Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines
Fuente:
arXiv
Saved in:
| Main Author: | Dhandapani, Sowmiya |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
PPTAM$η$: Energy Aware CI/CD Pipeline for Container Based Applications
by: Aneggi, Alessandro, et al.
Published: (2026)
by: Aneggi, Alessandro, et al.
Published: (2026)
On Queueing Theory for Large-Scale CI/CD Pipelines Optimization
by: Bournassenko, Grégory
Published: (2025)
by: Bournassenko, Grégory
Published: (2025)
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025)
by: Hegewald, Richard, et al.
Published: (2025)
Empirical Analysis on CI/CD Pipeline Evolution in Machine Learning Projects
by: Rzig, Dhia Elhaq, et al.
Published: (2024)
by: Rzig, Dhia Elhaq, et al.
Published: (2024)
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025)
by: Monperrus, Martin
Published: (2025)
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
Environmental Impact of CI/CD Pipelines
by: Saavedra, Nuno, et al.
Published: (2025)
by: Saavedra, Nuno, et al.
Published: (2025)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
Portable and Secure CI/CD for COBOL: Lessons from an Industrial Migration
by: Askholm, Andreas, et al.
Published: (2026)
by: Askholm, Andreas, et al.
Published: (2026)
Analyzing Challenges in Deployment of the SLSA Framework for Software Supply Chain Security
by: Tamanna, Mahzabin, et al.
Published: (2024)
by: Tamanna, Mahzabin, et al.
Published: (2024)
The "4W+1H" of Software Supply Chain Security Checklist for Critical Infrastructure
by: Dong, Liming, et al.
Published: (2025)
by: Dong, Liming, et al.
Published: (2025)
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024)
by: Kalu, Kelechi G., et al.
Published: (2024)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
by: O'Donoghue, Eric, et al.
Published: (2025)
by: O'Donoghue, Eric, et al.
Published: (2025)
Towards an Optimized Benchmarking Platform for CI/CD Pipelines
by: Japke, Nils, et al.
Published: (2025)
by: Japke, Nils, et al.
Published: (2025)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
Cascaded Vulnerability Attacks in Software Supply Chains
by: Baird, Laura, et al.
Published: (2026)
by: Baird, Laura, et al.
Published: (2026)
The Grand Software Supply Chain of AI Systems
by: Cesarano, Carmine, et al.
Published: (2026)
by: Cesarano, Carmine, et al.
Published: (2026)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
by: Schmid, Larissa, et al.
Published: (2026)
by: Schmid, Larissa, et al.
Published: (2026)
FaaSGuard: Secure CI/CD for Serverless Applications -- An OpenFaaS Case Study
by: Barrak, Amine, et al.
Published: (2025)
by: Barrak, Amine, et al.
Published: (2025)
Using Large Language Models to Support Automation of Failure Management in CI/CD Pipelines: A Case Study in SAP HANA
by: Bui, Duong, et al.
Published: (2026)
by: Bui, Duong, et al.
Published: (2026)
Why Software Signing (Still) Matters: Trust Boundaries in the Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
AI-Augmented CI/CD Pipelines: From Code Commit to Production with Autonomous Decisions
by: Baqar, Mohammad, et al.
Published: (2025)
by: Baqar, Mohammad, et al.
Published: (2025)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
by: Ruan, Bonan, et al.
Published: (2025)
by: Ruan, Bonan, et al.
Published: (2025)
Adoption and Adaptation of CI/CD Practices in Very Small Software Development Entities: A Systematic Literature Review
by: Ccallo, Mario, et al.
Published: (2024)
by: Ccallo, Mario, et al.
Published: (2024)
Decoupling Identity from Access: Credential Broker Patterns for Secure CI/CD
by: Avirneni, Surya Teja
Published: (2025)
by: Avirneni, Surya Teja
Published: (2025)
Trust in Software Supply Chains: Blockchain-Enabled SBOM and the AIBOM Future
by: Xia, Boming, et al.
Published: (2023)
by: Xia, Boming, et al.
Published: (2023)
An OpenSource CI/CD Pipeline for Variant-Rich Software-Defined Vehicles
by: Weiß, Matthias, et al.
Published: (2025)
by: Weiß, Matthias, et al.
Published: (2025)
An Architecture for Remote Container Builds and Artifact Delivery Using a Controller-Light Jenkins CI/CD Pipeline
by: Paul, Kawshik Kumar, et al.
Published: (2025)
by: Paul, Kawshik Kumar, et al.
Published: (2025)
LLM-Augmented Release Intelligence: Automated Change Summarization and Impact Analysis in Cloud-Native CI/CD Pipelines
by: Bhati, Happy
Published: (2026)
by: Bhati, Happy
Published: (2026)
Towards Sustainable and Secure Reuse in Dependency Supply Chains: Initial Analysis of NPM packages at the End of the Chain
by: Reid, Brittany Anne, et al.
Published: (2025)
by: Reid, Brittany Anne, et al.
Published: (2025)
Dirty-Waters: Detecting Software Supply Chain Smells
by: Liu, Raphina, et al.
Published: (2024)
by: Liu, Raphina, et al.
Published: (2024)
LogSage: An LLM-Based Framework for CI/CD Failure Detection and Remediation with Industrial Validation
by: Xu, Weiyuan, et al.
Published: (2025)
by: Xu, Weiyuan, et al.
Published: (2025)
A General Solution for the Implementation of CI/CD in Embedded Linux Development
by: Agahi, Behnam, et al.
Published: (2025)
by: Agahi, Behnam, et al.
Published: (2025)
When AI Agents Touch CI/CD Configurations: Frequency and Success
by: Ghaleb, Taher A.
Published: (2026)
by: Ghaleb, Taher A.
Published: (2026)
Developing a Llama-Based Chatbot for CI/CD Question Answering: A Case Study at Ericsson
by: Chaudhary, Daksh, et al.
Published: (2024)
by: Chaudhary, Daksh, et al.
Published: (2024)
"Good" and "Bad" Failures in Industrial CI/CD -- Balancing Cost and Quality Assurance
by: Sun, Simin, et al.
Published: (2025)
by: Sun, Simin, et al.
Published: (2025)
Exploring the Impact of Integrating UI Testing in CI/CD Workflows on GitHub
by: Gan, Xiaoxiao, et al.
Published: (2025)
by: Gan, Xiaoxiao, et al.
Published: (2025)
CI/CD Configuration Practices in Open-Source Android Apps: An Empirical Study
by: Ghaleb, Taher A., et al.
Published: (2024)
by: Ghaleb, Taher A., et al.
Published: (2024)
Investigating CI/CD-based Technical Debt Management in Open-source Projects
by: Biazotto, João Paulo, et al.
Published: (2026)
by: Biazotto, João Paulo, et al.
Published: (2026)
Chronicles of CI/CD: A Deep Dive into its Usage Over Time
by: da Gião, Hugo, et al.
Published: (2024)
by: da Gião, Hugo, et al.
Published: (2024)
Similar Items
-
PPTAM$η$: Energy Aware CI/CD Pipeline for Container Based Applications
by: Aneggi, Alessandro, et al.
Published: (2026) -
On Queueing Theory for Large-Scale CI/CD Pipelines Optimization
by: Bournassenko, Grégory
Published: (2025) -
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025) -
Empirical Analysis on CI/CD Pipeline Evolution in Machine Learning Projects
by: Rzig, Dhia Elhaq, et al.
Published: (2024) -
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025)