SlideShare a Scribd company logo
1 of 72
Download to read offline
Gail Murphy

Univ. of British Columbia
Tasktop Technologies

Software Supply Chains
@gail_murphy
Photo copyright Wierink/Shutterstock
With exception of pictures and icons
2
○
○○
○ ○○
○
○
○
iPhone Supply Chain
Source: Supply Chain 24/7, 09/14
California:

Design
TI:

Touchscreen
Micron:

Flash memory
Cirrus Logic:

Audio
Murata:

Bluetooth/

Wifi
Infineon:

Phone
network
Dialog
Semiconductors:

Power mngmt
Samsung:

Processors
ST

Microelectronics:

Accelerometers/

Gysroscope
3
Software Supply Chains
Loose Tight
4
Loose Software Supply Chain
component

requests
17.2B
suppliers
total 

components
>105K >834K
2014: Central Repository of Java open source components
2015 State of the Software: Supply Chain Report (Sonatype)
5
Tight Software Supply Chain
6
All is good?
7
Outline
Reality: Loose Supply Chain
Naïve View
Reality: Tight Supply Chain
„
ä
"
8
Open Problems
Key points:
(re)use is not free
controlled transparency
Caveats:
challenges over solutions
"
Naïve View
10
specialized excellence
lower costs
higher quality


Supply Chain: suppliers, parts, manufacturers, finished goods…
Naïve View
11
Software Supply Chain Spectrum
Naïve View
Loose Tight
Bouncy Castle

used >> 10K organizations
12Naïve View
Loose
(vast) majority of developers are part of a software supply chain
suppliers components YOU! software
13Naïve View
Loose
suppliers
total 

components
>105K >834K
central repository GitHub project dependences
14Naïve View
Loose
build products (and other components) faster

higher-quality components
low cost to (re)use
ongoing updates
{
{
{
{
15Naïve View
Tight
multiple tiers of contractually-obligated suppliers
Boeing General Electric Hydro-Aire
16Naïve View
Tight
higher-quality components
on-time production
lower overall product cost
{
{
{
17
Software Supply Chains
Loose Tight
faster, better, cheaper
open closed
Reality View:



Loose Supply
Chain
Photo copyright Gniot/Shutterstock
19Reality View / Loose Supply Chain
Two Parts
Social
S
Quality
Q
20Reality View / Loose Supply Chain
Social Implications of OSS Library Use
S
How often does the use of an OSS library
lead to a social link between projects?
Do social contributions occur before or after
a dependence is introduced on a library?
What kind of social contributions occur?
#1
#2
#3
Palyart and Murphy, 2015, under review
21
Terminology
Reality View / Loose Supply Chain S
A B
technical dependence
social interactions
issue
comments
pull request
commit
Palyart and Murphy, 2015, under review
user

project/
repository
library

project/
repository
22
Data
Reality View / Loose Supply Chain S
23,059 - not a fork
- public
- forked at least twice
- use Maven
17,900 - depend on GitHub 1,227 - high confidence in 

