arrow
返回

Are Your Dependencies Code Reviewed?: Measuring Code Review Coverage in Dependency Updates

delete2023-11-01
delete0
delete
OA
AI
N
Nasif Imtiaz *
L
Laurie Williams
DOI:10.1109/TSE.2023.3319509delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
As modern software extensively uses free open source packages as dependencies, developers have to regularly pull in new third-party code through frequent updates. However, without a proper review of every incoming change, vulnerable and malicious code can sneak into the codebase through these dependencies. The goal of this study is to aid developers in securely accepting dependency updates by measuring if the code changes in an update have passed through a code review process. We implement Depdive, an update audit tool for packages in Crates.io, npm, PyPI, and RubyGems registry. Depdive first (i) identifies the files and the code changes in an update that cannot be traced back to the package's source repository, i.e., phantom artifacts; and then (ii) measures what portion of changes in the update, excluding the phantom artifacts, has passed through a code review process, i.e., code review coverage. Using Depdive, we present an empirical study across the latest ten updates of the most downloaded 1000 packages in each of the four registries. We further evaluated our results through a maintainer agreement survey. We find that phantom artifacts are not uncommon in the updates (20.1% of the analyzed updates had at least one phantom file). The phantoms can appear either due to legitimate reasons, such as in the case of programmatically generated files, or from accidental inclusion, such as in the case of files that are ignored in the repository. Regarding code review coverage (CRC), we find the updates are typically only partially code-reviewed (52.5% of the time). Further, only 9.0% of the packages had all their updates in our data set fully code-reviewed, indicating that even the most used packages can introduce non-reviewed code in the software supply chain. We also observe that updates either tend to have high CRC or low CRC, suggesting that packages at the opposite end of the spectrum may require a separate set of treatments.
Keyword:
Codes
Phantoms
Software
Software development management
Source coding
Security
Supply chains
Software supply chain security
open source security
dependency analysis

期刊

IEEE Transactions on Software Engineering 封面图
IEEE Transactions on Software Engineering
IF:
5.6
论文数:
2.8K
被引数:
1.1W

机构

N
North Carolina State University
学者数:
2.6W
论文数: 2.3W
被引数: 3.7W
引用论文

引用论文

An empirical study of the impact of modern code review practices on software quality
err2015-04-25
err208
PREAI
errMcIntosh, Shane; Kamei, Yasutaka; Adams, Bram; Hassan, Ahmed E.
err分享
err收藏
err分享
err收藏
Human vs robotic organ retraction during laparoscopic Nissen fundoplication
err2014-02-27
err0
PREAI
errB. K. Poulose; M. F. Kutka; M. Mendoza-Sagaon; A. C. Barnes; C. Yang; R. H. Taylor; M. A. Talamini
err分享
err收藏
err
IF0
err
err0
PREAI
err
err分享
err收藏
Release of Vasoactive Intestinal Polypeptide (VIP) by Electric Stimulation of the Vagal Nerves
err1977-02-01
err0
errOAAI
errO.B. Schaffalitzky de Muckadell; J. Fahrenkrug; J.J. Holst
err分享
err收藏
学者 查看更多内容