Software Supply Chains

How can software reuse remain trustworthy at ecosystem scale?

Modern software systems depend on components produced by people and organizations their developers may never meet. Package registries and build systems make that reuse inexpensive, but they also leave developers to decide which producers and artifacts to trust.

We study the evidence available for those decisions. Some of our work examines identity, software signing, and provenance; other work studies whether developers can use those mechanisms effectively, how they assess dependencies, and how attackers exploit gaps in the distribution process.

Research

Signing can establish who vouched for an artifact. A valid signature does not tell a developer whether that producer is trustworthy, or whether the dependency is appropriate in a particular system. We therefore study both the mechanisms that carry evidence and the decisions developers make from it.

On the mechanism side, we have measured signing across public package registries and examined what identity-based signing establishes in practice. On the decision side, we have interviewed practitioners about why signing is or is not adopted, studied how developers choose dependencies, and shown how naming and metadata become an attack surface when an ecosystem assumes that a familiar package name identifies a familiar producer.

Evidence attaches to different edges: identity to the producer, provenance and signatures to the artifact, policy to the consuming system. Signing establishes one edge; whether the accumulated evidence suffices is decide
Evidence attaches to different edges: identity to the producer, provenance and signatures to the artifact, policy to the consuming system. Signing establishes one edge; whether the accumulated evidence suffices is decided in context.

Applications

The same questions recur wherever software is assembled from artifacts produced elsewhere, and the newer ecosystems inherit the problem before they inherit the defences.

Pre-trained models are distributed through registries much like packages, and a model file can execute code when it is loaded. Research software has supply chains of its own, with different incentives and less tooling. Agent ecosystems are beginning to distribute executable capability in the same way.

2026
ICSE Journal Ahead Workshop (JAWs)
Agent ecosystems are beginning to distribute executable capability, and they inherit the registry trust problem before they inherit its defences.
2025
Proceedings of the 32nd ACM Conference on Computer and Communications Security (CCS)
A model file that executes code when loaded is an attack surface, and model repositories distribute those files the way registries distribute packages.

Publications

2026
Proceedings of the 35th USENIX Security Symposium (SECURITY)
A usability study of Sigstore adoption. Identity-based signing removes the key-management problem and introduces others.
Proceedings of the 48th IEEE/ACM International Conference on Software Engineering (ICSE)
ConfuGuard detects package confusion from metadata, treating a familiar package name as evidence that can be forged.
ICSE Journal Ahead Workshop (JAWs)
Maintainers can review a pull request for correctness but not for the trustworthiness of its author; ARMS proposes reputation as the missing signal.
ICSE Journal Ahead Workshop (JAWs)
Dependency decision-making has no benchmark, so competing approaches cannot be compared. This proposes one.
ICSE Journal Ahead Workshop (JAWs)
Research software has a supply chain with different incentives and far less tooling than industry's.
arXiv
Follows identity-based signing usability over time rather than at one moment, which is where adoption problems become visible.
2025
Proceedings of the ACM/IEEE 47th International Conference on Software Engineering (ICSE)
ZTD-JAVA moves the trust decision to the point of use: a library gets the permissions its call site needs, not those of the whole application.
Proceedings of the 34th USENIX Security Symposium (SECURITY)
Interviewed industry practitioners about signing. Found that the obstacles are organizational as often as technical.
IEEE Security & Privacy Magazine -- Special Issue 'Secure Software Before Codeing'
States the provenance-before-coding argument for a practitioner audience.
2024
Proceedings of the 45th IEEE Symposium on Security and Privacy (S&P)
Measured signing across four public registries. Established how rare and how poor-quality signing actually was, against which later adoption work reads.
2023
Proceedings of the 2nd ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED)
Tests whether language models can analyze supply-chain failures at the scale the evidence actually exists.
2022
Proceedings of the 1st ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED)
Systematized the field around three properties — transparency, validity, separation — giving later work a vocabulary for what a defence establishes.
In preparation
Context-Aware Trust Verification for Identity-Based Software Signing
Verification that accounts for context: what a signature means depends on what is being installed where.

Funding and support

This work has been supported by:

US National Science Foundation
Collaborative Research: Planning: CROSS: Building a Community aROund Securing the Research Software Supply Chain (#2537308)
Socket, Inc.
Unrestricted Gift: Typosquat Detection in Open-Source Ecosystems
Google, LLC
Unrestricted Gift: Improving OSS Supply Chain Security by Promoting Software Signing
US National Science Foundation
POSE: Phase I: Scoping An Open-Source Ecosystem Around Proactive Software Supply Chain Monitoring (#2229703)
Cisco
Monitor and manage security risks in software supply chains with Sigstore