Ecosystem-scale measurement shows commit signing on GitHub is rarely deliberate or sustained by developers, with rising lapse rates and unrevoked expired keys, so supply-chain security frameworks relying on it do not hold in practice.
Research directions in software supply chain security
6 Pith papers cite this work. Polarity classification is still indexing.
citation-role summary
citation-polarity summary
representative citing papers
Malicious Skills induce coding agents to hallucinate and import attacker-controlled packages at high rates while evading detection.
A taxonomy of GitHub abuse behaviors is proposed along with a detection framework achieving F1-scores exceeding 89% on a manually labeled dataset of 392 instances.
The paper shows that heterogeneous graph attention networks can classify vulnerable components in real SBOMs at 91% accuracy and that a simple MLP can predict documented multi-vulnerability chains with 0.93 ROC-AUC.
Presents a framework for generating cryptographically signed CSAF VEX advisories for agentic AI by binding SBOM/AIBOM artifacts to deterministic environment capture and runtime telemetry.
citing papers explorer
-
Analysis of Commit Signing on Github
Ecosystem-scale measurement shows commit signing on GitHub is rarely deliberate or sustained by developers, with rising lapse rates and unrevoked expired keys, so supply-chain security frameworks relying on it do not hold in practice.
-
Weaponizing the Commons: A Taxonomy and Detection Framework of Abuse on GitHub
A taxonomy of GitHub abuse behaviors is proposed along with a detection framework achieving F1-scores exceeding 89% on a manually labeled dataset of 392 instances.
-
Towards Predicting Multi-Vulnerability Attack Chains in Software Supply Chains from Software Bill of Materials Graphs
The paper shows that heterogeneous graph attention networks can classify vulnerable components in real SBOMs at 91% accuracy and that a simple MLP can predict documented multi-vulnerability chains with 0.93 ROC-AUC.
-
Execution-bound advisory automation for agentic AI: a reproducible AIBOM-driven CSAF-VEX framework
Presents a framework for generating cryptographically signed CSAF VEX advisories for agentic AI by binding SBOM/AIBOM artifacts to deterministic environment capture and runtime telemetry.
- Classport: Designing Runtime Dependency Introspection for Java