correct library dependences
1,409 - > 20 issues
- issues > 5% pull requests
- handle account deletions
=1,125 GitHub repos
Palyart and Murphy, 2015, under review
23
Data
Reality View / Loose Supply Chain S
A B
Library / Date
Technical Link
Dev / Date / Contrib
issue
comments
pull request
commit
Social Link
Palyart and Murphy, 2015, under review
24
#1 - How often does library use lead to social links?
Reality View / Loose Supply Chain S
Guava
mcMMO
Vault
Netty
Assertj
Junit
AppsgateJSONassert
0%
25%
50%
75%
100%
4 32 256 2048
Number of user repositories
Rs:Ratioofuserrepositorieshavingasociallink
Palyart and Murphy, 2015, under review
25
#1 - How often does library use lead to social links?
Reality View / Loose Supply Chain S
Guava
mcMMO
Vault
Netty
Assertj
Junit
AppsgateJSONassert
0%
25%
50%
75%
100%
4 32 256 2048
Number of user repositories
Rs:Ratioofuserrepositorieshavingasociallink
projects that often have
a social link (28%)
Palyart and Murphy, 2015, under review
26
#1 - How often does library use lead to social links?
Reality View / Loose Supply Chain S
Guava
mcMMO
Vault
Netty
Assertj
Junit
AppsgateJSONassert
0%
25%
50%
75%
100%
4 32 256 2048
Number of user repositories
Rs:Ratioofuserrepositorieshavingasociallink
projects that sometimes
have a social link (23%)
Palyart and Murphy, 2015, under review
27
#1 - How often does library use lead to social links?
Reality View / Loose Supply Chain S
Guava
mcMMO
Vault
Netty
Assertj
Junit
AppsgateJSONassert
0%
25%
50%
75%
100%
4 32 256 2048
Number of user repositories
Rs:Ratioofuserrepositorieshavingasociallink
projects that rarely have
a social link (49%)
Palyart and Murphy, 2015, under review
28
#1 - How often does library use lead to social links?
Reality View / Loose Supply Chain S
Guava
mcMMO
Vault
Netty
Assertj
Junit
AppsgateJSONassert
0%
25%
50%
75%
100%
4 32 256 2048
Number of user repositories
Rs:Ratioofuserrepositorieshavingasociallink
generally…

the more popular the library, 

the less likely developers of a user
project are to get involved
Palyart and Murphy, 2015, under review
29
#2 - When do social contributions occur related to library use?
Reality View / Loose Supply Chain S
A B
Technical Link
Social Link
in only 61% of pairs, 

did technical precede social
Palyart and Murphy, 2015, under review
30
#2 - When do social contributions occur related to library use?
Reality View / Loose Supply Chain S
Palyart and Murphy, 2015, under review
July August September October November
in 39% of pairs,
social preceded technical
social before technical
http://www.cs.ubc.ca/~mpalyart/stc_timeline/
31
#2 - When do social contributions occur related to library use?
Reality View / Loose Supply Chain S
0
1000
2000
3000
Social before technical Technical before social
Numberofdays
social before technical


most interactions within a
few months



technical before social



more interactions span a
longer time
time to involvement
Palyart and Murphy, 2015, under review
0
1000
2000
3000
Social before technical Technical before social
Numberofdays
10
1000
Social before technical Technical before social
Numberofdays
1
10
100
1000
10000
Social before technical Technical before social
Numberofcontributions
32
#2 - When do social contributions occur related to library use?
Reality View / Loose Supply Chain S
0
1000
2000
3000
Social before technical Technical before social
Numberofdays
10
1000
Social before technical Technical before social
Numberofdays
social before technical


either short involvement or

quite long



technical before social



most involvement under 5 days
duration of involvement
Palyart and Murphy, 2015, under review
10
1000
Social before technical Technical before social
Numberofdays
1
10
100
1000
10000
Social before technical Technical before social
Numberofcontributions
1
10
100
1000
10000
Social before technical Technical before social
Numberofcontributions
33
#2 - When do social contributions occur related to library use?
Reality View / Loose Supply Chain S
social before technical


more contributions, stronger

communities?



technical before social



mostly < 10 contributions
number of contributions
1
10
100
1000
10000
Social before technical Technical before social
Numberofcontributions
Palyart and Murphy, 2015, under review
0
1000
2000
3000
Social before technical Technical before social
Numberofdays
10
1000
Social before technical Technical before social
Numberofdays
34
#2 - When do social contributions occur related to library use?
Reality View / Loose Supply Chain S
0
1000
2000
3000
Social before technical Technical before social
Numberofdays
10
1000
Social before technical Technical before social
Numberofdays
1
10
100
1000
10000
Social before technical Technical before social
Numberofcontributions
when social before technical (39%)…



more often closely tied to technical and often more
contributions
when technical before social (61%)…
may take a long time for interaction and then the
interactions are often quick

Palyart and Murphy, 2015, under review
35
#3 - What kind of social contributions occur?
Reality View / Loose Supply Chain S
A B
Technical Link
Social Link
Forward
User Library
35% of pairs
seeking help, feature requests, pull requests
Palyart and Murphy, 2015, under review
36
#3 - What kind of social contributions occur?
Reality View / Loose Supply Chain S
A B
Technical Link
Social Link
Backward
User Library
30% of pairs
existing social community between projects
Palyart and Murphy, 2015, under review
37
#3 - What kind of social contributions occur?
Reality View / Loose Supply Chain S
A B
Technical Link
Social Link
Forward & Backward
User Library
35% of pairs
user developers contribute to library
library developers later do pull-request to user project to update library
Palyart and Murphy, 2015, under review
38
#3 - What kind of social contributions occur?
Reality View / Loose Supply Chain S
●
●●●
●●●
●
●●
●●
●
●
●
●
●
●
●
●
●
●
●
●●●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●●●●●●
●
●●●●
●
●●●●●●●●●
●
●●
●
●
●
●
●
●
●●
●
●●●
●
●
●●
●
●●●●●●●●●
●
●
●●●●●
●
●●●
●
●●●
●
●
●●●
●
●●●
●
●
●
●
●●●
●
●●●
●
●●●
●
●●●●
●
●●●●●●
●
●
●
●
●
●
●
●●●
●
●
0
10
20
30
40
BO F&B FO
Numberofdevelopers
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●●
●●●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
0
200
400
600
BO F&B FO
Numberofdays
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●●
●
●
●
●
●
●●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●●●
●
●
●
●
●
●●
●
●
●
●
●
●●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
0
500
1000
1500
2000
BO F&B FO
Numberofcontributions
= backward only = forward &
backward
= forward only
# developers # social contributions
Palyart and Murphy, 2015, under review
39
#3 - What kind of social contributions occur?
Reality View / Loose Supply Chain S
●
●●●
●●●
●
●●
●●
●
●
●
●
●
●
●
●
●
●
●
●●●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●●●●●●
●
●●●●
●
●●●●●●●●●
●
●●
●
●
●
●
●
●
●●
●
●●●
●
●
●●
●
●●●●●●●●●
●
●
●●●●●
●
●●●
●
●●●
●
●
●●●
●
●●●
●
●
●
●
●●●
●
●●●
●
●●●
●
●●●●
●
●●●●●●
●
●
●
●
●
●
●
●●●
●
●
0
10
20
30
40
BO F&B FO
Numberofdevelopers
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●●
●●●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
0
200
400
600
BO F&B FO
Numberofdays
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●●
●
●
●
●
●
●●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●●●
●
●
●
●
●
●●
●
●
●
●
●
●●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
0
500
1000
1500
2000
BO F&B FO
Numberofcontributions
= backward only = forward &
backward
= forward only
Palyart and Murphy, 2015, under review
involvement time
40
#3 - What kind of social contributions occur?
Reality View / Loose Supply Chain S
●
●●●
●●●
●
●●
●●
●
●
●
●
●
●
●
●
●
●
●
●●●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●●●●●●
●
●●●●
●
●●●●●●●●●
●
●●
●
●
●
●
●
●
●●
●
●●●
●
●
●●
●
●●●●●●●●●
●
●
●●●●●
●
●●●
●
●●●
●
●
●●●
●
●●●
●
●
●
●
●●●
●
●●●
●
●●●
●
●●●●
●
●●●●●●
●
●
●
●
●
●
●
●●●
●
●
0
10
20
30
40
BO F&B FO
Numberofdevelopers
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●●
●●●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
0
200
400
600
BO F&B FO
Numberofdays
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●●●
●
●
●
●
●
●●
●
●
●
●●
●
●
●
●
●
●
●
●
●
●
●
●●●
●
●
●
●
●
●●
●
●
●
●
●
●●●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
0
500
1000
1500
2000
BO F&B FO
Numberofcontributions
= backward only = forward &
backward
= forward only
# developers # social contributions
Palyart and Murphy, 2015, under review
more backward social contributions than expected
and their presence indicates a strong social link

involvement time
41
Loose Software Supply Chain
Reality View / Loose Supply Chain
often a social cost to using a library
more often than expected cost to being a library
42Reality / Tight Supply Chain
Two Parts
Social
S
Quality
Q
43Reality View / Loose Supply Chain
Quality Implications of OSS Library Use
Q
component

requests
17.2B
suppliers
total 

components
>105K >834K
2014: Central Repository of Java open source components
2015 State of the Software: Supply Chain Report (Sonatype)
constant
updating
~ 3.5 times / yr
44Reality View / Loose Supply Chain
Quality Implications of OSS Library Use
Q
Almost too Big to Fail, Geer and Corman, USENIX 2014
A B
direct (1-hop)
only 41% of vulnerable dependencies remediated
mean-time-to-repair of these was 390 days
CVSS level 10 - still 224 days to repair
B’
45Reality View / Loose Supply Chain
Quality Implications of OSS Library Use
Q
CVE-2013-2251

CVSS 9.3

Exploitability 10
since identification…
4,076 organizations have downloaded the vulnerable
component 179,050 times
2015 State of the Software: Supply Chain Report (Sonatype)
46Reality View / Loose Supply Chain
Quality Implications of OSS Library Use
Q
CVE-2007-6721

CVSS 10

Exploitability 10
since identification…
11,236 organizations have downloaded the vulnerable
component 214,484 times
2015 State of the Software: Supply Chain Report (Sonatype)
47Reality View / Loose Supply Chain
Quality Implications of OSS Library Use
Q
2015 State of the Software: Supply Chain Report (Sonatype)
7.5%
66%
of 240,757 component
downloads by large
financial or technology
firms in 2014…
were of known
defective part
and or those with
a defective part,
the defects were
older than 2013
48
Loose Software Supply Chain
Reality View / Loose Supply Chain
(re)use is not free
social and upgrade costs to use
Reality View:
Tight Supply

Chain
Photo copyright Gniot/Shutterstock
50Reality / Tight Supply Chain
Two Parts
Social
S
Quality
Q
51
Tight Software Supply Chain
Reality / Tight Supply Chains S
contractual
agreement
contractual
agreement
52
Tight Software Supply Chain
Reality / Tight Supply Chains
Boeing
General
Electric
Hydro-
Aire
S
contractual
agreement
contractual
agreement
53
Communication
Reality / Tight Supply Chains S
contractual
agreement
contractual
agreement
restricted
information flow
restricted
information flow
54
Communication
Reality / Tight Supply Chains S
contractual
agreement
contractual
agreement
Req Change #2
Req Change #1
Test Result #3
55
Communication
Reality / Tight Supply Chains S
contractual
agreement
contractual
agreement
Req Change #2
Req Change #1
Test Result #3
56
Communication
Reality / Tight Supply Chains S
contractual
agreement
contractual
agreement
57
Communication
Reality / Tight Supply Chains S
Doors

RTC
HP Quality Center
Blueprint
RTC
HP Quality Center
VersionOne
Eclipse
HP Quality Center
58
Communication
Reality / Tight Supply Chains S
Doors

RTC
HP Quality Center
Blueprint
RTC
HP Quality Center
VersionOne
Eclipse
HP Quality Center
Schema
Mappings
Schema
Mappings
59
Tight Software Supply Chain
Reality View / Loose Supply Chain
need tools to facilitate
appropriate communication
60Reality / Tight Supply Chain
Two Parts
Social
S
Quality
Q
61
Tight Software Supply Chain
Reality / Tight Supply Chains
Boeing
General
Electric
Hydro-
Aire
Q
ability to verify the
brake software
wasn’t built in
62
Tight Software Supply Chain
Reality / Tight Supply Chains
Boeing
General
Electric
Hydro-
Aire
Q
full transparency

full opacity
63
Tight Software Supply Chain
Reality / Tight Supply Chains Q
controlled transparency
balance need to share with
protection of intellectual property
Open

