A Literature Survey on Pitfalls of Open-Source Dependency Management in Enterprise

Andrey Kharitonov, Amro Abdalla, Abdulrahman Nahhas, Daniel Staegemann, Christian Haertel, Christian Daase, Klaus Turowski

2024

Abstract

Open-source dependencies are an integral part of the modern enterprise software development process for numerous technology stacks. Often, these dependencies are distributed through public repositories located outside of the secure corporate environment, which introduces numerous challenges in ensuring the security, compliance, and maintainability of the developed software. In this work, we conduct a systematic literature review focused on the pitfalls of relying on open-source dependencies. We discovered 23 relevant publications between 2016 and the beginning of 2024 pointing out that supply chain attacks, outdated or abandoned dependencies, licensing issues, security vulnerabilities, as well as reliance on trivial packages and complex dependency trees are mentioned in the analyzed literature as significant challenges. Among the ways to tackle these, it is commonly suggested in the literature to use scanning tools to ensure security, consciously select the used dependencies, document, and keep track of the open-source dependencies used in software projects. Maintaining up-to-date dependencies and actively contributing to the development of the open-source project is encouraged.

Download


Paper Citation


in Harvard Style

Kharitonov A., Abdalla A., Nahhas A., Staegemann D., Haertel C., Daase C. and Turowski K. (2024). A Literature Survey on Pitfalls of Open-Source Dependency Management in Enterprise. In Proceedings of the 19th International Conference on Software Technologies - Volume 1: ICSOFT; ISBN 978-989-758-706-1, SciTePress, pages 15-22. DOI: 10.5220/0012710800003753


in Bibtex Style

@conference{icsoft24,
author={Andrey Kharitonov and Amro Abdalla and Abdulrahman Nahhas and Daniel Staegemann and Christian Haertel and Christian Daase and Klaus Turowski},
title={A Literature Survey on Pitfalls of Open-Source Dependency Management in Enterprise},
booktitle={Proceedings of the 19th International Conference on Software Technologies - Volume 1: ICSOFT},
year={2024},
pages={15-22},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0012710800003753},
isbn={978-989-758-706-1},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 19th International Conference on Software Technologies - Volume 1: ICSOFT
TI - A Literature Survey on Pitfalls of Open-Source Dependency Management in Enterprise
SN - 978-989-758-706-1
AU - Kharitonov A.
AU - Abdalla A.
AU - Nahhas A.
AU - Staegemann D.
AU - Haertel C.
AU - Daase C.
AU - Turowski K.
PY - 2024
SP - 15
EP - 22
DO - 10.5220/0012710800003753
PB - SciTePress