Page 114 - 《软件学报》2026年第7期
P. 114
胡帅 等: 产业研发视角下的开源软件供应链攻击问题研究 2799
[31] Traykov K. A framework for security testing of large language models. In: Proc. of the 12th IEEE Int’l Conf. on Intelligent Systems.
Varna: IEEE, 2024. 1–7. [doi: 10.1109/IS61756.2024.10705238]
[32] Wu YL, Wen M, Yu ZL, Guo XC, Jin H. Effective vulnerable function identification based on CVE description empowered by large
language models. In: Proc. of the 39th IEEE/ACM Int’l Conf. on Automated Software Engineering. Sacramento: IEEE, 2024. 393–405.
[33] Shen ZD, Chen S. A survey of automatic software vulnerability detection, program repair, and defect prediction techniques. Security and
Communication Networks, 2020, 2020: 8858010. [doi: 10.1155/2020/8858010]
[34] Chen WB, Li JY, Ma JQ, Conradi R, Ji JZ, Liu CN. A survey of software development with open source components in Chinese
software industry. In: Proc. of the 2007 Int’l Conf. on Software Process. Minneapolis: Springer, 2007. 208–220. [doi: 10.1007/978-3-
540-72426-1_18]
[35] Manan WNW, Kahar MNM, Ali NM. A survey on current malicious JavaScript behavior of infected Web content in detection of
malicious Web pages. IOP Conf. Series: Materials Science and Engineering, 2020, 769: 012074. [doi 10.1088/1757-899X/769/1/
012074]
[36] Jin ZF, Zhang YW, Ye WH, Zhang H, Shao D. Research on application of DevOps in documentation towards full value delivery. Ruan
Jian Xue Bao/Journal of Software, 2019, 30(10): 3127–3147 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/5792.
htm [doi: 10.13328/j.cnki.jos.005792]
[37] He XX, Zhang YQ, Liu QX. Survey of software supply chain security. Journal of Cyber Security, 2020, 5(1): 57–73 (in Chinese with
English abstract). [doi: 10.19363/J.cnki.cn10-1380/tn.2020.01.06]
[38] Zhang DG, Li B, He P, Zhou HY. Characteristic study of open-source community based on software ecosystem. Computer Engineering,
2015, 41(11): 106–113 (in Chinese with English abstract). [doi: 10.3969/j.issn.1000-3428.2015.11.019]
[39] Sun ZY, Wu JZ, Ling X, Wei YL, Luo TY, Wu YJ. Research on key technologies of SBOM in software supply chain. Ruan Jian Xue
Bao/Journal of Software, 2025, 36(6): 2604–2642 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/7308.htm [doi:
10.13328/j.cnki.jos.007308]
[40] Afaneh S, Al-Mousa MR, Al-Hamid HS, AL-Awasa BS, Alia M, Almimi H, Alkhatib AA. Security challenges review in agile and
DevOps practices. In: Proc. of the 2023 Int’l Conf. on Information Technology. Amman: IEEE, 2023. 102–107. [doi: 10.1109/
ICIT58056.2023.10226018]
[41] Valdés-Rodríguez Y, Hochstetter-Diez J, Diéguez-Rebolledo M, Bustamante-Mora A, Cadena-Martínez R. Analysis of strategies for the
integration of security practices in agile software development: A sustainable SME approach. IEEE Access, 2024, 12: 35204–35230.
[doi: 10.1109/ACCESS.2024.3372385]
[42] Ascenção C, Teixeira H, Gonçalves J, Almeida F. Large-scale agile security practices in software engineering. Information and
Computer Security, 2024, 33(3): 344–361. [doi: 10.1108/ICS-07-2023-0136]
[43] Karanam R. Securing ci/cd pipelines: Strategies for mitigating risks in modern software delivery. Int’l Journal of Engineering and
Technology Research (IJETR), 2024, 9(2): 1–9.
[44] Pan ZY, Shen WB, Wang XK, Yang YT, Chang R, Liu Y, Liu CW, Liu Y, Ren K. Ambush from all sides: Understanding security
threats in open-source software CI/CD pipelines. IEEE Trans. on Dependable and Secure Computing, 2024, 21(1): 403–418. [doi: 10.
1109/tdsc.2023.3253572]
[45] Düllmann TF, Paule C, van Hoorn A. Exploiting DevOps practices for dependable and secure continuous delivery pipelines. In: Proc. of
the 4th Int’l Workshop on Rapid Continuous Software Engineering. Gothenburg: ACM, 2018. 27–30. [doi: 10.1145/3194760.3194763]
[46] Czekster RM. Continuous risk assessment in secure DevOps. arXiv:2409.03405, 2024.
[47] Throner S, Abeck S, Petrovic P, Hütter H. A DevOps approach to the mitigation of security vulnerabilities in runtime environments. In:
Proc. of the 2023 IEEE Int’l Conf. on Service-oriented System Engineering. Athens: IEEE, 2023. 106–113. [doi: 10.1109/SOSE58276.
2023.00019]
[48] Sermpezis E, Karapiperis D, Tjortjis C. Integration of security in the DevOps methodology. In: Proc. of the 15th Int’l Conf. on
Information, Intelligence, Systems & Applications. Chania Crete: IEEE, 2024. 1–6. [doi: 10.1109/IISA62523.2024.10786669]
[49] Tatineni S. Compliance and audit challenges in DevOps: A security perspective. Int’l Research Journal of Modernization in Engineering
Technology and Science, 2023, 5(10): 1306–1316. [doi: 10.56726/IRJMETS45309]
[50] Merkow MS. Practical Security for Agile and DevOps. New York: Auerbach Publications, 2022. [doi: 10.1201/9781003265566]
[51] Enoiu EP, Truscan D, Sadovykh A, Mallouli W. VeriDevOps software methodology: Security verification and validation for DevOps
practices. In: Proc. of the 18th Int’l Conf. on Availability, Reliability and Security. Benevento: ACM, 2023. 135. [doi: 10.1145/3600160.
3605054]
[52] Zhou X, Mao RF, Zhang H, Dai QM, Huang H, Shen HF, Li JY, Rong GP. Revisit security in the era of DevOps: An evidence-based

