• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
 
  • Details
  • Full
Options
2025
Conference Paper
Title

SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems

Abstract
The disconnect between distributed software artifacts and their supposed source code enables attackers to leverage the build process for inserting malicious functionality. Past research in this field focuses on compiled language ecosystems, mostly analysing Linux distribution packages. However, the popular scripting language ecosystems potentially face unique issues given the systematic difference in distributed artifacts. This SoK provides an overview of existing research, aiming to highlight future directions, as well as chances to transfer existing knowledge from compiled language ecosystems. To that end, we work out key aspects in current research, systematize identified challenges for software reproducibility, and map them between the ecosystems. We find that the literature is sparse, focusing on few individual problems and ecosystems. This allows us to effectively identify next steps to improve reproducibility in this field.
Author(s)
Pohl, Timo
Universität Bonn
Novák, Pavel
Masaryk University
Ohm, Marc
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Meier, Michael
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Mainwork
Lecture Notes in Computer Science
Conference
20th International Conference on Availability, Reliability and Security, ARES 2025
Open Access
DOI
10.1007/978-3-032-00627-1_11
Additional link
Full text
Language
English
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Keyword(s)
  • library reproducibility

  • reproducible builds

  • software packages

  • software security

  • software supply chain security

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024