Skip to content

Commit 08fd848

Browse files
Update master-thesis.md
1 parent f40d776 commit 08fd848

File tree

1 file changed

+11
-0
lines changed

1 file changed

+11
-0
lines changed

master-thesis.md

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,8 +13,19 @@ Open-source projects rely on a community of maintainers and contributors, which
1313

1414
Related Work:
1515
[1] [OpenSSF Scorecard: On the Path Toward Ecosystem-Wide Automated Security Metrics](ieeexplore.ieee.org/abstract/document/10163720)
16+
1617
[2] [Decomposing and Measuring Trust in Open-Source Software Supply Chains](dl.acm.org/doi/abs/10.1145/3639476.3639775)
1718

19+
### Comparative Analysis of Software Composition Analysis Tools
20+
Contact: Larissa Schmid
21+
22+
Software Composition Analysis (SCA) tools scan a project's dependencies to identify known security vulnerabilities, thereby supporting software supply chain security. Although numerous SCA tools have been developed, they differ significantly in functionality, capabilities, and the ecosystems they support. To date, there is no comprehensive evaluation that systematically compares these tools. This Master’s thesis aims to collect a representative set of SCA tools, analyze and compare their features, and evaluate them on a shared dataset. The study will provide practical insights into how SCA tools perform across different ecosystems and their relative strengths and limitations.
23+
24+
Related Work:
25+
[1] [Software composition analysis for vulnerability detection: An empirical study on Java projects](dl.acm.org/doi/abs/10.1145/3611643.3616299)
26+
[2] [Understanding Similarities and Differences Between Software Composition Analysis Tools](ieeexplore.ieee.org/abstract/document/10645968)
27+
[3] [Adversarial Analysis of Software Composition Analysis Tools](https://link.springer.com/chapter/10.1007/978-3-031-75764-8_9)
28+
1829
### Empirical Study of API Difference Tools for Java Dependencies
1930
Contact: Frank Reyes Garcia
2031

0 commit comments

Comments
 (0)