首页> 外文会议>IEEE/ACM International Conference on Software Engineering: Software Engineering in Practice >Enterprise-Driven Open Source Software: A Case Study on Security Automation
【24h】

Enterprise-Driven Open Source Software: A Case Study on Security Automation

机译:企业驱动的开源软件:安全自动化案例研究

获取原文

摘要

Agile and DevOps are widely adopted by the industry. Hence, integrating security activities with industrial practices, such as continuous integration (CI) pipelines, is necessary to detect security flaws and adhere to regulators’ demands early. In this paper, we analyze automated security activities in CI pipelines of enterprise-driven open source software (OSS). This shall allow us, in the long-run, to better understand the extent to which security activities are (or should be) part of automated pipelines. In particular, we mine publicly available OSS repositories and survey a sample of project maintainers to better understand the role that security activities and their related tools play in their CI pipelines. To increase transparency and allow other researchers to replicate our study (and to take different perspectives), we further disclose our research artefacts.Our results indicate that security activities in enterprise-driven OSS projects are scarce and protection coverage is rather low. Only 6.83% of the analyzed 8,243 projects apply security automation in their CI pipelines, even though maintainers consider security to be rather important. This alerts industry to keep the focus on vulnerabilities of 3rd Party software and it opens space for other improvements of practice which we outline in this manuscript.
机译:敏捷和Devops被行业被广泛采用。因此,必须将安全活动与工业实践相结合,例如持续集成(CI)管道,是检测安全缺陷,并遵守监管​​机构的需求。在本文中,我们分析了企业驱动的开源软件(OSS)的CI管道中的自动安全活动。这将使我们长期允许我们更好地了解安全活动的程度(或应该是)自动化管道的一部分。特别是,我们挖掘了公开的OSS存储库并调查了一个项目维护者的样本,以更好地了解安全活动和相关工具在其CI管道中的作用。为了提高透明度并允许其他研究人员复制我们的研究(并采取不同的观点),我们进一步披露了我们的研究人工制品。我们的结果表明企业驱动的OSS项目中的安全活动稀缺,保护覆盖率相当低。只有6.83%的分析的8,243个项目在他们的CI管道中应用安全自动化,即使保持者认为安全性相当重要。这一警告行业将重点关注第三方软件的漏洞,并为我们在此手稿中概述的其他实践的空间。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号