Uppsats

Vulnerabilities in Open-Source Dependencies : A Developer’s Perspective

Master-uppsats

Blekinge Tekniska Högskola/Institutionen för programvaruteknik

Publicerad: 2026

Språk: Engelska

Sammanfattning

Background: Free and open-source software (FOSS) and open-source software (OSS) have long been the backbone of the software industry. FOSS/OSS offers benefits, but using FOSS/OSS dependencies in projects carries security risks, as attackers can exploit vulnerabilities in the software because the source code is freely available. The rise of high-profile SSC attacks, most of which exploit vulnerabilitiesin dependencies, means the continued use of vulnerable dependencies leaves software exposed. Objectives: The aim of this study is to explore how software developers perceive and assess vulnerabilities in OSS dependencies, to understand their awareness of software supply chain attack risks, and the factors that influence their decision-making, security practices, and responses to dependency risks. Methods: Semi-structured interviews were conducted with 21 developers across five web frameworks: Django, Laravel, Next.js, Ruby on Rails and Spring Boot. The transcribed data were analysed using thematic analysis. Results: This study finds that developers’ perception of vulnerable FOSS/OSS dependencies is shaped by various intertwined factors, namely uneven awareness of supply chain attacks, inconsistent security governance models, ecosystem norms, varying dependency management practices, and is constrained by developers’ security skills. Security governance, ecosystem maturity, and the practical realities of maintaining modern dependency graphs shape the remediation process for developers. These insights provide a more comprehensive understanding of why vulnerabilities persist and where targeted improvements can strengthen the security of FOSS/OSS dependencies. Conclusions: The study demonstrated that addressing vulnerabilities in FOSS/OSS dependencies requires not only technical skills but also improved awareness, security governance, and ecosystem support.

Information

Författare
Makarudze, Anna
Lärosäte / institution
Blekinge Tekniska Högskola/Institutionen för programvaruteknik
Publiceringsdatum
2026
Uppsatstyp
Master-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.