Pith. sign in

REVIEW 2 cited by

Taxonomy of Attacks on Open-Source Software Supply Chains

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2204.04008 v2 pith:TFJ4CXMY submitted 2022-04-08 cs.CR cs.SE

classification cs.CRcs.SE
keywords open-sourcesupplyattackschainssoftwaretaxonomyattackcode
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

The widespread dependency on open-source software makes it a fruitful target for malicious actors, as demonstrated by recurring attacks. The complexity of today's open-source supply chains results in a significant attack surface, giving attackers numerous opportunities to reach the goal of injecting malicious code into open-source artifacts that is then downloaded and executed by victims. This work proposes a general taxonomy for attacks on open-source supply chains, independent of specific programming languages or ecosystems, and covering all supply chain stages from code contributions to package distribution. Taking the form of an attack tree, it covers 107 unique vectors, linked to 94 real-world incidents, and mapped to 33 mitigating safeguards. User surveys conducted with 17 domain experts and 134 software developers positively validated the correctness, comprehensiveness and comprehensibility of the taxonomy, as well as its suitability for various use-cases. Survey participants also assessed the utility and costs of the identified safeguards, and whether they are used.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. OpenAlex reports about 15 citations worldwide. Full citation record

  1. No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild

    cs.SE 2026-07 conditional novelty 7.0 of 10

    Over half of published SBOMs declare no dependency graph; a degeneracy-aware 'unknown' reachability semantics recovered KEV recall from 0.600 to 0.950 in one production system.

  2. Which Is Better For Reducing Outdated and Vulnerable Dependencies: Pinning or Floating?

    cs.SE 2025-10 conditional novelty 5.0 of 10

    Across three package ecosystems, floating version constraints are less likely than pinning to leave dependencies outdated, while the claim that floating-minor is least vulnerability-prone is the main genuinely empiric...

Pith tools