Published April 20, 2024 | Version v1
Conference paper Open

Supplementary Material for Decomposing and Measuring Trust in Open-Source Software Supply Chains

  • 1. ROR icon College of Wooster
  • 2. ROR icon Carnegie Mellon University
  • 3. University of Paderborn
  • 4. ROR icon North Carolina State University

Description

This replication package contains the full open-source software supply chain trust contracts table used for the paper Decomposing and Measuring Trust in Open-Source Software Supply Chains (ICSE NIER 2024).

  • supplyChainTrustContractsTable.pdf is a table with the full list of trust contracts identified in the paper as well as the proposed indicators and operationalizable metrics

For more details on how the trust contracts were identified please see Section 3.1 of the paper

Files

supplyChainTrustContractsTable.pdf

Files (106.1 kB)

Name Size Download all
md5:54d3e8daab53e0b64fcdaa777a7946d6
106.1 kB Preview Download