Software Supply Chains

How can software reuse remain trustworthy at ecosystem scale?

Trustworthy reuse requires more than one kind of evidence
Three complementary trust problems sit side by side. Identity and provenance asks who produced an artifact and what evidence follows it. Distribution asks whether the consumer received what they intended. Trust in context asks what authority is warranted for a particular use. Beneath them, cross-cutting work on security properties and failure analysis establishes what those mechanisms need to achieve. The same trust problems recur in pre-trained model, AI agent and research-software ecosystems.

Modern software systems depend on artifacts produced by people and organizations their developers may never meet. Package registries and build systems make reuse inexpensive, but they separate the act of using software from direct knowledge of who produced it, how it reached the consumer, and what authority it should receive once incorporated into a system.

We study the evidence and engineering mechanisms that make trust possible across those boundaries: establishing identity and provenance, protecting the distribution process, and making trust decisions sensitive to the context in which a dependency is actually used. Across these problems, the recurring question is not simply whether software is trusted, but what evidence justifies what trust, for what use.

Understanding software supply-chain security

Before defending a software supply chain, we need to know what a defense is supposed to establish, and where real supply chains actually fail. This cross-cutting work develops models for reasoning about supply-chain security and methods for extracting evidence from failures at ecosystem scale.

Establishing identity and provenance

Software signing can bind an artifact to evidence about its producer and history — but only if the mechanism is adopted, usable, and interpreted correctly. We study what signing and identity establish in practice, why organizations adopt them, and what prevents these mechanisms from becoming routine parts of software development.

Protecting the distribution boundary

Even trustworthy producers and valid artifacts can be defeated by ambiguity in distribution. Package ecosystems use names and metadata to connect developer intent to producers and artifacts; attackers exploit that mapping through typosquatting and package-confusion attacks. We study how those ambiguities can be detected before the wrong dependency enters a system.

Making trust contextual

Provenance is evidence, not a verdict. A valid signature does not establish that its producer is trustworthy, that a dependency is appropriate for a particular system, or that it should receive all of the authority available to its caller. We study how trust decisions can incorporate the context in which software is actually used — and how systems can limit the consequences when that trust is misplaced.

The same trust problems in newer ecosystems

New ecosystems often acquire mechanisms for distributing reusable artifacts before they acquire mature mechanisms for trusting them. Pre-trained models, AI agents, and research software change what is distributed and how it is consumed, but inherit familiar problems of provenance, distribution, authority, and ecosystem governance.

Funding and support

This work has been supported by: