Designing SocialTrust.md to Enhance Developer Awareness of Risks in Utilizing Open-Source GitHub Repositories
Tony W. Li, Yunpeng Zhao, Yujin Zhang, R. Stuart Geiger, Haojian Jin
摘要
Developing software today typically involves the use of external open-source software libraries. Often, developers do not scrutinize the source code to ascertain its security properties; instead, they employ a range of ad-hoc methods to evaluate the risk of integrating an open-source repository. This paper explores the design of SocialTrust.md , a Markdown-formatted label which structures socially-informed trustworthiness signals to enhance developer awareness of risks in utilizing a specific repository. We conduct need-finding interviews (n = 12) to discover that open-source users desire synthesized, comprehensive, versatile, and comparable metrics. After multiple rounds of design iteration, we validate the design decisions of SocialTrust.md through usability studies and interviews (n = 13). Our results suggest that SocialTrust.md helps participants identify more risk signals, and participants find it useful for both consumers and maintainers.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- "Threat modeling is very formal, it's very technical, and also very hard to do correctly": Investigating Threat Modeling Practices in Open-Source Software ProjectsHarjot Kaur, Carson Powers, Ronald E. Thompson III, Sascha Fahl 等USENIX Security 2025
- Representation of Developer Expertise in Open Source SoftwareTapajit Dey, Andrey Karnauch, Audris MockusICSE 2021 · 被引用 8 次
- Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software SecurityAlfusainey Jallow, Michael Schilling, Michael Backes, Sven BugielS&P 2024 · 被引用 6 次
- Is a Trustmark and QR Code Enough? The Effect of IoT Security and Privacy Label Information Complexity on Consumer Comprehension and BehaviorClaire C. Chen, Dillon Shu, Hamsini Ravishankar, Xinran Li 等CHI 2024 · 被引用 27 次
- Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIsPeter Leo Gorski, Yasemin Acar, Luigi Lo Iacono, Sascha FahlCHI 2020 · 被引用 39 次
