Authors:
Andrey Kharitonov
;
Amro Abdalla
;
Abdulrahman Nahhas
;
Daniel Staegemann
;
Christian Haertel
;
Christian Daase
and
Klaus Turowski
Affiliation:
Otto von Guericke University Magdeburg, Universitätsplatz 2, 39106 Magdeburg, Germany
Keyword(s):
Open-Source Dependencies, Enterprise Software Development, Dependency Management, Software Dependencies
Abstract:
Open-source dependencies are an integral part of the modern enterprise software development process for numerous technology stacks. Often, these dependencies are distributed through public repositories located outside of the secure corporate environment, which introduces numerous challenges in ensuring the security, compliance, and maintainability of the developed software. In this work, we conduct a systematic literature review focused on the pitfalls of relying on open-source dependencies. We discovered 23 relevant publications between 2016 and the beginning of 2024 pointing out that supply chain attacks, outdated or abandoned dependencies, licensing issues, security vulnerabilities, as well as reliance on trivial packages and complex dependency trees are mentioned in the analyzed literature as significant challenges. Among the ways to tackle these, it is commonly suggested in the literature to use scanning tools to ensure security, consciously select the used dependencies, documen
t, and keep track of the open-source dependencies used in software projects. Maintaining up-to-date dependencies and actively contributing to the development of the open-source project is encouraged.
(More)