CHAINS research project at KTH Royal Institute of Technology
"Consistent Hardening and Analysis of Software Supply Chains" at KTH, funded by SSF
Pinned Repositories
breaking-good
make breaking updates look good 👗 https://arxiv.org/abs/2407.03880
bump
A dataset of reproducible breaking dependency updates, SANER 2024 (https://doi.org/10.1109/SANER60148.2024.00024)
chains-project.github.io
The source for the website of the SSF CHAINS project https://chains.proj.kth.se/
dirty-waters
automatically detect software supply chain smells and issues
ghasum
Checksums for GitHub Actions.
GoSurf
Static analyzer to find locations to hide malicious code in Go
maven-lockfile
Lockfiles for Maven. Pin your dependencies. Build with integrity.
SBOM-2023
Experimental Data about Java SBOMs https://arxiv.org/pdf/2303.11102.pdf
sbom-files
Long term storage of software bills of materials (sbom) https://arxiv.org/pdf/2303.11102.pdf
sbom.exe
calls the police if a prohibited class is loaded by the JVM http://arxiv.org/pdf/2407.00246
CHAINS research project at KTH Royal Institute of Technology's Repositories
chains-project/ethereum-ssc
Open science data of "The Multibillion Dollar Software Supply Chain of Ethereum", IEEE Computer, 2022 http://arxiv.org/pdf/2202.07029
chains-project/cdis-poster
A KTH CDIS poster template based on beamerposter, fork of kth-poster
chains-project/OSSRH-87984
Proving ownership for Sonatype
chains-project/VSOBFS
verifiable source-only bootstrap from scratch to a Posix-like OS and a C99 compiler (copy of tor website)
chains-project/frozen-sorald
Immutable fork to monitor changes in the SBOM producer behaviour
chains-project/frozen-spoon
Immutable fork to monitor changes in the SBOM producer behaviour