What are weak links in the npm supply chain?

Author:

Zahan Nusrat1,Zimmermann Thomas2,Godefroid Patrice2,Murphy Brendan2,Maddila Chandra2,Williams Laurie1

Affiliation:

1. North Carolina State University

2. Microsoft Research

Funder

NCSU Secure Computing Institute

Cisco Systems

Publisher

ACM

Reference46 articles.

1. Bird, Christian, 2009 . Does distributed development affect software quality? an empirical case study of windows vista . In 2009 IEEE 31st International Conference on Software Engineering. IEEE, 518--528 . Bird, Christian, et al. 2009. Does distributed development affect software quality? an empirical case study of windows vista. In 2009 IEEE 31st International Conference on Software Engineering. IEEE, 518--528.

2. Bird, Christian, 2011 . Don't touch my code! Examining the effects of ownership on software quality . In Proceedings of the 19th ACM SIGSOFT symposium and the 13th European conference on Foundations of software engineering. 4--14 . Bird, Christian, et al. 2011. Don't touch my code! Examining the effects of ownership on software quality. In Proceedings of the 19th ACM SIGSOFT symposium and the 13th European conference on Foundations of software engineering. 4--14.

3. Myles Borins. 2022. Top-100 npm package maintainers now require 2FA. https://github.blog/2022-02-01-top-100-npm-package-maintainers-require-2fa-additional-security/ Myles Borins. 2022. Top-100 npm package maintainers now require 2FA. https://github.blog/2022-02-01-top-100-npm-package-maintainers-require-2fa-additional-security/

4. Catalin Cimpanu. 2018. Backdoored Python Library Caught Stealing SSH Credentials. https://www.bleepingcomputer.com/news/security/backdoored-python-library-caught-stealing-ssh-credentials/ Catalin Cimpanu. 2018. Backdoored Python Library Caught Stealing SSH Credentials. https://www.bleepingcomputer.com/news/security/backdoored-python-library-caught-stealing-ssh-credentials/

5. Codecov. 2021. Bash Uploader Security Update. https://about.codecov.io/security-update/ Codecov. 2021. Bash Uploader Security Update. https://about.codecov.io/security-update/

Cited by 28 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. SBOM Ouverture: What We Need and What We Have;Proceedings of the 19th International Conference on Availability, Reliability and Security;2024-07-30

2. Bloat beneath Python’s Scales: A Fine-Grained Inter-Project Dependency Analysis;Proceedings of the ACM on Software Engineering;2024-07-12

3. On the Accuracy of GitHub's Dependency Graph;Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering;2024-06-18

4. Just another copy and paste? Comparing the security vulnerabilities of ChatGPT generated code and StackOverflow answers;2024 IEEE Security and Privacy Workshops (SPW);2024-05-23

5. Weird Machines in Package Managers: A Case Study of Input Language Complexity and Emergent Execution in Software Systems;2024 IEEE Security and Privacy Workshops (SPW);2024-05-23

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3