软件供应链已死:面向用例的再生
Software Supply Chains are Dead: Use-Case-Oriented Regeneration
AI总结:
研究现代软件开发中构建与复用权衡因软件供应链攻击及生成式人工智能而改变,提出面向用例的再生范式,评估智能工作流程,通过对180个存储库-依赖对测量,证明该方法可行,推动软件采购向可验证的特定于存储库的代码合成发展。
AI中文摘要:
现代软件开发依赖一个越来越可疑的前提:采用依赖所节省的前期实施成本超过维护成本。软件供应链攻击增加了外部依赖成本,而生成式人工智能降低了本地实施成本,这两个变化正在重塑构建与复用的权衡。我们设想面向用例的再生作为一种新的软件采购范式,将供应链从外部信任转变为本地验证。我们评估了一种智能工作流程,该流程仅合成存储库使用的特定依赖功能切片。我们对180个存储库-依赖对的测量表明,这种方法是可行的:替换在基线验证检查中保留了99.8%的存储库观察到的行为,并将导出的API表面减少了93%。软件采购可能会朝着可验证的特定于存储库的代码合成发展,特别是当所需功能狭窄、稳定且经过充分测试时。
英文摘要:
Modern software development relies on an increasingly doubtful premise: that the up-front implementation savings from adopting a dependency outweighs the maintenance costs. Two changes are reshaping the build-vs.-reuse calculus: software supply chain attacks have raised the cost of external reliance, while generative AI has lowered the cost of local implementation. We envision use-case-oriented regeneration as a new software sourcing paradigm that shifts the supply chain from external trust to local verification. We evaluate an agentic workflow that synthesizes only the specific slice of dependency functionality that a repository exercises. Our measurements across 180 repository-dependency pairs suggest that this approach is feasible: the replacements preserve 99.8% of repository-observed behavior across baseline validation checks and reduce the exported API surface by 93%. Software sourcing may evolve toward verifiable repository-specific code synthesis, especially when the required functionality is narrow, stable, and well tested.