Why Software Signing (Still) Matters: Trust Boundaries in the Software Supply Chain
Fuente:
arXiv
Saved in:
| Main Authors: | Kalu, Kelechi G., Davis, James C. |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024)
by: Kalu, Kelechi G., et al.
Published: (2024)
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
A Longitudinal Study of Usability in Identity-Based Software Signing
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
by: Schorlemmer, Taylor R., et al.
Published: (2024)
by: Schorlemmer, Taylor R., et al.
Published: (2024)
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
by: Schorlemmer, Taylor R, et al.
Published: (2024)
by: Schorlemmer, Taylor R, et al.
Published: (2024)
Trust in Software Supply Chains: Blockchain-Enabled SBOM and the AIBOM Future
by: Xia, Boming, et al.
Published: (2023)
by: Xia, Boming, et al.
Published: (2023)
Cascaded Vulnerability Attacks in Software Supply Chains
by: Baird, Laura, et al.
Published: (2026)
by: Baird, Laura, et al.
Published: (2026)
The Grand Software Supply Chain of AI Systems
by: Cesarano, Carmine, et al.
Published: (2026)
by: Cesarano, Carmine, et al.
Published: (2026)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025)
by: Hegewald, Richard, et al.
Published: (2025)
A Guide to Stakeholder Analysis for Cybersecurity Researchers
by: Davis, James C, et al.
Published: (2025)
by: Davis, James C, et al.
Published: (2025)
ZTD$_{JAVA}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies
by: Amusuo, Paschal C., et al.
Published: (2023)
by: Amusuo, Paschal C., et al.
Published: (2023)
How Do Agents Perform Code Optimization? An Empirical Study
by: Peng, Huiyun, et al.
Published: (2025)
by: Peng, Huiyun, et al.
Published: (2025)
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025)
by: Monperrus, Martin
Published: (2025)
DiVerify: Hardening Identity-Based Software Signing with Diverse-Context Scopes
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
Manifestations of Empathy in Software Engineering: How, Why, and When It Matters
by: Gunatilake, Hashini, et al.
Published: (2025)
by: Gunatilake, Hashini, et al.
Published: (2025)
It is Giving Major Satisfaction: Why Fairness Matters for Software Practitioners
by: Sesari, Emeralda, et al.
Published: (2024)
by: Sesari, Emeralda, et al.
Published: (2024)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
by: O'Donoghue, Eric, et al.
Published: (2025)
by: O'Donoghue, Eric, et al.
Published: (2025)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
Dirty-Waters: Detecting Software Supply Chain Smells
by: Liu, Raphina, et al.
Published: (2024)
by: Liu, Raphina, et al.
Published: (2024)
Why Does the Engineering Manager Still Exist in Agile Software Development?
by: Kalluri, Ravi
Published: (2025)
by: Kalluri, Ravi
Published: (2025)
Analyzing Challenges in Deployment of the SLSA Framework for Software Supply Chain Security
by: Tamanna, Mahzabin, et al.
Published: (2024)
by: Tamanna, Mahzabin, et al.
Published: (2024)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
by: Ruan, Bonan, et al.
Published: (2025)
by: Ruan, Bonan, et al.
Published: (2025)
The "4W+1H" of Software Supply Chain Security Checklist for Critical Infrastructure
by: Dong, Liming, et al.
Published: (2025)
by: Dong, Liming, et al.
Published: (2025)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
by: Reyes, Frank, et al.
Published: (2024)
by: Reyes, Frank, et al.
Published: (2024)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
by: Schmid, Larissa, et al.
Published: (2026)
by: Schmid, Larissa, et al.
Published: (2026)
An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management
by: Tran, Nguyen Khoi, et al.
Published: (2023)
by: Tran, Nguyen Khoi, et al.
Published: (2023)
Towards Predicting Multi-Vulnerability Attack Chains in Software Supply Chains from Software Bill of Materials Graphs
by: Baird, Laura, et al.
Published: (2026)
by: Baird, Laura, et al.
Published: (2026)
Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines
by: Dhandapani, Sowmiya
Published: (2025)
by: Dhandapani, Sowmiya
Published: (2025)
TrustOps: Continuously Building Trustworthy Software
by: Brito, Eduardo, et al.
Published: (2024)
by: Brito, Eduardo, et al.
Published: (2024)
FAIL: Analyzing Software Failures from the News Using LLMs
by: Anandayuvaraj, Dharun, et al.
Published: (2024)
by: Anandayuvaraj, Dharun, et al.
Published: (2024)
Elevating Software Trust: Unveiling and Quantifying the Risk Landscape
by: Siddiqui, Sarah Ali, et al.
Published: (2024)
by: Siddiqui, Sarah Ali, et al.
Published: (2024)
GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
by: Cesarano, Carmine, et al.
Published: (2025)
by: Cesarano, Carmine, et al.
Published: (2025)
Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack
by: Przymus, Piotr, et al.
Published: (2025)
by: Przymus, Piotr, et al.
Published: (2025)
No Silver Bullets: Why Understanding Software Cycle Time is Messy, Not Magic
by: Flournoy, John C., et al.
Published: (2025)
by: Flournoy, John C., et al.
Published: (2025)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
OmniBOR: A System for Automatic, Verifiable Artifact Resolution across Software Supply Chains
by: Seshadri, Bharathi, et al.
Published: (2024)
by: Seshadri, Bharathi, et al.
Published: (2024)
Reusing Deep Learning Models: Challenges and Directions in Software Engineering
by: Davis, James C., et al.
Published: (2024)
by: Davis, James C., et al.
Published: (2024)
Similar Items
-
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024) -
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026) -
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
by: Kalu, Kelechi G., et al.
Published: (2025) -
A Longitudinal Study of Usability in Identity-Based Software Signing
by: Kalu, Kelechi G., et al.
Published: (2026) -
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)