Publication details

SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems

Authors

POHL Timo NOVÁK Pavel OHM Marc MEIER Michael

Year of publication 2025
Type Article in Proceedings
Conference Availability, Reliability and Security
MU Faculty or unit

Faculty of Informatics

Citation
web https://doi.org/10.1007/978-3-032-00627-1_11
Doi https://doi.org/10.1007/978-3-032-00627-1_11
Keywords reproducible builds; software supply chain security; software packages; software security; library reproducibility
Description The disconnect between distributed software artifacts and their supposed source code enables attackers to leverage the build process for inserting malicious functionality. Past research in this field focuses on compiled language ecosystems, mostly analysing Linux distribution packages. However, the popular scripting language ecosystems potentially face unique issues given the systematic difference in distributed artifacts. This SoK provides an overview of existing research, aiming to highlight future directions, as well as chances to transfer existing knowledge from compiled language ecosystems. To that end, we work out key aspects in current research, systematize identified challenges for software reproducibility, and map them between the ecosystems. We find that the literature is sparse, focusing on few individual problems and ecosystems. This allows us to effectively identify next steps to improve reproducibility in this field.
Related projects:

You are running an old browser version. We recommend updating your browser to its latest version.

More info