The "4W+1H" of Software Supply Chain Security Checklist for Critical Infrastructure
Fuente:
arXiv
Saved in:
| Main Authors: | Dong, Liming, Lee, Sung Une, Xing, Zhenchang, Ahmed, Muhammad Ejaz, Avgoustakis, Stefan |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Software Security Mapping Framework: Operationalization of Security Requirements
by: Lee, Sung Une, et al.
Published: (2025)
by: Lee, Sung Une, et al.
Published: (2025)
Trust in Software Supply Chains: Blockchain-Enabled SBOM and the AIBOM Future
by: Xia, Boming, et al.
Published: (2023)
by: Xia, Boming, et al.
Published: (2023)
Towards a Responsible AI Metrics Catalogue: A Collection of Metrics for AI Accountability
by: Xia, Boming, et al.
Published: (2023)
by: Xia, Boming, et al.
Published: (2023)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
A Structured Approach to Safety Case Construction for AI Systems
by: Lee, Sung Une, et al.
Published: (2026)
by: Lee, Sung Une, et al.
Published: (2026)
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025)
by: Hegewald, Richard, et al.
Published: (2025)
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025)
by: Monperrus, Martin
Published: (2025)
Analyzing Challenges in Deployment of the SLSA Framework for Software Supply Chain Security
by: Tamanna, Mahzabin, et al.
Published: (2024)
by: Tamanna, Mahzabin, et al.
Published: (2024)
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024)
by: Kalu, Kelechi G., et al.
Published: (2024)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
by: O'Donoghue, Eric, et al.
Published: (2025)
by: O'Donoghue, Eric, et al.
Published: (2025)
Blockchain-Enabled Accountability in Data Supply Chain: A Data Bill of Materials Approach
by: Liu, Yue, et al.
Published: (2024)
by: Liu, Yue, et al.
Published: (2024)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
Cascaded Vulnerability Attacks in Software Supply Chains
by: Baird, Laura, et al.
Published: (2026)
by: Baird, Laura, et al.
Published: (2026)
The Grand Software Supply Chain of AI Systems
by: Cesarano, Carmine, et al.
Published: (2026)
by: Cesarano, Carmine, et al.
Published: (2026)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
by: Schmid, Larissa, et al.
Published: (2026)
by: Schmid, Larissa, et al.
Published: (2026)
SeeAction: Towards Reverse Engineering How-What-Where of HCI Actions from Screencasts for UI Automation
by: Zhao, Dehai, et al.
Published: (2025)
by: Zhao, Dehai, et al.
Published: (2025)
Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines
by: Dhandapani, Sowmiya
Published: (2025)
by: Dhandapani, Sowmiya
Published: (2025)
Why Software Signing (Still) Matters: Trust Boundaries in the Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
A Taxonomy of Foundation Model based Systems through the Lens of Software Architecture
by: Lu, Qinghua, et al.
Published: (2023)
by: Lu, Qinghua, et al.
Published: (2023)
Towards Responsible Generative AI: A Reference Architecture for Designing Foundation Model based Agents
by: Lu, Qinghua, et al.
Published: (2023)
by: Lu, Qinghua, et al.
Published: (2023)
When AI Takes the Wheel: Security Analysis of Framework-Constrained Program Generation
by: Liu, Yue, et al.
Published: (2025)
by: Liu, Yue, et al.
Published: (2025)
Towards Sustainable and Secure Reuse in Dependency Supply Chains: Initial Analysis of NPM packages at the End of the Chain
by: Reid, Brittany Anne, et al.
Published: (2025)
by: Reid, Brittany Anne, et al.
Published: (2025)
Dirty-Waters: Detecting Software Supply Chain Smells
by: Liu, Raphina, et al.
Published: (2024)
by: Liu, Raphina, et al.
Published: (2024)
Automated Soap Opera Testing Directed by LLMs and Scenario Knowledge: Feasibility, Challenges, and Road Ahead
by: Su, Yanqi, et al.
Published: (2024)
by: Su, Yanqi, et al.
Published: (2024)
A Taxonomy of Architecture Options for Foundation Model-based Agents: Analysis and Decision Model
by: Zhou, Jingwen, et al.
Published: (2024)
by: Zhou, Jingwen, et al.
Published: (2024)
From Code to Courtroom: LLMs as the New Software Judges
by: He, Junda, et al.
Published: (2025)
by: He, Junda, et al.
Published: (2025)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
by: Ruan, Bonan, et al.
Published: (2025)
by: Ruan, Bonan, et al.
Published: (2025)
Evaluation-Driven Development and Operations of LLM Agents: A Process Model and Reference Architecture
by: Xia, Boming, et al.
Published: (2024)
by: Xia, Boming, et al.
Published: (2024)
LLM-as-a-Judge for Software Engineering: Literature Review, Vision, and the Road Ahead
by: He, Junda, et al.
Published: (2025)
by: He, Junda, et al.
Published: (2025)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
by: Reyes, Frank, et al.
Published: (2024)
by: Reyes, Frank, et al.
Published: (2024)
An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management
by: Tran, Nguyen Khoi, et al.
Published: (2023)
by: Tran, Nguyen Khoi, et al.
Published: (2023)
An AI System Evaluation Framework for Advancing AI Safety: Terminology, Taxonomy, Lifecycle Mapping
by: Xia, Boming, et al.
Published: (2024)
by: Xia, Boming, et al.
Published: (2024)
A Reference Architecture for Designing Foundation Model based Systems
by: Lu, Qinghua, et al.
Published: (2023)
by: Lu, Qinghua, et al.
Published: (2023)
Object Oriented-Based Metrics to Predict Fault Proneness in Software Design
by: Mir, Areeb Ahmed, et al.
Published: (2025)
by: Mir, Areeb Ahmed, et al.
Published: (2025)
Deployability-Centric Infrastructure-as-Code Generation: Fail, Learn, Refine, and Succeed through LLM-Empowered DevOps Simulation
by: Zhang, Tianyi, et al.
Published: (2025)
by: Zhang, Tianyi, et al.
Published: (2025)
Patch2QL: Discover Cognate Defects in Open Source Software Supply Chain With Auto-generated Static Analysis Rules
by: Wang, Fuwei, et al.
Published: (2024)
by: Wang, Fuwei, et al.
Published: (2024)
A State-of-the-practice Release-readiness Checklist for Generative AI-based Software Products
by: Patel, Harsh, et al.
Published: (2024)
by: Patel, Harsh, et al.
Published: (2024)
SBOMproof: Beyond Alleged SBOM Compliance for Supply Chain Security of Container Images
by: Bufalino, Jacopo, et al.
Published: (2025)
by: Bufalino, Jacopo, et al.
Published: (2025)
GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
by: Cesarano, Carmine, et al.
Published: (2025)
by: Cesarano, Carmine, et al.
Published: (2025)
Similar Items
-
Software Security Mapping Framework: Operationalization of Security Requirements
by: Lee, Sung Une, et al.
Published: (2025) -
Trust in Software Supply Chains: Blockchain-Enabled SBOM and the AIBOM Future
by: Xia, Boming, et al.
Published: (2023) -
Towards a Responsible AI Metrics Catalogue: A Collection of Metrics for AI Accountability
by: Xia, Boming, et al.
Published: (2023) -
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025) -
A Structured Approach to Safety Case Construction for AI Systems
by: Lee, Sung Une, et al.
Published: (2026)