Skip to main navigation Skip to search Skip to main content

Exploring the SECURITY.md in the Dependency Chain: Preliminary Analysis of the PyPI Ecosystem

  • Mahidol University
  • Osaka University
  • Nara Institute of Science and Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Security policies, such as SECURITY.md files, are now common in open-source projects. They help guide responsible vulnerability reporting and build trust among users and contributors. Despite their growing use, it is still unclear how these policies influence the structure and evolution of software dependencies. Software dependencies are external packages or libraries that a project relies on, and their interconnected nature affects both functionality and security. This study explores the relationship between security policies and dependency management in PyPI projects. We analyzed projects with and without a SECURITY.md file by examining their dependency trees and tracking how dependencies change over time. The analysis shows that projects with a security policy tend to rely on a broader set of direct dependencies, while overall depth and transitive dependencies remain similar. Historically, projects created after the introduction of SECURITY.md, particularly later adopters, show more frequent dependency updates. These results suggest that security policies are linked to more modular and feature-rich projects, and highlight the role of SECURITY.md in promoting proactive dependency management and reducing risks in the software supply chain.

Original languageEnglish
Title of host publicationProceedings - 2025 40th IEEE/ACM International Conference on Automated Software Engineering Workshops, ASEW 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages260-267
Number of pages8
ISBN (Electronic)9798331585037
DOIs
Publication statusPublished - 2025
Event40th IEEE/ACM International Conference on Automated Software Engineering Workshops, ASEW 2025 - Seoul, Korea, Republic of
Duration: 16 Nov 202520 Nov 2025

Publication series

NameProceedings - 2025 40th IEEE/ACM International Conference on Automated Software Engineering Workshops, ASEW 2025

Conference

Conference40th IEEE/ACM International Conference on Automated Software Engineering Workshops, ASEW 2025
Country/TerritoryKorea, Republic of
CitySeoul
Period16/11/2520/11/25

Keywords

  • open-source software
  • security policy
  • software dependency

Fingerprint

Dive into the research topics of 'Exploring the SECURITY.md in the Dependency Chain: Preliminary Analysis of the PyPI Ecosystem'. Together they form a unique fingerprint.

Cite this