ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
Fuente:
arXiv
Saved in:
| Main Authors: | Kalu, Kelechi G., Okorafor, Sofia, Durak, Betül, Laine, Kim, Moreno, Radames C., Torres-Arias, Santiago, Davis, James C. |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Why Software Signing (Still) Matters: Trust Boundaries in the Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024)
by: Kalu, Kelechi G., et al.
Published: (2024)
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
A Longitudinal Study of Usability in Identity-Based Software Signing
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
by: Schorlemmer, Taylor R., et al.
Published: (2024)
by: Schorlemmer, Taylor R., et al.
Published: (2024)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
by: Schorlemmer, Taylor R, et al.
Published: (2024)
by: Schorlemmer, Taylor R, et al.
Published: (2024)
A Guide to Stakeholder Analysis for Cybersecurity Researchers
by: Davis, James C, et al.
Published: (2025)
by: Davis, James C, et al.
Published: (2025)
ZTD$_{JAVA}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies
by: Amusuo, Paschal C., et al.
Published: (2023)
by: Amusuo, Paschal C., et al.
Published: (2023)
How Do Agents Perform Code Optimization? An Empirical Study
by: Peng, Huiyun, et al.
Published: (2025)
by: Peng, Huiyun, et al.
Published: (2025)
DiVerify: Hardening Identity-Based Software Signing with Diverse-Context Scopes
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
Dirty-Waters: Detecting Software Supply Chain Smells
by: Liu, Raphina, et al.
Published: (2024)
by: Liu, Raphina, et al.
Published: (2024)
Sandi: A System for Accountability
by: Durak, F. Betül, et al.
Published: (2024)
by: Durak, F. Betül, et al.
Published: (2024)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
by: Schmid, Larissa, et al.
Published: (2026)
by: Schmid, Larissa, et al.
Published: (2026)
Cascaded Vulnerability Attacks in Software Supply Chains
by: Baird, Laura, et al.
Published: (2026)
by: Baird, Laura, et al.
Published: (2026)
The Grand Software Supply Chain of AI Systems
by: Cesarano, Carmine, et al.
Published: (2026)
by: Cesarano, Carmine, et al.
Published: (2026)
Patch2QL: Discover Cognate Defects in Open Source Software Supply Chain With Auto-generated Static Analysis Rules
by: Wang, Fuwei, et al.
Published: (2024)
by: Wang, Fuwei, et al.
Published: (2024)
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025)
by: Hegewald, Richard, et al.
Published: (2025)
A First Look at the General Data Protection Regulation (GDPR) in Open-Source Software
by: Franke, Lucas, et al.
Published: (2024)
by: Franke, Lucas, et al.
Published: (2024)
An Exploratory Mixed-Methods Study on General Data Protection Regulation (GDPR) Compliance in Open-Source Software
by: Franke, Lucas, et al.
Published: (2024)
by: Franke, Lucas, et al.
Published: (2024)
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025)
by: Monperrus, Martin
Published: (2025)
Software Dependencies 2.0: An Empirical Study of Reuse and Integration of Pre-Trained Models in Open-Source Projects
by: Yasmin, Jerin, et al.
Published: (2025)
by: Yasmin, Jerin, et al.
Published: (2025)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
Trust in Software Supply Chains: Blockchain-Enabled SBOM and the AIBOM Future
by: Xia, Boming, et al.
Published: (2023)
by: Xia, Boming, et al.
Published: (2023)
OpenLambdaVerse: A Dataset and Analysis of Open-Source Serverless Applications
by: Chavez-Moreno, Angel C., et al.
Published: (2025)
by: Chavez-Moreno, Angel C., et al.
Published: (2025)
Measuring Software Development Waste in Open-Source Software Projects
by: Varanasi, Dhiraj SM, et al.
Published: (2024)
by: Varanasi, Dhiraj SM, et al.
Published: (2024)
Measuring Software Innovation with Open Source Software Development Data
by: Brown, Eva Maxfield, et al.
Published: (2024)
by: Brown, Eva Maxfield, et al.
Published: (2024)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
by: Ruan, Bonan, et al.
Published: (2025)
by: Ruan, Bonan, et al.
Published: (2025)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
by: O'Donoghue, Eric, et al.
Published: (2025)
by: O'Donoghue, Eric, et al.
Published: (2025)
Understanding Underrepresented Groups in Open Source Software
by: Santos, Reydne, et al.
Published: (2025)
by: Santos, Reydne, et al.
Published: (2025)
Extension Decisions in Open Source Software Ecosystem
by: Onagh, Elmira, et al.
Published: (2025)
by: Onagh, Elmira, et al.
Published: (2025)
An Empirical Validation of Open Source Repository Stability Metrics
by: Adejumo, Elijah Kayode, et al.
Published: (2025)
by: Adejumo, Elijah Kayode, et al.
Published: (2025)
The "4W+1H" of Software Supply Chain Security Checklist for Critical Infrastructure
by: Dong, Liming, et al.
Published: (2025)
by: Dong, Liming, et al.
Published: (2025)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
by: Reyes, Frank, et al.
Published: (2024)
by: Reyes, Frank, et al.
Published: (2024)
An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management
by: Tran, Nguyen Khoi, et al.
Published: (2023)
by: Tran, Nguyen Khoi, et al.
Published: (2023)
The Evaluation of Open Source Software Innovativeness
by: Benkeltoum, Nordine
Published: (2025)
by: Benkeltoum, Nordine
Published: (2025)
Community Engagement and the Lifespan of Open-Source Software Projects
by: Kaushik, Mohit, et al.
Published: (2025)
by: Kaushik, Mohit, et al.
Published: (2025)
Context Engineering for AI Agents in Open-Source Software
by: Mohsenimofidi, Seyedmoein, et al.
Published: (2025)
by: Mohsenimofidi, Seyedmoein, et al.
Published: (2025)
Similar Items
-
Why Software Signing (Still) Matters: Trust Boundaries in the Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025) -
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
by: Kalu, Kelechi G., et al.
Published: (2025) -
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024) -
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026) -
A Longitudinal Study of Usability in Identity-Based Software Signing
by: Kalu, Kelechi G., et al.
Published: (2026)