Dependency Network Structure and Security Vulnerabilities in Software Supply Chains

成果类型:
Article
署名作者:
Yoo, Eunae; Craighead, Christopher W.; Samtani, Sagar
署名单位:
Indiana University System; IU Kelley School of Business; Indiana University Bloomington; University of Tennessee System; University of Tennessee Knoxville; Indiana University System; IU Kelley School of Business; Indiana University Bloomington
刊物名称:
JOURNAL OF MANAGEMENT INFORMATION SYSTEMS
ISSN/ISSBN:
0742-1222; 1557-928X
DOI:
10.1080/07421222.2025.2561385
发表日期:
2025-10-02
页码:
1149-1176
关键词:
Dependency network security vulnerability vulnerable dependency software complexity software coupling software supply chain Cybersecurity DATA-BREACH complexity IMPACT RISK performance reliability motivation management failures roles
摘要:
Software packages can be susceptible to attack whenever they utilize dependencies containing security vulnerabilities (vulnerable dependencies). We theorize that the likelihood of relying on vulnerable dependencies is heightened by two structural dimensions of dependency networks: complexity (dependency count) and tight coupling (interdependence). Analyzing 40,049 packages, we find that complexity is positively associated with this likelihood and that vertical complexity (depth) plays a more prominent role than horizontal complexity (breadth). However, tight coupling is negatively associated with the likelihood of vulnerable dependencies. Further analyses reveal that this relationship turns positive with greater complexity but becomes more strongly negative as the number of package developers and the average number of developers per dependency increase. Our findings identify key boundary conditions under which tight coupling may be beneficial and offer a nuanced understanding of how dependency network structure influences the security of dependencies and, more broadly, the security of software supply chains.
来源URL: