Pith. sign in

REVIEW 1 cited by

What is Software Supply Chain Security?

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2209.04006 v1 pith:DS6TMDKM submitted 2022-09-08 cs.CR cs.SE

classification cs.CRcs.SE
keywords securitysoftwarechainsolutionssupplygoalsholisticprocesses
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

The software supply chain involves a multitude of tools and processes that enable software developers to write, build, and ship applications. Recently, security compromises of tools or processes has led to a surge in proposals to address these issues. However, these proposals commonly overemphasize specific solutions or conflate goals, resulting in unexpected consequences, or unclear positioning and usage. In this paper, we make the case that developing practical solutions is not possible until the community has a holistic view of the security problem; this view must include both the technical and procedural aspects. To this end, we examine three use cases to identify common security goals, and present a goal-oriented taxonomy of existing solutions demonstrating a holistic overview of software supply chain security.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Integrating Artificial Open Generative Artificial Intelligence into Software Supply Chain Security

    cs.CR 2024-12 reject novelty 2.0 of 10

    An under-specified evaluation of five open LLMs on vulnerability and deprecated-code detection reports moderate average scores (60.4 to 67.0) but lacks baselines, data, and reproducibility.

Pith tools