Loading _data/publications.yml 0 → 100644 +101 −0 Original line number Diff line number Diff line - title: Reflections on trusting trust source: Commun. ACM, 27 (8), 761–763 authors: Thompson, K. date: 1984 url: https://doi.org/10.1145/358198.358210 - title: Fully countering trusting trust through diverse double-compiling authors: Wheeler, D. A. date: 2010 url: https://arxiv.org/abs/1004.5534 - title: Functional package management with guix authors: Courtès, L. date: 2013 url: https://arxiv.org/abs/1305.4584 - title: Reproducible and User-Controlled Software Environments in HPC with Guix source: 2nd International Workshop on Reproducibility in Parallel Computing (RepPar) authors: Courtès, L., & Wurmus, R. date: 2015, August url: https://inria.hal.science/hal-01161771 - title: Automated localization for unreproducible builds. source: Proceedings of the 40th International Conference on Software Engineering authors: Ren, Z., Jiang, H., Xuan, J., & Yang, Z. date: 2018, May url: https://doi.org/10.1145/3180155.3180224 - title: Transparent, provenance-assured, and secure software-as-a-service source: 2019 IEEE 18th International Symposium on Network Computing and Applications (NCA), 1–8 authors: Tapas, N., Longo, F., Merlino, G., & Puliafito, A. date: 2019 url: https://doi.org/10.1109/NCA.2019.8935014 - title: "In-toto: Providing farm-to-table guarantees for bits and bytes" source: Proceedings of the 28th USENIX Conference on Security Symposium, 1393–1410 authors: Torres-Arias, S., Afzali, H., Kuppusamy, T. K., Curtmola, R., & Cappos, J. date: 2019 url: https://www.usenix.org/conference/usenixsecurity19/presentation/torres-arias - title: "Backstabber’s knife collection: A review of open source software supply chain attacks" source: In_ Lecture notes in computer science _(pp. 23–43). Springer International Publishing. authors: Ohm, M., Plate, H., Sykosch, A., & Meier, M. date: 2020 url: https://doi.org/10.1007/978-3-030-52683-2_2 - title: Reproducible containers source: Proceedings of the Twenty-Fifth International Conference on Architectural Support for Programming Languages and Operating Systems, 167–182 authors: Navarro Leija, O. S., Shiptoski, K., Scott, R. G., Wang, B., Renner, N., Newton, R. R., & Devietti, J. date: 2020 url: https://doi.org/10.1145/3373376.3378519 - title: Towards detection of software supply chain attacks by forensic artifacts source: Proceedings of the 15th International Conference on Availability, Reliability and Security authors: Ohm, M., Sykosch, A., & Meier, M. date: 2020 url: https://doi.org/10.1145/3407023.3409183 - title: Toward long-term and archivable reproducibility source: Computing in Science & Engineering, 23(3), 82–91 authors: Akhlaghi, M., Infante-Sainz, R., Roukema, B. F., Khellat, M., Valls-Gabaud, D., & Baena-Galle, R. date: 2021 url: https://doi.org/10.1109/mcse.2021.3072860 - title: "Reproducible builds: Increasing the integrity of software supply chains" source: IEEE Software, 39(2), 62–70 authors: Lamb, C., & Zacchiroli, S. date: 2022 url: https://doi.org/10.1109/MS.2021.3073045 - title: An experience report on producing verifiable builds for large-scale commercial systems source: IEEE Transactions on Software Engineering, 48(9), 3361–3377 authors: Shi, Y., Wen, M., Cogo, F. R., Chen, B., & Jiang, Z. M. date: 2022 url: https://doi.org/10.1109/TSE.2021.3092692 - title: Automated patching for unreproducible builds source: Proceedings of the 44th International Conference on Software Engineering, 200–211 authors: Ren, Z., Sun, S., Xuan, J., Li, X., Zhou, Z., & Jiang, H. date: 2022 url: https://doi.org/10.1145/3510003.3510102 - title: "Top five challenges in software