DCI:用于评估开源依赖可信度的依赖置信指数
DCI: Dependency Confidence Index for Assessing Open-Source Dependency Trustworthiness
浏览论文内容
中文总结 AI 辅助
针对软件供应链安全中开源依赖选择的挑战,提出DCI复合指数,结合9个信任因子实现自动化评估,经92个PyPI包验证,与现有工具互补,为相关研究和审计提供基础。
中文摘要 AI 辅助
选择可信的开源软件依赖项仍然是软件供应链安全中的一个主要挑战。我们提出了依赖置信指数(Dependency Confidence Index,简称DCI),这是一种复合形成指数,将9个经经验加权的信任因子组合为单一归一化复合得分,用于依赖项选择。DCI的信任因子结合了系统文献综述的见解以及对10名软件开发者进行的探索性层次分析法(Analytic Hierarchy Process,简称AHP)调查的结果,强调安全性、源代码质量和项目健康是最具影响力的维度。遵循目标-问题-度量(Goal-Question-Metric)方法,我们使用SonarQube、GitHub API和OpenSSF Scorecard数据实现了12项自动化度量,并部署在容器化评估平台中。我们对92个流行的PyPI包进行了归一化DCI的试点评估,观察到其与OpenSSF Scorecard得分存在中等一致性,且具有完美的重测信度。分析显示,基于流程的因子(依赖管理、CI)在高质量包的得分中占主导地位,而安全指标达到饱和,表明DCI对现有工具具有补充作用。我们公开可用的实现为开源软件可信度研究和实际依赖项审计提供了基础。
英文摘要
Selecting trustworthy open source software dependencies remains a major challenge in software supply chain security. We present the Dependency Confidence Index (DCI), a composite formative index that combines nine empirically weighted trust factors into a single normalized composite score for dependency selection. DCI's trust factors combine insights from a systematic literature review and an exploratory Analytic Hierarchy Process (AHP) survey of ten software developers, highlighting security, source code quality, and project health as the most influential dimensions. Following Goal-Question-Metric methodology, we implemented 12 automated measurements using SonarQube, GitHub APIs, and OpenSSF Scorecard data, deployed in a containerized evaluation platform. We conducted a pilot evaluation of the normalized DCI on 92 popular PyPI packages, observing moderate agreement with OpenSSF Scorecard scores and perfect test--retest reliability. Analysis reveals process-based factors (dependency management, CI) dominate scores on high-quality packages, while security metrics saturate---suggesting DCI's complementary role to existing tools. Our publicly available implementation provides a foundation for open source software trustworthiness research and practical dependency auditing.