Problems
Illustration copyright Ai825/Shutterstock
65Open Problems
Loose Software Supply Chains






assess when
a component
upgrade
is needed?




lower the cost
of quality and
security upgrades?






measure

and predict

social cost of

component use?












determine when
backward social

contributions are

needed?
can we….
ä ä ä ä
66Open Problems
Tight Software Supply Chains










cost-effectively
manage
multi-tiered
supply chains?




effectively handle
arrangements of
tight and loose
supply chains?






automatically
apply IP
filters to
information
exchange?






provide white-box
information without
revealing secret
sauce?
can we….
ä ä ä ä
Illustration copyright
Nenov Brothers Images
/Shutterstock
68Summary
Thanks to many post-docs, students and industrial collaborators over the years for their insights.



Thanks to NECSIS colleagues (particularly Jo Atlee, Marsha Chechik and Mark Lawford)

for conversations.
Thanks to Sonatype for an analysis of the Central Repository.
Marc Palyart Mik Kersten Dave West
69Summary
Software Supply Chains
Naïve
Better, faster, cheaper
Loose Supply Chain
Reuse is not free
Tight Supply Chain
Controlled transparencyNaïve
Tight
Loose
Open
Open Problems
Technical and ecosystem
70Summary
Software Supply Chains
“supply chain” conjures up thoughts of
organized, managed flows
for software supply chains, the reality
is different (chaotic? brittle?)
(re)use is not free
controlled transparency
@gail_murphy
Loose Tight
Photo copyright Wierink/Shutterstock
71Summary
Software Supply Chains
“supply chain” conjures up thoughts of
organized, managed flows
for software supply chains, the reality
is different (chaotic? brittle?)
(re)use is not free
controlled transparency
@gail_murphy
Loose Tight
Photo copyright Wierink/Shutterstock
Gail Murphy

Univ. of British Columbia
Tasktop Technologies

Software Supply Chains
@gail_murphy
Photo copyright Wierink/Shutterstock
With exception of pictures and icons

More Related Content

What's hot

SUPPLYCHAIN PROCESS FLOW CHART
SUPPLYCHAIN PROCESS FLOW CHARTSUPPLYCHAIN PROCESS FLOW CHART
SUPPLYCHAIN PROCESS FLOW CHART
Andrew Mugambi
 
Apple Supply Chain Mgmt
Apple Supply Chain MgmtApple Supply Chain Mgmt
Apple Supply Chain Mgmt
Lloyd Soans
 
Tafe - New Centralized Warehouse
Tafe - New Centralized WarehouseTafe - New Centralized Warehouse
Tafe - New Centralized Warehouse
Anif Antony Amalan
 

What's hot (20)

S&OP FINAL
S&OP FINALS&OP FINAL
S&OP FINAL
 
Supply Chain Management, Designing the Supply Chain Network
Supply Chain Management, Designing the Supply Chain NetworkSupply Chain Management, Designing the Supply Chain Network
Supply Chain Management, Designing the Supply Chain Network
 
Ariba Coverage of Risk Management within the Supplier Lifecycle
Ariba Coverage of Risk Management within the Supplier LifecycleAriba Coverage of Risk Management within the Supplier Lifecycle
Ariba Coverage of Risk Management within the Supplier Lifecycle
 
SUPPLYCHAIN PROCESS FLOW CHART
SUPPLYCHAIN PROCESS FLOW CHARTSUPPLYCHAIN PROCESS FLOW CHART
SUPPLYCHAIN PROCESS FLOW CHART
 
Supplier Management 101: Drive Spend Toward Preferred Suppliers and Reduce Risk
Supplier Management 101: Drive Spend Toward Preferred Suppliers and Reduce Risk Supplier Management 101: Drive Spend Toward Preferred Suppliers and Reduce Risk
Supplier Management 101: Drive Spend Toward Preferred Suppliers and Reduce Risk
 
Supply chain relationships and collaboration
Supply chain relationships and collaborationSupply chain relationships and collaboration
Supply chain relationships and collaboration
 
