Quarterly journal published in SPbPU
and edited by prof. Dmitry Zegzhda
Peter the Great St. Petersburg Polytechnic University
Institute of computer sciences and technologies
information security of computer systems
Information Security Problems. Computer Systems
Published since 1999.
ISSN 2071-8217
RISK ASSESSMENT OF USING OPEN SOURCE PROJECTS: ANALYSIS OF EXISTING APPROACHES
M. A. Eremeev, I. I. Zakharchuk Institute of Cyber Security and Digital Technologies, MIREA - Russian Technological University
Annotation: The article analyzes the existing approaches to evaluating and accounting for the software composition analysis, including open source projects. The analysis of existing frameworks for evaluating software development processes is carried out, including from the point of view of information security. Considered typical risks of using open source components with open licenses. The possibility of evaluating development processes to identify threats to information security in open source projects was noted, as well as the need to automate such a process in order to ensure the efficiency of dependency management in projects using open components as dependencies.
Keywords: software composition analysis, open-source, software development processes maturity.
Pages 58-69