TY - GEN
T1 - Exploring the SECURITY.md in the Dependency Chain
T2 - 40th IEEE/ACM International Conference on Automated Software Engineering Workshops, ASEW 2025
AU - Termphaiboon, Chayanid
AU - Kula, Raula Gaikovina
AU - Fan, Youmei
AU - Choetkiertikul, Morakot
AU - Ragkhitwetsagul, Chaiyong
AU - Sunetnanta, Thanwadee
AU - Matsumoto, Kenichi
N1 - Publisher Copyright:
© 2025 IEEE.
PY - 2025
Y1 - 2025
N2 - Security policies, such as SECURITY.md files, are now common in open-source projects. They help guide responsible vulnerability reporting and build trust among users and contributors. Despite their growing use, it is still unclear how these policies influence the structure and evolution of software dependencies. Software dependencies are external packages or libraries that a project relies on, and their interconnected nature affects both functionality and security. This study explores the relationship between security policies and dependency management in PyPI projects. We analyzed projects with and without a SECURITY.md file by examining their dependency trees and tracking how dependencies change over time. The analysis shows that projects with a security policy tend to rely on a broader set of direct dependencies, while overall depth and transitive dependencies remain similar. Historically, projects created after the introduction of SECURITY.md, particularly later adopters, show more frequent dependency updates. These results suggest that security policies are linked to more modular and feature-rich projects, and highlight the role of SECURITY.md in promoting proactive dependency management and reducing risks in the software supply chain.
AB - Security policies, such as SECURITY.md files, are now common in open-source projects. They help guide responsible vulnerability reporting and build trust among users and contributors. Despite their growing use, it is still unclear how these policies influence the structure and evolution of software dependencies. Software dependencies are external packages or libraries that a project relies on, and their interconnected nature affects both functionality and security. This study explores the relationship between security policies and dependency management in PyPI projects. We analyzed projects with and without a SECURITY.md file by examining their dependency trees and tracking how dependencies change over time. The analysis shows that projects with a security policy tend to rely on a broader set of direct dependencies, while overall depth and transitive dependencies remain similar. Historically, projects created after the introduction of SECURITY.md, particularly later adopters, show more frequent dependency updates. These results suggest that security policies are linked to more modular and feature-rich projects, and highlight the role of SECURITY.md in promoting proactive dependency management and reducing risks in the software supply chain.
KW - open-source software
KW - security policy
KW - software dependency
UR - https://www.scopus.com/pages/publications/105033707263
U2 - 10.1109/ASEW67777.2025.00055
DO - 10.1109/ASEW67777.2025.00055
M3 - Conference contribution
AN - SCOPUS:105033707263
T3 - Proceedings - 2025 40th IEEE/ACM International Conference on Automated Software Engineering Workshops, ASEW 2025
SP - 260
EP - 267
BT - Proceedings - 2025 40th IEEE/ACM International Conference on Automated Software Engineering Workshops, ASEW 2025
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 16 November 2025 through 20 November 2025
ER -