Apple case study
Apple case studyApple case study
Apple case study
 
How Zappos Built a Billion Dollar Company Through a Customer Focused Culture
How Zappos Built a Billion Dollar Company Through a Customer Focused CultureHow Zappos Built a Billion Dollar Company Through a Customer Focused Culture
How Zappos Built a Billion Dollar Company Through a Customer Focused Culture
 
Apple Supply Chain Mgmt
Apple Supply Chain MgmtApple Supply Chain Mgmt
Apple Supply Chain Mgmt
 
Supply Chain Process Improvement
Supply Chain Process ImprovementSupply Chain Process Improvement
Supply Chain Process Improvement
 
Ultimate Guide to Supply Chain Resiliency Program Success
Ultimate Guide to Supply Chain Resiliency Program SuccessUltimate Guide to Supply Chain Resiliency Program Success
Ultimate Guide to Supply Chain Resiliency Program Success
 
Tafe - New Centralized Warehouse
Tafe - New Centralized WarehouseTafe - New Centralized Warehouse
Tafe - New Centralized Warehouse
 
Warehouse Management System
Warehouse Management SystemWarehouse Management System
Warehouse Management System
 
Merck’s Supply Chain Collaboration with Contract Manufacturers and Direct Sup...
Merck’s Supply Chain Collaboration with Contract Manufacturers and Direct Sup...Merck’s Supply Chain Collaboration with Contract Manufacturers and Direct Sup...
Merck’s Supply Chain Collaboration with Contract Manufacturers and Direct Sup...
 
S&OP Introduction
S&OP IntroductionS&OP Introduction
S&OP Introduction
 
Guided Buying: Exploration and Best Practices
Guided Buying: Exploration and Best PracticesGuided Buying: Exploration and Best Practices
Guided Buying: Exploration and Best Practices
 
Vendor Managed Inventory
Vendor Managed InventoryVendor Managed Inventory
Vendor Managed Inventory
 
Kpis for scm
Kpis for scmKpis for scm
Kpis for scm
 
Sap ewm detailed presentation
Sap ewm detailed presentationSap ewm detailed presentation
Sap ewm detailed presentation
 
Transform Procurement with the SAP S/4HANA Digital Core and SAP Ariba Solutions
Transform Procurement with the SAP S/4HANA Digital Core and SAP Ariba SolutionsTransform Procurement with the SAP S/4HANA Digital Core and SAP Ariba Solutions
Transform Procurement with the SAP S/4HANA Digital Core and SAP Ariba Solutions
 

Similar to Software Supply Chains

Embracing Web 2.0 - Archives and the Next Generation of Web Apps
Embracing Web 2.0 - Archives and the Next Generation of Web AppsEmbracing Web 2.0 - Archives and the Next Generation of Web Apps
Embracing Web 2.0 - Archives and the Next Generation of Web Apps
guestf0bb3e
 
Social Information & Browsing March 6
Social Information & Browsing   March 6Social Information & Browsing   March 6
Social Information & Browsing March 6
sritikumar
 
Privacy Concerns vs. User Behavior in Community Question Answering
Privacy Concerns vs. User Behavior in Community Question AnsweringPrivacy Concerns vs. User Behavior in Community Question Answering
Privacy Concerns vs. User Behavior in Community Question Answering
Nicolas Kourtellis
 

Similar to Software Supply Chains (20)

Findings Revealed: 2015 State of the Software Supply Chain
Findings Revealed: 2015 State of the Software Supply Chain Findings Revealed: 2015 State of the Software Supply Chain
Findings Revealed: 2015 State of the Software Supply Chain
 
Embracing Web 2.0 - Archives and the Next Generation of Web Apps
Embracing Web 2.0 - Archives and the Next Generation of Web AppsEmbracing Web 2.0 - Archives and the Next Generation of Web Apps
Embracing Web 2.0 - Archives and the Next Generation of Web Apps
 
Energy Patterns for Web: An Exploratory Study
Energy Patterns for Web: An Exploratory StudyEnergy Patterns for Web: An Exploratory Study
Energy Patterns for Web: An Exploratory Study
 
Twitter analytics: some thoughts on sampling, tools, data, ethics and user re...
Twitter analytics: some thoughts on sampling, tools, data, ethics and user re...Twitter analytics: some thoughts on sampling, tools, data, ethics and user re...
Twitter analytics: some thoughts on sampling, tools, data, ethics and user re...
 
LAM 2015 - Social Networks Technologies
LAM 2015 - Social Networks TechnologiesLAM 2015 - Social Networks Technologies
LAM 2015 - Social Networks Technologies
 
Social Information & Browsing March 6
Social Information & Browsing   March 6Social Information & Browsing   March 6
Social Information & Browsing March 6
 
Blockchain
BlockchainBlockchain
Blockchain
 
The evolution of research on social media
The evolution of research on social mediaThe evolution of research on social media
The evolution of research on social media
 
Enhancing user engagement on mobile devices
Enhancing user engagement on mobile devicesEnhancing user engagement on mobile devices
Enhancing user engagement on mobile devices
 
Implications of Open Source Software Use (or Let's Talk Open Source)
Implications of Open Source Software Use (or Let's Talk Open Source)Implications of Open Source Software Use (or Let's Talk Open Source)
Implications of Open Source Software Use (or Let's Talk Open Source)
 
Managing Community Contributions: Lessons Learned from a Case Study on Andro...
Managing Community Contributions:  Lessons Learned from a Case Study on Andro...Managing Community Contributions:  Lessons Learned from a Case Study on Andro...
Managing Community Contributions: Lessons Learned from a Case Study on Andro...
 
Privacy Concerns vs. User Behavior in Community Question Answering
Privacy Concerns vs. User Behavior in Community Question AnsweringPrivacy Concerns vs. User Behavior in Community Question Answering
Privacy Concerns vs. User Behavior in Community Question Answering
 
Crowdsourcing and data journalism
Crowdsourcing and data journalism Crowdsourcing and data journalism
Crowdsourcing and data journalism
 
ICSE10 StakeSource Talk
ICSE10 StakeSource TalkICSE10 StakeSource Talk
ICSE10 StakeSource Talk
 
2015 pdf-marc smith-node xl-social media sna
2015 pdf-marc smith-node xl-social media sna2015 pdf-marc smith-node xl-social media sna
2015 pdf-marc smith-node xl-social media sna
 
SENTIMENT ANALYSIS OF SOCIAL MEDIA DATA USING DEEP LEARNING
SENTIMENT ANALYSIS OF SOCIAL MEDIA DATA USING DEEP LEARNINGSENTIMENT ANALYSIS OF SOCIAL MEDIA DATA USING DEEP LEARNING
SENTIMENT ANALYSIS OF SOCIAL MEDIA DATA USING DEEP LEARNING
 
Io t loraalliance-marketingday_vfinal
Io t loraalliance-marketingday_vfinalIo t loraalliance-marketingday_vfinal
Io t loraalliance-marketingday_vfinal
 
NYPL Internet Lending pre-pilot OST survey results
NYPL Internet Lending pre-pilot OST survey resultsNYPL Internet Lending pre-pilot OST survey results
NYPL Internet Lending pre-pilot OST survey results
 
WiFi: Current And Future Opportunities
WiFi: Current And Future Opportunities WiFi: Current And Future Opportunities
WiFi: Current And Future Opportunities
 
Digital Generation
Digital GenerationDigital Generation
Digital Generation
 

More from Gail Murphy

More from Gail Murphy (16)

Architecting-Flow-in-SE.pdf
Architecting-Flow-in-SE.pdfArchitecting-Flow-in-SE.pdf
Architecting-Flow-in-SE.pdf
 
The (Un) Expected Impact of Tools in Software Evolution
The (Un) Expected Impact of Tools in Software EvolutionThe (Un) Expected Impact of Tools in Software Evolution
The (Un) Expected Impact of Tools in Software Evolution
 
Icsme 2021-keynote-creating-usable-and-useful-software-tools
Icsme 2021-keynote-creating-usable-and-useful-software-toolsIcsme 2021-keynote-creating-usable-and-useful-software-tools
Icsme 2021-keynote-creating-usable-and-useful-software-tools
 
Is software engineering research addressing software engineering problems?
Is software engineering research addressing software engineering problems?Is software engineering research addressing software engineering problems?
Is software engineering research addressing software engineering problems?
 
