Ändra sökning
RefereraExporteraLänk till posten
Permanent länk

Direktlänk
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annat format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annat språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Policy-Driven Software Bill of Materials on GitHub: An Empirical Study
Blekinge Tekniska Högskola, Fakulteten för datavetenskaper, Institutionen för programvaruteknik.
Blekinge Tekniska Högskola, Fakulteten för datavetenskaper, Institutionen för programvaruteknik.ORCID-id: 0000-0002-0679-4361
Blekinge Tekniska Högskola, Fakulteten för datavetenskaper, Institutionen för programvaruteknik.ORCID-id: 0000-0002-0120-5388
Blekinge Tekniska Högskola, Fakulteten för datavetenskaper, Institutionen för programvaruteknik.ORCID-id: 0000-0003-0619-6027
2026 (Engelska)Ingår i: Product-Focused Software Process Improvement: 26th International Conference, PROFES 2025, Salerno, Italy, December 1–3, 2025, Proceedings / [ed] Scanniello G., Romano S., Francese R., Lenarduzzi V., Vegas S., 2026, s. 253-268Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

Background. The Software Bill of Materials (SBOM) is a machine-readable list of all the software dependencies included in a software. SBOM emerged as way to assist securing the software supply chain. However, despite mandates from governments to use SBOM, research on this artifact is still in its early stages.

Aims. We want to understand the current state of SBOM in open-source projects, focusing specifically on policy-driven SBOMs—i.e., SBOM created to achieve security goals, such as enhancing project transparency and ensuring compliance, rather than being used as fixtures for tools or artificially generated for benchmarking or academic research purposes.

Method. We performed a mining software repository study to collect and carefully select 620 SBOM files hosted on GitHub. We analyzed the information reported in policy-driven SBOMs and the vulnerabilities associated with the declared dependencies by means of descriptive statistics.

Results. We show that only 0.56% of popular GitHub repositories contain policy-driven SBOM. The declared dependencies contain 2,202 unique vulnerabilities, while 22% of them do not report licensing information.

Conclusion. Our findings provide insights for SBOM usage to support security assessment and licensing. 

Ort, förlag, år, upplaga, sidor
2026. s. 253-268
Serie
Lecture Notes in Computer Science, ISSN 0302-9743 ; 16361
Nyckelord [en]
dependencies, open-source, SBOM, software security, Supply chain attacks, vulnerabilities, Network security, Open systems, Supply chains, Bill of materials, Dependency, Empirical studies, Policy driven, Software bill of material, Software dependencies, Supply chain attack, Vulnerability, Open source software
Nationell ämneskategori
Programvaruteknik
Identifikatorer
URN: urn:nbn:se:bth-28990DOI: 10.1007/978-3-032-12089-2_16ISI: 001718768800016Scopus ID: 2-s2.0-105023309206ISBN: 9783032120885 (tryckt)OAI: oai:DiVA.org:bth-28990DiVA, id: diva2:2020987
Konferens
26th International Conference on Product-Focused Software Process Improvement, PROFES 2025, Salerno, Dec 1-3, 2025
Ingår i projekt
SERT- Software Engineering ReThought, KK-stiftelsenSESAM – Secure Software Engineering Through Sensible AutoMation, KK-stiftelsen
Forskningsfinansiär
KK-stiftelsen, 20180010KK-stiftelsen, 20230087Tillgänglig från: 2025-12-12 Skapad: 2025-12-12 Senast uppdaterad: 2026-04-17Bibliografiskt granskad

Open Access i DiVA

Fulltext saknas i DiVA

Övriga länkar

Förlagets fulltextScopus

Person

Novikov, OleksiiFucci, DavideAdamov, OleksandrMendez, Daniel

Sök vidare i DiVA

Av författaren/redaktören
Novikov, OleksiiFucci, DavideAdamov, OleksandrMendez, Daniel
Av organisationen
Institutionen för programvaruteknik
Programvaruteknik

Sök vidare utanför DiVA

GoogleGoogle Scholar

doi
isbn
urn-nbn

Altmetricpoäng

doi
isbn
urn-nbn
Totalt: 107 träffar
RefereraExporteraLänk till posten
Permanent länk

Direktlänk
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annat format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annat språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf