Designing SocialTrust.md to Enhance Developer Awareness of Risks in Utilizing Open-Source GitHub Repositories
Tony W. Li, Yunpeng Zhao, Yujin Zhang, R. Stuart Geiger, Haojian Jin
Abstract
Developing software today typically involves the use of external open-source software libraries. Often, developers do not scrutinize the source code to ascertain its security properties; instead, they employ a range of ad-hoc methods to evaluate the risk of integrating an open-source repository. This paper explores the design of SocialTrust.md , a Markdown-formatted label which structures socially-informed trustworthiness signals to enhance developer awareness of risks in utilizing a specific repository. We conduct need-finding interviews (n = 12) to discover that open-source users desire synthesized, comprehensive, versatile, and comparable metrics. After multiple rounds of design iteration, we validate the design decisions of SocialTrust.md through usability studies and interviews (n = 13). Our results suggest that SocialTrust.md helps participants identify more risk signals, and participants find it useful for both consumers and maintainers.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- "Threat modeling is very formal, it's very technical, and also very hard to do correctly": Investigating Threat Modeling Practices in Open-Source Software ProjectsHarjot Kaur, Carson Powers, Ronald E. Thompson III, Sascha Fahl et al.USENIX Security 2025
- Representation of Developer Expertise in Open Source SoftwareTapajit Dey, Andrey Karnauch, Audris MockusICSE 2021 · 8 citations
- Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software SecurityAlfusainey Jallow, Michael Schilling, Michael Backes, Sven BugielS&P 2024 · 6 citations
- Is a Trustmark and QR Code Enough? The Effect of IoT Security and Privacy Label Information Complexity on Consumer Comprehension and BehaviorClaire C. Chen, Dillon Shu, Hamsini Ravishankar, Xinran Li et al.CHI 2024 · 27 citations
- Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIsPeter Leo Gorski, Yasemin Acar, Luigi Lo Iacono, Sascha FahlCHI 2020 · 39 citations
