Large Scale Study of Orphan Vulnerabilities in the Software Supply Chain

David Reid, Kristiina Rahkema, James Walden · 2023

The security of the software supply chain has become a critical issue in an era where the majority of software projects use open source software dependencies, exposing them to vulnerabilities in those dependencies. Awareness of this issue has led to the creation of dependency tracking tools that can identify and remediate such vulnerabilities. These tools rely on package manager metadata to identify dependencies, but open source developers often copy dependencies into their repositories manually without the use of a package manager.

Read the paper · More papers on PaperTik