Page 115 - 《软件学报》2026年第7期
P. 115
2800 软件学报 2026 年第 37 卷第 7 期
inquiry into DevSecOps industry. IET Software, 2023, 17(4): 435–454. [doi: 10.1049/sfw2.12132]
[53] Rajapakse RN, Zahedi M, Babar MA. An empirical analysis of practitioners’ perspectives on security tool integration into DevOps. In:
Proc. of the 15th ACM/IEEE Int’l Symp. on Empirical Software Engineering and Measurement. Bari: ACM, 2021. 6. [doi: 10.1145/
3475716.3475776]
[54] Ur Rahman AA, Williams L. Software security in DevOps: Synthesizing practitioners’ perceptions and practices. In: Proc. of the 2016
IEEE/ACM Int’l Workshop on Continuous Software Evolution and Delivery. Austin: IEEE, 2016. 70–76.
[55] Sadovykh A, Widforss G, Truscan D, Enoiu EP, Mallouli W, Iglesias R, Bagnto A, Hendel O. VeriDevOps: Automated protection and
prevention to meet security requirements in DevOps. In: Proc. of the 2021 Design, Automation & Test in Europe Conf. & Exhibition.
Grenoble: IEEE, 2021. 1330–1333. [doi: 10.23919/DATE51398.2021.9474185]
[56] Mohan V, Othmane LB. SecDevOps: Is it a marketing buzzword?—Mapping research on security in DevOps. In: Proc. of the 11th Int’l
Conf. on Availability, Reliability and Security. Salzburg: IEEE, 2016. 542–547. [doi: 10.1109/ARES.2016.92]
[57] Nikolov L, Aleksieva-Petrova A. Framework for integrating threat modeling into a DevOps pipeline for enhanced software
development. In: Proc. of the 2024 Int’l Conf. on Software, Telecommunications and Computer Networks. Split: IEEE, 2024. 1–5. [doi:
10.23919/SoftCOM62040.2024.10721871]
[58] Bolling T, Lennon RG. Viewing DevOps security processes through an applied cyberpsychology lens. In: Proc. of the 2023 Cyber
Research Conf. Ireland. IEEE, 2023. 1–6. [doi: 10.1109/Cyber-RCI59474.2023.10671453]
[59] Scanlon T, Morales J. Revelations from an agile and DevSecOps transformation in a large organization: An experiential case study. In:
Proc. of the 2022 Int’l Conf. on Software and System Processes and Int’l Conf. on Global Software Engineering. Pittsburgh: ACM,
2022. 77–81. [doi: 10.1145/3529320.3529329]
[60] Xiao C. Novel malware XcodeGhost modifies xcode, infects apple iOS Apps and hits App store. 2015. https://unit42.paloaltonetworks.
com/novel-malware-xcodeghost-modifies-xcode-infects-apple-ios-apps-and-hits-app-store/
[61] Northwood C. Today’s JavaScript trash fire and pile on. 2018. https://cnorthwood.medium.com/todays-javascript-trash-fire-and-pile-on-
f3efcf8ac8c7
[62] Tarr D. Backdoored dependency? Flatmap-stream-0.1.1 and flatmap-stream-0.1.2. 2025. https://github.com/dominictarr/event-stream/
issues/115
[63] Grander D. Malicious code found in npm package event-stream downloaded 8 million times in the past 2.5 months. 2018. https://snyk.
io/blog/malicious-code-found-in-npm-package-event-stream/
[64] Sharma A. PHP’s git server hacked to add backdoors to PHP source code. 2021. https://www.bleepingcomputer.com/news/security/phps-
git-server-hacked-to-add-backdoors-to-php-source-code/
[65] Ding YW, Cui BJ. Security analysis for third-party component dependency confusion: A risk assessment framework based on source
code tree matching. In: Proc. of the 6th Int’l Conf. on Frontier Technologies of Information and Computer. Qingdao: IEEE, 2024.
243–250. [doi: 10.1109/ICFTIC64248.2024.10912978]
[66] Martínez J, Durán JM. Software supply chain attacks, a threat to global cybersecurity: Solarwinds’ case study. Int’l Journal of Safety and
Security Engineering, 2021, 11(5): 537–545. [doi: 10.18280/ijsse.110505]
[67] CCleaner. Security notification for CCleaner v5.33.6162 and CCleaner cloud v1.07.3191 for 32-bit windows users. 2017. https://www.
ccleaner.com/knowledge/security-notification-ccleaner-v5336162-ccleaner-cloud-v1073191?cc-noredirect=
[68] Global Research & Analysis Team, Anti-malware Research Team. Operation ShadowHammer. 2019. https://securelist.com/operation-
shadowhammer/89992/
[69] Lakshmanan R. Travis CI flaw exposes secrets of thousands of open source projects. 2021. https://thehackernews.com/2021/09/travis-ci-
flaw-exposes-secrets-of.html
[70] Lisa V. NVIDIA’s stolen code-signing certs used to sign malware. 2022. https://threatpost.com/nvidias-stolen-code-signing-certs-sign-
malware/178784/
[71] Jonathan L. Popular Codecov code coverage tool hacked to steal Dev credentials. 2021. https://www.privacy.com.sg/cybersecurity/
popular-codecov-code-coverage-tool-hacked-to-steal-dev-credentials/
[72] Phan B. June 20 Incident Details and Remediation. 2023. https://jumpcloud.com/blog/security-update-june-20-incident-details-and-
remediation
[73] Cybersecurity & Infrastructure Security Agency. Reported supply chain compromise affecting XZ utils data compression library, CVE-
2024-3094. 2024. https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-com
pression-library-cve-2024-3094
[74] Lakshmanan R. Newly discovered bugs in VSCode extensions could lead to supply chain attacks. 2021. https://thehackernews.com/

