OSSIntegrity: Collaborative open-source code integrity verification

Published: 2024, Last Modified: 25 May 2026Comput. Secur. 2024EveryoneRevisionsBibTeXCC BY-SA 4.0
Abstract: Highlights•Focus on targeted open-source software (OSS) supply chain attacks directed at a single organization or an individual user.•Present a secure crowdsource-based code verification, a novel distributed and scalable framework for verifying OSS libraries.•Integrated into the build phase of software production, as an additional step before packaging and deploying the application.•Identify inconsistencies between verifiers’ consensus and the user’s package code preventing any unauthorized alterations.•A total of 127,000 files were evaluated and it took an average of just 26 s to issue an alert against the attacks.
Loading