How to characterize the health of an Open Source Software project? A snowball literature review of an emerging practice

J Linåker, E Papatheocharous, T Olsson - Proceedings of the 18th …, 2022 - dl.acm.org
Motivation: Society's dependence on Open Source Software (OSS) and the communities that
maintain the OSS is ever-growing. So are the potential risks of, eg, vulnerabilities being …

Software supply chain: review of attacks, risk assessment strategies and security controls

B Gokkaya, L Aniello, B Halak - arxiv preprint arxiv:2305.14157, 2023 - arxiv.org
The software product is a source of cyber-attacks that target organizations by using their
software supply chain as a distribution vector. As the reliance of software projects on open …

Modeling interconnected social and technical risks in open source software ecosystems

W Schueller, J Wachs - Collective intelligence, 2024 - journals.sagepub.com
Open source software ecosystems consist of thousands of interdependent libraries, which
users can combine to great effect. Recent work has pointed out two kinds of risks in these …

The Emerging Artifacts of Centralized Open-Code

MZ Choksi, I Mandel, D Widder… - Proceedings of the 2024 …, 2024 - dl.acm.org
In 2022, generative model based coding assistants became widely available with the public
release of GitHub Copilot. Approaches to generative coding are often critiqued within the …

Free open source communities sustainability: Does it make a difference in software quality?

A Alami, R Pardo, J Linåker - Empirical Software Engineering, 2024 - Springer
Abstract Context Free and Open Source Software (FOSS) communities' ability to stay viable
and productive over time is pivotal for society as they maintain the building blocks that digital …

An Overview and Catalogue of Dependency Challenges in Open Source Software Package Registries

T Mens, A Decan - arxiv preprint arxiv:2409.18884, 2024 - arxiv.org
While open-source software has enabled significant levels of reuse to speed up software
development, it has also given rise to the dreadful dependency hell that all software …

A Toolkit for Measuring the Impacts of Public Funding on Open Source Software Development

C Osborne, P Sharratt, D Foster, M Boehm - arxiv preprint arxiv …, 2024 - arxiv.org
Governments are increasingly employing funding for open source software (OSS)
development as a policy lever to support the security of software supply chains, digital …

A Static Analysis of Popular C Packages in Linux

J Ruohonen, M Saddiqa, K Sierszecki - arxiv preprint arxiv:2409.18530, 2024 - arxiv.org
Static analysis is a classical technique for improving software security and software quality in
general. Fairly recently, a new static analyzer was implemented in the GNU Compiler …

Countering underproduction of peer produced goods

K Champion, BM Hill - New Media & Society, 2024 - journals.sagepub.com
Peer produced goods, such as online knowledge bases and free/libre open source software
rely on contributors who often choose their tasks regardless of consumer needs. These …

Measuring Wikipedia article quality in one dimension by extending ORES with ordinal regression

N TeBlunthuis - Proceedings of the 17th international symposium on …, 2021 - dl.acm.org
Organizing complex peer production projects and advancing scientific knowledge of open
collaboration each depend on the ability to measure quality. Wikipedia community members …