Evaluating Security and Community Health Metrics of FOSS Repositories

Niraj Salvi -, Amal Thundiyil -, Seema Supe -, Nataasha Raul · International Journal For Multidisciplinary Research · 2024

The extensive use of open-source packages in software development has greatly increased output and effectiveness. However, this development presents a challenging security environment in which vulnerabilities found in these packages can spread to other projects. To address this challenge, we suggest creating an open-source security assessment tool that has been painstakingly designed. The purpose of this tool is to assess security risks related to third-party dependencies and packages that are available on npm and GitHub. Concerns are raised by the lack of a thorough assessment because seemingly innocuous packages could be hiding vulnerabilities that could lead to significant financial losses, service interruptions, and data breaches. Within the dynamic realm of open-source packages, developers often struggle to stay up to date with the ever changing security landscape. The main difficulty with this problem is figuring out which secure packages are kept up to date and which are either showing signs of poor maintenance or contain latent vulnerabilities. Therefore, it becomes necessary to have a methodical, data-driven security evaluation tool so that developers can make informed choices about which packages to install. This project uses a wide range of parameters in an attempt to meet this requirement. These parameters allow for a quantitative evaluation of a package's security posture. They include metrics like stars, forks, resolved issues, and community engagement. Our project aims to strengthen software security measures and mitigate potential risks associated with using third-party packages by giving developers actionable insights into the security status of their dependencies.

Read the paper · More papers on PaperTik