Systematic literature review of the trust reinforcement mechanisms exist in package ecosystems

A Temelko, F Hou, S Farshidi, S Jansen - arxiv preprint arxiv:2407.02522, 2024 - arxiv.org
We conducted a thorough SLR to better grasp the challenges and possible solutions
associated with existing npm security tools. Our goal was to delve into documented …

Not all dependencies are equal: An empirical study on production dependencies in npm

J Latendresse, S Mujahid, DE Costa… - Proceedings of the 37th …, 2022 - dl.acm.org
Modern software systems are often built by leveraging code written by others in the form of
libraries and packages to accelerate their development. While there are many benefits to …

Charting the path to SBOM adoption: A business stakeholder-centric approach

B Kloeg, AY Ding, S Pellegrom… - Proceedings of the 19th …, 2024 - dl.acm.org
Organizations are increasingly reliant on third-party software products to expedite their own
development cycles, often incorporating numerous components into their end systems …

Where to Go Now? Finding Alternatives for Declining Packages in the npm Ecosystem

S Mujahid, DE Costa, R Abdalkareem… - 2023 38th IEEE/ACM …, 2023 - ieeexplore.ieee.org
Software ecosystems (eg, npm, PyPI) are the backbone of modern software developments.
Developers add new packages to ecosystems every day to solve new problems or provide …

The role of library versions in Developer-ChatGPT conversations

R Raj, DE Costa - Proceedings of the 21st International Conference on …, 2024 - dl.acm.org
The latest breakthroughs in large language models (LLM) have empowered software
development tools, such as ChatGPT, to aid developers in complex tasks. Developers use …

Library network security measures as determinants of archives preservation in public libraries in Rivers State, Nigeria

HE Obi - Asian Journal of Information Science and Technology, 2023 - ajist.co
This study examined available library network security measures as determinants of
archives preservation in public libraries in Rivers state. The descriptive survey design was …

Maven Unzipped: Exploring the Impact of Library Packaging on the Ecosystem

M Keshani, G Bot, P Rungta, M Izadi… - 2024 IEEE …, 2024 - ieeexplore.ieee.org
MAVEN is a popular dependency management tool and ecosystem used by millions of
developers. However, the over-whelming amount of available open-source software and the …

Why Johnny Can't Use Secure Docker Images: Investigating the Usability Challenges in Using Docker Image Vulnerability Scanners through Heuristic Evaluation

T Kim, S Park, H Kim - Proceedings of the 26th International Symposium …, 2023 - dl.acm.org
This paper explores the usability of Docker Image Vulnerability Scanners (DIVSes) through
heuristic evaluations. Docker simplifies the process of software development, distribution …

A Survey of Third-Party Library Security Research in Application Software

J Zeng, D Han, Y Zhu, Y Wang, F Weng - arxiv preprint arxiv:2404.17955, 2024 - arxiv.org
In the current software development environment, third-party libraries play a crucial role.
They provide developers with rich functionality and convenient solutions, speeding up the …

Side Benefits of Cybersecurity Measures an Empirical Study

MNE Saulaiman, M Kozlovszky… - 2023 IEEE 21st Jubilee …, 2023 - ieeexplore.ieee.org
Cybersecurity is mostly seen as a necessary evil to protect us from the increasing threat of
hacker attacks. While this is definitely justified in terms of the damage caused, there are also …