2025/05/24 by Kelechi G. Kalu, Kalu, Kelechi G., Sofia Okorafor +11 · 1 citation
Business, Management and Accounting · Computer Science · #Big Data and Business Intelligence #Business Process Modeling and Analysis #Cloud Computing and Resource Management #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Software Engineering (cs.SE)
paper · pdf · doi:10.48550/arxiv.2505.18760
openalex publication_date 2025/05/24 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Many critical information technology and cyber-physical systems rely on a supply chain of open-source software projects. OSS project maintainers often integrate contributions from external actors. While maintainers can assess the correctness of a pull request, assessing a pull request's cybersecurity implications is challenging. To help maintainers make this decision, we propose that the open-source ecosystem should incorporate Actor Reputation Metrics (ARMS). This capability would enable OSS maintainers to assess a prospective contributor's cybersecurity reputation. To support the future instantiation of ARMS, we identify seven generic security signals from industry standards; map concrete metrics from prior work and available security tools, describe study designs to refine and assess the utility of ARMS, and finally weigh its pros and cons.