Debido al alto tráfico generado por robots, aplicamos límites en el número de peticiones permitidas por cliente y bloqueos por IP automáticos. Si haces un uso legítimo y estás teniendo problemas, avísanos para reevaluar nuestras políticas de bloqueo. Disculpa las molestias.

Resumen:
Software Composition Analysis and Supply Chain Security in Apache Projects: an Empirical Study

bs.conference.acronymJISBD
bs.conference.nameJornadas de Ingeniería del Software y Bases de Datos (2026)
bs.edition.date2026-06-16
bs.edition.locationAlicante
bs.edition.nameXXX Jornadas de Ingeniería del Software y Bases de Datos (JISBD 2026)
bs.proceedings.editorCetina, C.
bs.proceedings.nameActas de las XXX Jornadas de Ingeniería del Software y Bases de Datos (JISBD 2026)
dc.contributor.affiliationUniversity of Salerno, Italy
dc.contributor.affiliationUniversidad Politécnica de Madrid, Spain
dc.contributor.affiliationUniversity of Salerno, Italy
dc.contributor.affiliationUniversidad Politécnica de Madrid, Spain
dc.contributor.authorNocera, Sabato
dc.contributor.authorVegas, Sira
dc.contributor.authorScanniello, Giuseppe
dc.contributor.authorJuristo, Natalia
dc.contributor.emailsnocera@unisa.it
dc.contributor.emailsvegas@fi.upm.es
dc.contributor.emailgscanniello@unisa.it
dc.contributor.emailnatalia@fi.upm.es
dc.contributor.signatureNocera, Sabato
dc.contributor.signatureVegas, Sira
dc.contributor.signatureScanniello, Giuseppe
dc.contributor.signatureJuristo, Natalia
dc.date.accessioned2026-05-30T19:44:45Z
dc.date.issued2026-06-16
dc.description.abstractA software supply chain consists of anything needed to develop and deliver a software project, including (third-party) components. Software Composition Analysis (SCA) allows for managing the security of software supply chains by identifying such components and their (security) vulnerabilities. The main goal of the empirical study presented in this paper is to investigate the effects of adopting/using over time an SCA tool like OWASP Dependency-Check (OWASP DC) in the context of the security of the software supply chain. To this end, following a cohort design, we analyzed the vulnerabilities affecting the components of the open-source (OS) Java Maven projects owned by the Apache Software Foundation (ASF) and publicly hosted on GitHub. These projects could adopt (or not) OWASP DC. The results indicate that the adoption of OWASP DC appears to be causing a significant reduction in the overall number/score of vulnerabilities, including those with a high Common Vulnerability Scoring System (CVSS) severity level. The use of OWASP DC also increased the vulnerabilities with a low severity level. Our results seem to encourage practitioners to adopt SCA to improve the security of their software supply chains.
dc.identifier.citationNocera, S., Vegas, S., Scanniello, G., Juristo, N.: Software Composition Analysis and Supply Chain Security in Apache Projects: an Empirical Study. In: Cetina, C. (ed.) Actas de las XXX Jornadas de Ingeniería del Software y Bases de Datos (JISBD 2026). Sistedes (2026). https://hdl.handle.net/11705/JISBD/2026/24
dc.identifier.citation-bibtex@inproceedings{11705:JISBD:2026:24, title = {{Software Composition Analysis and Supply Chain Security in Apache Projects: an Empirical Study}}, author = {Nocera, S. and Vegas, S. and Scanniello, G. and Juristo, N.}, url = {https://hdl.handle.net/11705/JISBD/2026/24}, crossref = {11705:JISBD:2026} } @proceedings{11705:JISBD:2026, title = {{Actas de las XXX Jornadas de Ingenier\'{i}a del Software y Bases de Datos (JISBD 2026)}}, author = {Cetina, C.}, year = {2026}, publisher = {{Sistedes}}, }
dc.identifier.sistedes11705/JISBD/2026/24
dc.identifier.urihttps://hdl.handle.net/11705/3964
dc.publisherSistedes
dc.relation.ispartofActas de las XXX Jornadas de Ingeniería del Software y Bases de Datos (JISBD 2026)
dc.rights.licenseCC BY-NC-ND 4.0
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectCohort Study
dc.subjectEmpirical Study
dc.subjectSoftware Composition Analysis
dc.subjectSoftware Supply Chain Security
dc.subjectSoftware Vulnerabilities
dc.titleSoftware Composition Analysis and Supply Chain Security in Apache Projects: an Empirical Study
dspace.entity.typeResumen
relation.isAuthorOfAbstract4a4ac33e-ee72-44fd-8113-e4d964cf62ff
relation.isAuthorOfAbstract60dcf190-8ec1-4879-9c63-3d418e852d71
relation.isAuthorOfAbstractc133a2ce-3c17-48b8-84d0-c5853fc709ab
relation.isAuthorOfAbstract5f6fb1e0-164c-413e-ad2b-36216bf3221b
relation.isAuthorOfAbstract.latestForDiscovery4a4ac33e-ee72-44fd-8113-e4d964cf62ff

Archivos

Bloque original

Mostrando 1 - 1 de 1
Cargando...
Miniatura
Nombre:
11705-JISBD-2026-24.pdf
Tamaño:
146.92 KB
Formato:
Adobe Portable Document Format