loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Authors: Andrey Kharitonov ; Amro Abdalla ; Abdulrahman Nahhas ; Daniel Staegemann ; Christian Haertel ; Christian Daase and Klaus Turowski

Affiliation: Otto von Guericke University Magdeburg, Universitätsplatz 2, 39106 Magdeburg, Germany

Keyword(s): Open-Source Dependencies, Enterprise Software Development, Dependency Management, Software Dependencies

Abstract: Open-source dependencies are an integral part of the modern enterprise software development process for numerous technology stacks. Often, these dependencies are distributed through public repositories located outside of the secure corporate environment, which introduces numerous challenges in ensuring the security, compliance, and maintainability of the developed software. In this work, we conduct a systematic literature review focused on the pitfalls of relying on open-source dependencies. We discovered 23 relevant publications between 2016 and the beginning of 2024 pointing out that supply chain attacks, outdated or abandoned dependencies, licensing issues, security vulnerabilities, as well as reliance on trivial packages and complex dependency trees are mentioned in the analyzed literature as significant challenges. Among the ways to tackle these, it is commonly suggested in the literature to use scanning tools to ensure security, consciously select the used dependencies, documen t, and keep track of the open-source dependencies used in software projects. Maintaining up-to-date dependencies and actively contributing to the development of the open-source project is encouraged. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.144.12.246

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Kharitonov, A.; Abdalla, A.; Nahhas, A.; Staegemann, D.; Haertel, C.; Daase, C. and Turowski, K. (2024). A Literature Survey on Pitfalls of Open-Source Dependency Management in Enterprise. In Proceedings of the 19th International Conference on Software Technologies - ICSOFT; ISBN 978-989-758-706-1; ISSN 2184-2833, SciTePress, pages 15-22. DOI: 10.5220/0012710800003753

@conference{icsoft24,
author={Andrey Kharitonov. and Amro Abdalla. and Abdulrahman Nahhas. and Daniel Staegemann. and Christian Haertel. and Christian Daase. and Klaus Turowski.},
title={A Literature Survey on Pitfalls of Open-Source Dependency Management in Enterprise},
booktitle={Proceedings of the 19th International Conference on Software Technologies - ICSOFT},
year={2024},
pages={15-22},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0012710800003753},
isbn={978-989-758-706-1},
issn={2184-2833},
}

TY - CONF

JO - Proceedings of the 19th International Conference on Software Technologies - ICSOFT
TI - A Literature Survey on Pitfalls of Open-Source Dependency Management in Enterprise
SN - 978-989-758-706-1
IS - 2184-2833
AU - Kharitonov, A.
AU - Abdalla, A.
AU - Nahhas, A.
AU - Staegemann, D.
AU - Haertel, C.
AU - Daase, C.
AU - Turowski, K.
PY - 2024
SP - 15
EP - 22
DO - 10.5220/0012710800003753
PB - SciTePress