Understanding vulnerabilities in software supply chains

Yijun Shen,Xiang Gao,Hailong Sun,Yu Guo
DOI: https://doi.org/10.1007/s10664-024-10581-2
IF: 3.762
2024-11-08
Empirical Software Engineering
Abstract:Due to the dependency relations among software, vulnerabilities in software supply chains (SSC) may cause more serious security threats than independent software systems. This poses new challenges for ensuring software security including the spread of risks and the increase in maintenance costs.
computer science, software engineering
What problem does this paper attempt to address?