supply chain security: Observations from 30 industry and organizations" source: IEEE Security & Privacy, 20(2), 96–100 authors: Enck, W., & Williams, L. date: 2022 url: https://doi.org/10.1109/MSEC.2022.3142338 - title: On business adoption and use of reproducible builds for open and closed source software source: Software Quality Journal, 31(3), 687–719 authors: Butler, S., Gamalielsson, J., Lundell, B., Brax, C., Mattsson, A., Gustavsson, T., Feist, J., Kvarnström, B., & Lönroth, E. date: 2022 url: https://doi.org/10.1007/s11219-022-09607-z - title: "It’s like flossing your teeth: On the importance and challenges of reproducible builds for software supply chain security" source: 2023 IEEE Symposium on Security and Privacy (SP), 1527–1544 authors: Fourne, M., Wermke, D., Enck, W., Fahl, S., & Acar, Y. date: 2023 url: https://doi.org/10.1109/SP46215.2023.10179320 - title: "Signing in four public software package registries: Quantity, quality, and influencing factors" authors: Schorlemmer, T. R., Kalu, K. G., Chigges, L., Ko, K. M., Isghair, E. A.-M. A., Baghi, S., Torres-Arias, S., & Davis, J. C. date: 2024 url: https://arxiv.org/abs/2401.14635 - title: Reproducibility of build environments through space and time authors: Malka, J., Zacchiroli, S., & Zimmermann, T. date: 2024 url: https://arxiv.org/abs/2402.00424 - title: "Options Matter: Documenting and Fixing Non-Reproducible Builds in Highly-Configurable Systems" source: MSR 2024 - 21th International Conference on Mining Software Repository, 1–11. authors: Randrianaina, G. A., Khelladi, D. E., Zendra, O., & Acher, M. date: 2024 url: https://inria.hal.science/hal-04441579 - title: Reproducibility in software engineering source: University of Mons. authors: Dellaiera, P. date: 2024 url: https://doi.org/10.5281/zenodo.12666898 No newline at end of file Loading
_data/publications.yml 0 → 100644 +101 −0 Original line number Diff line number Diff line - title: Reflections on trusting trust source: Commun. ACM, 27 (8), 761–763 authors: Thompson, K. date: 1984 url: https://doi.org/10.1145/358198.358210 - title: Fully countering trusting trust through diverse double-compiling authors: Wheeler, D. A. date: 2010 url: https://arxiv.org/abs/1004.5534 - title: Functional package management with guix authors: Courtès, L. date: 2013 url: https://arxiv.org/abs/1305.4584 - title: Reproducible and User-Controlled Software Environments in HPC with Guix source: 2nd International Workshop on Reproducibility in Parallel Computing (RepPar) authors: Courtès, L., & Wurmus, R. date: 2015, August url: https://inria.hal.science/hal-01161771 - title: Automated localization for unreproducible builds. source: Proceedings of the 40th International Conference on Software Engineering authors: Ren, Z., Jiang, H., Xuan, J., & Yang, Z. date: 2018, May url: https://doi.org/10.1145/3180155.3180224 - title: Transparent, provenance-assured, and secure software-as-a-service source: 2019 IEEE 18th International Symposium on Network Computing and Applications (NCA), 1–8 authors: Tapas, N., Longo, F., Merlino, G., & Puliafito, A. date: 2019 url: https://doi.org/10.1109/NCA.2019.8935014 - title: "In-toto: Providing farm-to-table guarantees for bits and bytes" source: Proceedings of the 28th USENIX Conference on Security Symposium, 1393–1410 authors: Torres-Arias, S., Afzali, H., Kuppusamy, T. K., Curtmola, R., & Cappos, J. date: 2019 url: https://www.usenix.org/conference/usenixsecurity19/presentation/torres-arias - title: "Backstabber’s knife collection: A review of open source software supply chain attacks" source: In_ Lecture notes in computer science _(pp. 23–43). Springer International