Åpne denne publikasjonen i ny fane eller vindu >>Vise andre…
2023 (engelsk)Inngår i: SCORED 2023 - Proceedings of the 2023 Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses, Association for Computing Machinery (ACM) , 2023, s. 75-76Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]
Modern software applications are virtually never built entirely in-house. As a matter of fact, they reuse many third-party dependencies, which form the core of their software supply chain [1]. The large number of dependencies in an application has turned into a major challenge for both security and reliability. For example, to compromise a high-value application, malicious actors can choose to attack a less well-guarded dependency of the project [2]. Even when there is no malicious intent, bugs can propagate through the software supply chain and cause breakages in applications. Gathering accurate, upto- date information about all dependencies included in an application is, therefore, of vital importance.
sted, utgiver, år, opplag, sider
Association for Computing Machinery (ACM), 2023
Emneord
sbom, software supply chain
HSV kategori
Identifikatorer
urn:nbn:se:kth:diva-341683 (URN)10.1145/3605770.3625207 (DOI)001123143300012 ()2-s2.0-85180010428 (Scopus ID)
Konferanse
2nd Edition of the ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses, SCORED 2023, Copenhagen, Denmark, Nov 30 2023
Forskningsfinansiär
Swedish Foundation for Strategic Research, chains
Merknad
Part of proceedings ISBN 9798400702631
QC 20231229
2023-12-292023-12-292024-09-30bibliografisk kontrollert