Exploring the SECURITY.md in the Dependency Chain: Preliminary Analysis of the PyPI Ecosystem

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Termphaiboon, Chayanid, Kula, Raula Gaikovina, Fan, Youmei, Choetkiertikul, Morakot, Ragkhitwetsagul, Chaiyong, Sunetnanta, Thanwadee, Matsumoto, Kenichi
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915640538824704
author Termphaiboon, Chayanid
Kula, Raula Gaikovina
Fan, Youmei
Choetkiertikul, Morakot
Ragkhitwetsagul, Chaiyong
Sunetnanta, Thanwadee
Matsumoto, Kenichi
author_facet Termphaiboon, Chayanid
Kula, Raula Gaikovina
Fan, Youmei
Choetkiertikul, Morakot
Ragkhitwetsagul, Chaiyong
Sunetnanta, Thanwadee
Matsumoto, Kenichi
contents Security policies, such as SECURITY.md files, are now common in open-source projects. They help guide responsible vulnerability reporting and build trust among users and contributors. Despite their growing use, it is still unclear how these policies influence the structure and evolution of software dependencies. Software dependencies are external packages or libraries that a project relies on, and their interconnected nature affects both functionality and security. This study explores the relationship between security policies and dependency management in PyPI projects. We analyzed projects with and without a SECURITY.md file by examining their dependency trees and tracking how dependencies change over time. The analysis shows that projects with a security policy tend to rely on a broader set of direct dependencies, while overall depth and transitive dependencies remain similar. Historically, projects created after the introduction of SECURITY.md, particularly later adopters, show more frequent dependency updates. These results suggest that security policies are linked to more modular and feature-rich projects, and highlight the role of SECURITY.md in promoting proactive dependency management and reducing risks in the software supply chain.
format Preprint
id arxiv_https___arxiv_org_abs_2511_22186
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Exploring the SECURITY.md in the Dependency Chain: Preliminary Analysis of the PyPI Ecosystem
Termphaiboon, Chayanid
Kula, Raula Gaikovina
Fan, Youmei
Choetkiertikul, Morakot
Ragkhitwetsagul, Chaiyong
Sunetnanta, Thanwadee
Matsumoto, Kenichi
Software Engineering
Security policies, such as SECURITY.md files, are now common in open-source projects. They help guide responsible vulnerability reporting and build trust among users and contributors. Despite their growing use, it is still unclear how these policies influence the structure and evolution of software dependencies. Software dependencies are external packages or libraries that a project relies on, and their interconnected nature affects both functionality and security. This study explores the relationship between security policies and dependency management in PyPI projects. We analyzed projects with and without a SECURITY.md file by examining their dependency trees and tracking how dependencies change over time. The analysis shows that projects with a security policy tend to rely on a broader set of direct dependencies, while overall depth and transitive dependencies remain similar. Historically, projects created after the introduction of SECURITY.md, particularly later adopters, show more frequent dependency updates. These results suggest that security policies are linked to more modular and feature-rich projects, and highlight the role of SECURITY.md in promoting proactive dependency management and reducing risks in the software supply chain.
title Exploring the SECURITY.md in the Dependency Chain: Preliminary Analysis of the PyPI Ecosystem
topic Software Engineering
url https://arxiv.org/abs/2511.22186