Communities
Connect sessions
AI calendar
Organizations
Join Slack
Contact Sales
Search
Open menu
Home
Papers
2208.03412
Cited By
v1
v2
v3
v4 (latest)
OpenSSF Scorecard: On the Path Toward Ecosystem-wide Automated Security Metrics
IEEE Security and Privacy (IEEE S&P), 2022
6 August 2022
Nusrat Zahan
Parth Kanakiya
Brian Hambleton
S. Shohan
Laurie A. Williams
Re-assign community
ArXiv (abs)
PDF
HTML
Github (5374★)
Papers citing
"OpenSSF Scorecard: On the Path Toward Ecosystem-wide Automated Security Metrics"
12 / 12 papers shown
An LLM-based Quantitative Framework for Evaluating High-Stealthy Backdoor Risks in OSS Supply Chains
Zihe Yan
Kai Luo
Haoyu Yang
Yang Yu
Zhuosheng Zhang
Guancheng Li
116
0
0
17 Nov 2025
Which Is Better For Reducing Outdated and Vulnerable Dependencies: Pinning or Floating?
Imranur Rahman
Jill Marley
William Enck
Laurie A. Williams
91
1
0
07 Oct 2025
Establishing a Baseline of Software Supply Chain Security Task Adoption by Software Organizations
Laurie Williams
Sammy Migues
131
0
0
09 Sep 2025
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
Kelechi G. Kalu
Sofia Okorafor
Betül Durak
Kim Laine
R. C. Moreno
Santiago Torres-Arias
James C. Davis
207
3
0
24 May 2025
LibVulnWatch: A Deep Assessment Agent System and Leaderboard for Uncovering Hidden Vulnerabilities in Open-Source AI Libraries
Zekun Wu
Seonglae Cho
U. Mohammed
Cristian Muñoz
Kleyton Costa
Xin Guan
Theo King
Ze Wang
Emre Kazim
Adriano Soares Koshiyama
ELM
344
2
0
13 May 2025
Assumptions to Evidence: Evaluating Security Practices Adoption and Their Impact on Outcomes in the npm Ecosystem
Nusrat Zahan
Imranur Rahman
Laurie A. Williams
199
0
0
18 Apr 2025
Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ Utils
Sivana Hamer
Jacob Bowen
Md Nazmul Haque
Robert Hines
Chris Madden
Laurie A. Williams
361
8
0
15 Mar 2025
Pinning Is Futile: You Need More Than Local Dependency Versioning to Defend against Supply Chain Attacks
Hao He
Bogdan Vasilescu
Jane Hsieh
158
8
0
10 Feb 2025
Six Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware
Hao He
Haoqin Yang
Philipp Burckhardt
A. Kapravelos
Bogdan Vasilescu
Jane Hsieh
406
6
0
18 Dec 2024
An Industry Interview Study of Software Signing for Supply Chain Security
Kelechi G. Kalu
Tanya Singla
C. Okafor
Santiago Torres-Arias
James C. Davis
448
16
0
12 Jun 2024
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
IEEE Symposium on Security and Privacy (S&P), 2024
Taylor R. Schorlemmer
Kelechi G. Kalu
Luke Chigges
Kyung Myung Ko
Eman Abdul-Muhd Abu Isghair
Saurabh Baghi
Santiago Torres-Arias
James C. Davis
298
16
0
26 Jan 2024
Do Software Security Practices Yield Fewer Vulnerabilities?
Nusrat Zahan
S. Shohan
Dan Harris
Laurie A. Williams
285
25
0
20 Oct 2022
1
Page 1 of 1