Towards a proactive management of Open Source Supply Chains
实现开源供应链的主动管理
基本信息
- 批准号:RGPIN-2021-02476
- 负责人:
- 金额:$ 2.11万
- 依托单位:
- 依托单位国家:加拿大
- 项目类别:Discovery Grants Program - Individual
- 财政年份:2022
- 资助国家:加拿大
- 起止时间:2022-01-01 至 2023-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Open Source Software (OSS), particularly in the form of libraries and frameworks, has become a fundamental part of software development; almost any software today relies on some OSS. A supply chain is a network of entities involved in supplying a product or service to a consumer. An Open Source Supply Chain (OSSC) is a supply chain that involves one or more OSS components that are used without a bilateral agreement between the component creator/maintainer and its customer. Thus, an OSSC is customer managed: the vendor (creator/maintainer of the OSS component being used) is usually not even aware of who its customers (users) are. When organizations incorporate an OSS component, they assume the associated risk with using this component, and cannot rely on support from the creator of the component. Thus, they must be careful when they evaluate and adopt an OSS component into their OSSC. They must also monitor the evolution of their entire OSSC, responding in a timely manner to potential defects (especially security related ones), upgrades, deprecations, and other changes in these components. These challenges are exacerbated by the ever growing number of dependencies required to build a software system today, and the continuous increase in the reuse of OSS components. The goal of this research program is to create models, methods and tools that help organizations proactively manage their Open Source Supply Chains. This will help software organizations reduce the cost and risk of reusing OSS in their OSSC, and improve the quality of the software they build with it.
开源软件(OSS),特别是在库和框架的形式中,已成为软件开发的基本组成部分;如今,几乎所有软件都依赖于某些OSS。供应链是涉及为消费者提供产品或服务的实体网络。开源供应链(OSSC)是一个供应链,涉及一个或多个OSS组件,这些组件在组件创建者/维护者及其客户之间无需双边协议而使用。因此,OSSC是客户管理的:供应商(所使用的OSS组件的创建者/维护者)通常都不知道其客户(用户)是谁。当组织合并OSS组件时,他们会在使用此组件的情况下承担相关的风险,并且不能依靠组件创建者的支持。因此,当他们评估并采用OSS组件中的OSSC时,他们必须小心。他们还必须监视整个OSSC的演变,及时响应潜在的缺陷(尤其是与安全相关的缺陷),这些组件中的升级,折旧和其他变化。当今构建软件系统所需的依赖数量不断增长以及OSS组件的重复使用不断增加所需的依赖性数量不断增长。该研究计划的目的是创建模型,方法和工具,以帮助组织主动管理其开源供应链。这将帮助软件组织降低OSSC中OSS重复使用的成本和风险,并提高其构建的软件的质量。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
German, Daniel其他文献
German, Daniel的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('German, Daniel', 18)}}的其他基金
Towards a proactive management of Open Source Supply Chains
实现开源供应链的主动管理
- 批准号:
RGPIN-2021-02476 - 财政年份:2021
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Improving License Compliance for Software Development
提高软件开发的许可合规性
- 批准号:
RGPIN-2016-04105 - 财政年份:2020
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Improving License Compliance for Software Development
提高软件开发的许可合规性
- 批准号:
RGPIN-2016-04105 - 财政年份:2019
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Improving License Compliance for Software Development
提高软件开发的许可合规性
- 批准号:
RGPIN-2016-04105 - 财政年份:2018
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Improving License Compliance for Software Development
提高软件开发的许可合规性
- 批准号:
RGPIN-2016-04105 - 财政年份:2017
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Improving License Compliance for Software Development
提高软件开发的许可合规性
- 批准号:
RGPIN-2016-04105 - 财政年份:2016
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Source code licensing as an essential aspect of modern software development
源代码许可是现代软件开发的一个重要方面
- 批准号:
250376-2011 - 财政年份:2015
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Source code licensing as an essential aspect of modern software development
源代码许可是现代软件开发的一个重要方面
- 批准号:
250376-2011 - 财政年份:2014
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Source code licensing as an essential aspect of modern software development
源代码许可是现代软件开发的一个重要方面
- 批准号:
250376-2011 - 财政年份:2013
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Source code licensing as an essential aspect of modern software development
源代码许可是现代软件开发的一个重要方面
- 批准号:
412373-2011 - 财政年份:2013
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Accelerator Supplements
相似海外基金
Developing a PROACTIVE telemedicine-related incident management system
开发主动式远程医疗相关事件管理系统
- 批准号:
24K07926 - 财政年份:2024
- 资助金额:
$ 2.11万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
Proactive Intelligent Construction Site Management Enabled by Automated On Site Monitoring (PRISM)
通过自动化现场监控 (PRISM) 实现主动式智能施工现场管理
- 批准号:
10081748 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
Collaborative R&D
Development of intelligent multisensoRy tEchnology For proactIve asset managemenT (REFIT)
开发用于主动资产管理(REFIT)的智能多感官技术
- 批准号:
10075727 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
Launchpad
MICA: Stomasense: A New Route to the Proactive Detection and Management of Leaks within Ostomy Pouches
MICA:Stomasense:主动检测和管理造口袋内泄漏的新途径
- 批准号:
MR/W029561/1 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
Research Grant