Skip to main navigation Skip to search Skip to main content

"Always Contribute Back": A Qualitative Study on Security Challenges of the Open Source Supply Chain

  • Dominik Wermke*
  • , Jan H. Klemmer
  • , Noah Wöhler
  • , Juliane Schmüser
  • , Harshini Sri Ramulu
  • , Yasemin Acar
  • , Sascha Fahl
  • *Corresponding author for this work

Research output: Chapter in book/report/conference proceedingConference contributionResearchpeer review

Abstract

Open source components are ubiquitous in companies' setups, processes, and software. Utilizing these external components as building blocks enables companies to leverage the benefits of open source software, allowing them to focus their efforts on features and faster delivery instead of writing their own components. But by introducing these components into their software stack, companies inherit unique security challenges and attack surfaces: including code from potentially unvetted contributors and obligations to assess and mitigate the impact of vulnerabilities in external components.In 25 in-depth, semi-structured interviews with software developers, architects, and engineers from industry projects, we investigate their projects' processes, decisions, and considerations in the context of external open source code. We find that open source components play an important role in many of our participants' projects, that most projects have some form of company policy or at least best practice for including external code, and that many developers wish for more developer-hours, dedicated teams, or tools to better audit included components. Based on our findings, we discuss implications for company stakeholders and the open source software ecosystem. Overall, we appeal to companies to not treat the open source ecosystem as a free (software) supply chain and instead to contribute towards the health and security of the overall software ecosystem they benefit from and are part of.

Original languageEnglish
Title of host publication44th IEEE Symposium on Security and Privacy
Subtitle of host publicationSP 2023
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1545-1560
Number of pages16
ISBN (Electronic)9781665493369
DOIs
Publication statusPublished - 2023
Event44th IEEE Symposium on Security and Privacy, SP 2023 - Hybrid, San Francisco, United States
Duration: 22 May 202325 May 2023

Publication series

NameProceedings - IEEE Symposium on Security and Privacy
Volume2023-May
ISSN (Print)1081-6011

Conference

Conference44th IEEE Symposium on Security and Privacy, SP 2023
Country/TerritoryUnited States
CityHybrid, San Francisco
Period22 May 202325 May 2023

Keywords

  • developers
  • interviews
  • open-source
  • supply-chain
  • usable-security

ASJC Scopus subject areas

  • Safety, Risk, Reliability and Quality
  • Software
  • Computer Networks and Communications

Cite this