March 27, 2024, 4:11 a.m. | Imranur Rahman, Nusrat Zahan, Stephen Magill, William Enck, Laurie Williams

cs.CR updates on arXiv.org arxiv.org

arXiv:2403.17382v1 Announce Type: cross
Abstract: Keeping dependencies up-to-date prevents software supply chain attacks through outdated and vulnerable dependencies. Developers may use packages' dependency update practice as one of the selection criteria for choosing a package as a dependency. However, the lack of metrics characterizing packages' dependency update practice makes this assessment difficult. To measure the up-to-date characteristics of packages, we focus on the dependency management aspect and propose two update metrics: Time-Out-Of-Date (TOOD) and Post-Fix-Exposure-Time (PFET), to measure the updatedness …

arxiv attacks cargo cs.cr cs.se date dependencies dependency developers may metrics npm package packages practice pypi software software supply chain software supply chain attacks supply supply chain supply chain attacks update up-to-date vulnerable

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC