Debido al alto tráfico generado por robots, aplicamos límites en el número de peticiones permitidas por cliente y bloqueos por IP automáticos. Si haces un uso legítimo y estás teniendo problemas, avísanos para reevaluar nuestras políticas de bloqueo. Disculpa las molestias.

Resumen:
Software Composition Analysis and Supply Chain Security in Apache Projects: an Empirical Study

Cargando...
Miniatura

Editor

Sistedes

Publicado en

Actas de las XXX Jornadas de Ingeniería del Software y Bases de Datos (JISBD 2026)

Licencia Creative Commons

Resumen

A software supply chain consists of anything needed to develop and deliver a software project, including (third-party) components. Software Composition Analysis (SCA) allows for managing the security of software supply chains by identifying such components and their (security) vulnerabilities. The main goal of the empirical study presented in this paper is to investigate the effects of adopting/using over time an SCA tool like OWASP Dependency-Check (OWASP DC) in the context of the security of the software supply chain. To this end, following a cohort design, we analyzed the vulnerabilities affecting the components of the open-source (OS) Java Maven projects owned by the Apache Software Foundation (ASF) and publicly hosted on GitHub. These projects could adopt (or not) OWASP DC. The results indicate that the adoption of OWASP DC appears to be causing a significant reduction in the overall number/score of vulnerabilities, including those with a high Common Vulnerability Scoring System (CVSS) severity level. The use of OWASP DC also increased the vulnerabilities with a low severity level. Our results seem to encourage practitioners to adopt SCA to improve the security of their software supply chains.

Descripción

Acerca de Nocera, Sabato

Palabras clave

Cohort Study, Empirical Study, Software Composition Analysis, Software Supply Chain Security, Software Vulnerabilities

Citación

Nocera, S., Vegas, S., Scanniello, G., Juristo, N.: Software Composition Analysis and Supply Chain Security in Apache Projects: an Empirical Study. In: Cetina, C. (ed.) Actas de las XXX Jornadas de Ingeniería del Software y Bases de Datos (JISBD 2026). Sistedes (2026). https://hdl.handle.net/11705/JISBD/2026/24