, Sofia
Durak, Betül
Laine, Kim
Moreno, Radames C.
Torres-Arias, Santiago
Davis, James C.
contents Many critical information technology and cyber-physical systems rely on a supply chain of open-source software projects. OSS project maintainers often integrate contributions from external actors. While maintainers can assess the correctness of a pull request, assessing a pull request's cybersecurity implications is challenging. To help maintainers make this decision, we propose that the open-source ecosystem should incorporate Actor Reputation Metrics (ARMS). This capability would enable OSS maintainers to assess a prospective contributor's cybersecurity reputation. To support the future instantiation of ARMS, we identify seven generic security signals from industry standards; map concrete metrics from prior work and available security tools, describe study designs to refine and assess the utility of ARMS, and finally weigh its pros and cons.
format Preprint
id arxiv_https___arxiv_org_abs_2505_18760
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
Kalu, Kelechi G.
Okorafor, Sofia
Durak, Betül
Laine, Kim
Moreno, Radames C.
Torres-Arias, Santiago
Davis, James C.
Cryptography and Security
Software Engineering
Many critical information technology and cyber-physical systems rely on a supply chain of open-source software projects. OSS project maintainers often integrate contributions from external actors. While maintainers can assess the correctness of a pull request, assessing a pull request's cybersecurity implications is challenging. To help maintainers make this decision, we propose that the open-source ecosystem should incorporate Actor Reputation Metrics (ARMS). This capability would enable OSS maintainers to assess a prospective contributor's cybersecurity reputation. To support the future instantiation of ARMS, we identify seven generic security signals from industry standards; map concrete metrics from prior work and available security tools, describe study designs to refine and assess the utility of ARMS, and finally weigh its pros and cons.
title ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2505.18760