DCI: Dependency Confidence Index for Assessing Open-Source Dependency Trustworthiness
A new composite index combines nine weighted trust signals to score open-source dependency risk — directly useful for CRA supply-chain due diligence and SBOM-driven governance.
Summary written by editorial AI · Source link below
arXiv:2608.16430v1 Announce Type: cross Abstract: Selecting trustworthy open source software dependencies remains a major challenge in software supply chain security. We present the Dependency Confidence Index (DCI), a composite formative index that combines nine empirically weighted trust factors into a single normalized composite score for dependency selection. DCI's trust factors combine insights from a systematic literature review and an exploratory Analytic Hierarchy Process (AHP) survey o
Editorial Analysis
With CRA mandating documented supply-chain risk management, a standardised dependency trust score can streamline vendor and library selection while creating auditable evidence.
Integrate dependency-trust scoring into your CI/CD gate criteria alongside existing SBOM and vulnerability scanning.
A research-backed scoring model for open-source dependency trust could help demonstrate CRA compliance for software supply chains.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the DevSecOps Desk
- Boundary-Mutation Testing for Pattern-Based Secret Detection: A Rule-Level Method and Cross-Scanner Evaluation4d
- PatchBench: Evaluating AI Agents for Vulnerability Patching4d
- Coder's registry infrastructure compromised to push malicious modules4d
- Modelstamp: Pre-Deserialization Verification of Machine-Learning Artifacts and Runtime Environment State5d
- Barriers to Using Static Application Security Testing (SAST) Tools: A Literature Review5d