Publishing. authors: Ohm, M., Plate, H., Sykosch, A., & Meier, M. date: 2020 url: https://doi.org/10.1007/978-3-030-52683-2_2 - title: Reproducible containers source: Proceedings of the Twenty-Fifth International Conference on Architectural Support for Programming Languages and Operating Systems, 167–182 authors: Navarro Leija, O. S., Shiptoski, K., Scott, R. G., Wang, B., Renner, N., Newton, R. R., & Devietti, J. date: 2020 url: https://doi.org/10.1145/3373376.3378519 - title: Towards detection of software supply chain attacks by forensic artifacts source: Proceedings of the 15th International Conference on Availability, Reliability and Security authors: Ohm, M., Sykosch, A., & Meier, M. date: 2020 url: https://doi.org/10.1145/3407023.3409183 - title: Toward long-term and archivable reproducibility source: Computing in Science & Engineering, 23(3), 82–91 authors: Akhlaghi, M., Infante-Sainz, R., Roukema, B. F., Khellat, M., Valls-Gabaud, D., & Baena-Galle, R. date: 2021 url: https://doi.org/10.1109/mcse.2021.3072860 - title: "Reproducible builds: Increasing the integrity of software supply chains" source: IEEE Software, 39(2), 62–70 authors: Lamb, C., & Zacchiroli, S. date: 2022 url: https://doi.org/10.1109/MS.2021.3073045 - title: An experience report on producing verifiable builds for large-scale commercial systems source: IEEE Transactions on Software Engineering, 48(9), 3361–3377 authors: Shi, Y., Wen, M., Cogo, F. R., Chen, B., & Jiang, Z. M. date: 2022 url: https://doi.org/10.1109/TSE.2021.3092692 - title: Automated patching for unreproducible builds source: Proceedings of the 44th International Conference on Software Engineering, 200–211 authors: Ren, Z., Sun, S., Xuan, J., Li, X., Zhou, Z., & Jiang, H. date: 2022 url: https://doi.org/10.1145/3510003.3510102 - title: "Top five challenges in software supply chain security: Observations from 30 industry and organizations" source: IEEE Security & Privacy, 20(2), 96–100 authors: Enck, W., & Williams, L. date: 2022 url: https://doi.org/10.1109/MSEC.2022.3142338 - title: On business adoption and use of reproducible builds for open and closed source software source: Software Quality Journal, 31(3), 687–719 authors: Butler, S., Gamalielsson, J., Lundell, B., Brax, C., Mattsson, A., Gustavsson, T., Feist, J., Kvarnström, B., & Lönroth, E. date: 2022 url: https://doi.org/10.1007/s11219-022-09607-z - title: "It’s like flossing your teeth: On the importance and challenges of reproducible builds for software supply chain security" source: 2023 IEEE Symposium on Security and Privacy (SP), 1527–1544 authors: Fourne, M., Wermke, D., Enck, W., Fahl, S., & Acar, Y. date: 2023 url: https://doi.org/10.1109/SP46215.2023.10179320 - title: "Signing in four public software package registries: Quantity, quality, and influencing factors" authors: Schorlemmer, T. R., Kalu, K. G., Chigges, L., Ko, K. M., Isghair, E. A.-M. A., Baghi, S., Torres-Arias, S., & Davis, J. C. date: 2024 url: https://arxiv.org/abs/2401.14635 - title: Reproducibility of build environments through space and time authors: Malka, J., Zacchiroli, S., & Zimmermann, T. date: 2024 url: https://arxiv.org/abs/2402.00424 - title: "Options Matter: Documenting and Fixing Non-Reproducible Builds in Highly-Configurable Systems" source: MSR 2024 - 21th International Conference on Mining Software Repository, 1–11. authors: Randrianaina, G. A., Khelladi, D. E., Zendra, O., & Acher, M. date: 2024 url: https://inria.hal.science/hal-04441579 - title: Reproducibility in software engineering source: University of Mons. authors: Dellaiera, P. date: 2024 url: https://doi.org/10.5281/zenodo.12666898 No newline at end of file