Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
Fuente:
arXiv
Saved in:
| Main Authors: | O'Donoghue, Eric, Hastings, Yvette, Ortiz, Ernesto, Muneza, A. Redempta Manzi |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025)
by: Hegewald, Richard, et al.
Published: (2025)
Software Security in Software-Defined Networking: A Systematic Literature Review
by: Diouf, Moustapha Awwalou, et al.
Published: (2025)
by: Diouf, Moustapha Awwalou, et al.
Published: (2025)
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025)
by: Monperrus, Martin
Published: (2025)
Towards Predicting Multi-Vulnerability Attack Chains in Software Supply Chains from Software Bill of Materials Graphs
by: Baird, Laura, et al.
Published: (2026)
by: Baird, Laura, et al.
Published: (2026)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024)
by: Kalu, Kelechi G., et al.
Published: (2024)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
by: Schmid, Larissa, et al.
Published: (2026)
by: Schmid, Larissa, et al.
Published: (2026)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
Dirty-Waters: Detecting Software Supply Chain Smells
by: Liu, Raphina, et al.
Published: (2024)
by: Liu, Raphina, et al.
Published: (2024)
AI-Based Software Vulnerability Detection: A Systematic Literature Review
by: Shimmi, Samiha, et al.
Published: (2025)
by: Shimmi, Samiha, et al.
Published: (2025)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
by: Ruan, Bonan, et al.
Published: (2025)
by: Ruan, Bonan, et al.
Published: (2025)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
by: Reyes, Frank, et al.
Published: (2024)
by: Reyes, Frank, et al.
Published: (2024)
An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management
by: Tran, Nguyen Khoi, et al.
Published: (2023)
by: Tran, Nguyen Khoi, et al.
Published: (2023)
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
by: Sharma, Aman, et al.
Published: (2024)
by: Sharma, Aman, et al.
Published: (2024)
GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
by: Cesarano, Carmine, et al.
Published: (2025)
by: Cesarano, Carmine, et al.
Published: (2025)
Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack
by: Przymus, Piotr, et al.
Published: (2025)
by: Przymus, Piotr, et al.
Published: (2025)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
OmniBOR: A System for Automatic, Verifiable Artifact Resolution across Software Supply Chains
by: Seshadri, Bharathi, et al.
Published: (2024)
by: Seshadri, Bharathi, et al.
Published: (2024)
QUT-DV25: A Dataset for Dynamic Analysis of Next-Gen Software Supply Chain Attacks
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
An Introduction to Adaptive Software Security
by: Nia, Mehran Alidoost
Published: (2023)
by: Nia, Mehran Alidoost
Published: (2023)
Software Security Analysis in 2030 and Beyond: A Research Roadmap
by: Böhme, Marcel, et al.
Published: (2024)
by: Böhme, Marcel, et al.
Published: (2024)
Security of Language Models for Code: A Systematic Literature Review
by: Chen, Yuchen, et al.
Published: (2024)
by: Chen, Yuchen, et al.
Published: (2024)
Challenges in Developing Secure Software -- Results of an Interview Study in the German Software Industry
by: Mattukat, Alex R., et al.
Published: (2025)
by: Mattukat, Alex R., et al.
Published: (2025)
Patch2QL: Discover Cognate Defects in Open Source Software Supply Chain With Auto-generated Static Analysis Rules
by: Wang, Fuwei, et al.
Published: (2024)
by: Wang, Fuwei, et al.
Published: (2024)
SBOMproof: Beyond Alleged SBOM Compliance for Supply Chain Security of Container Images
by: Bufalino, Jacopo, et al.
Published: (2025)
by: Bufalino, Jacopo, et al.
Published: (2025)
Securing Tomorrow's Smart Cities: Investigating Software Security in Internet of Vehicles and Deep Learning Technologies
by: Jain, Ridhi, et al.
Published: (2024)
by: Jain, Ridhi, et al.
Published: (2024)
Generating Proof-of-Vulnerability Tests to Help Enhance the Security of Complex Software
by: Kanchi, Shravya, et al.
Published: (2026)
by: Kanchi, Shravya, et al.
Published: (2026)
How to Secure Existing C and C++ Software without Memory Safety
by: Erlingsson, Úlfar
Published: (2025)
by: Erlingsson, Úlfar
Published: (2025)
The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
How Can ChatGPT Support Human Security Testers to Help Mitigate Supply Chain Attacks?
by: Zhang, Ying, et al.
Published: (2023)
by: Zhang, Ying, et al.
Published: (2023)
Toward Automated Security Risk Detection in Large Software Using Call Graph Analysis
by: Pecka, Nicholas, et al.
Published: (2025)
by: Pecka, Nicholas, et al.
Published: (2025)
Using AI Assistants in Software Development: A Qualitative Study on Security Practices and Concerns
by: Klemmer, Jan H., et al.
Published: (2024)
by: Klemmer, Jan H., et al.
Published: (2024)
SecDOAR: A Software Reference Architecture for Security Data Orchestration, Analysis and Reporting
by: Chauhan, Muhammad Aufeef, et al.
Published: (2024)
by: Chauhan, Muhammad Aufeef, et al.
Published: (2024)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
by: Cusick, James J.
Published: (2025)
by: Cusick, James J.
Published: (2025)
Investigating Vulnerability Disclosures in Open-Source Software Using Bug Bounty Reports and Security Advisories
by: Ayala, Jessy, et al.
Published: (2025)
by: Ayala, Jessy, et al.
Published: (2025)
Detecting Misuse of Security APIs: A Systematic Review
by: Mousavi, Zahra, et al.
Published: (2023)
by: Mousavi, Zahra, et al.
Published: (2023)
A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features
by: Ayala, Jessy, et al.
Published: (2024)
by: Ayala, Jessy, et al.
Published: (2024)
A Systematic Literature Review on Automated Exploit and Security Test Generation
by: Bui, Quang-Cuong, et al.
Published: (2025)
by: Bui, Quang-Cuong, et al.
Published: (2025)
Similar Items
-
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025) -
Software Security in Software-Defined Networking: A Systematic Literature Review
by: Diouf, Moustapha Awwalou, et al.
Published: (2025) -
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026) -
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025) -
Towards Predicting Multi-Vulnerability Attack Chains in Software Supply Chains from Software Bill of Materials Graphs
by: Baird, Laura, et al.
Published: (2026)