Developing Effective Software Productively
Developing Effective Software ProductivelyDeveloping Effective Software Productively
Developing Effective Software Productively
 
Making Effective, Useful Software Development Tools
Making Effective, Useful Software Development ToolsMaking Effective, Useful Software Development Tools
Making Effective, Useful Software Development Tools
 
The Need for Context in Software Engineering
The Need for Context in Software EngineeringThe Need for Context in Software Engineering
The Need for Context in Software Engineering
 
Beyond DevOps: Finding Value through Requirements
Beyond DevOps: Finding Value through RequirementsBeyond DevOps: Finding Value through Requirements
Beyond DevOps: Finding Value through Requirements
 
Impactful SE Research: Some Do's and More Don'ts
Impactful SE Research: Some Do's and More Don'tsImpactful SE Research: Some Do's and More Don'ts
Impactful SE Research: Some Do's and More Don'ts
 
The Elusive Nature of Context: Why We Need It and Were We Might Find It
The Elusive Nature of Context: Why We Need It and Were We Might Find ItThe Elusive Nature of Context: Why We Need It and Were We Might Find It
The Elusive Nature of Context: Why We Need It and Were We Might Find It
 
Human-centric Software Development Tools
Human-centric Software Development ToolsHuman-centric Software Development Tools
Human-centric Software Development Tools
 
Is Continuous Adoption in Software Engineering Achievable and Desirable?
Is Continuous Adoption in Software Engineering Achievable and Desirable? Is Continuous Adoption in Software Engineering Achievable and Desirable?
Is Continuous Adoption in Software Engineering Achievable and Desirable?
 
Acm productivity-webinar-2016-slides
Acm productivity-webinar-2016-slidesAcm productivity-webinar-2016-slides
Acm productivity-webinar-2016-slides
 
Getting to Flow in Software Development (ASWEC 2014 Keynote)
Getting to Flow in Software Development (ASWEC 2014 Keynote)Getting to Flow in Software Development (ASWEC 2014 Keynote)
Getting to Flow in Software Development (ASWEC 2014 Keynote)
 
The Human Element
The Human ElementThe Human Element
The Human Element
 
What is Software Development Productivity Anyway?
What is Software Development Productivity Anyway?What is Software Development Productivity Anyway?
What is Software Development Productivity Anyway?
 

Recently uploaded

%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
masabamasaba
 
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
masabamasaba
 
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
masabamasaba
 
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
masabamasaba
 

Recently uploaded (20)

%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand
 
WSO2Con2024 - From Code To Cloud: Fast Track Your Cloud Native Journey with C...
WSO2Con2024 - From Code To Cloud: Fast Track Your Cloud Native Journey with C...WSO2Con2024 - From Code To Cloud: Fast Track Your Cloud Native Journey with C...
WSO2Con2024 - From Code To Cloud: Fast Track Your Cloud Native Journey with C...
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
 
Microsoft AI Transformation Partner Playbook.pdf
Microsoft AI Transformation Partner Playbook.pdfMicrosoft AI Transformation Partner Playbook.pdf
Microsoft AI Transformation Partner Playbook.pdf
 
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
 
Artyushina_Guest lecture_YorkU CS May 2024.pptx
Artyushina_Guest lecture_YorkU CS May 2024.pptxArtyushina_Guest lecture_YorkU CS May 2024.pptx
Artyushina_Guest lecture_YorkU CS May 2024.pptx
 
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
 
AI & Machine Learning Presentation Template
AI & Machine Learning Presentation TemplateAI & Machine Learning Presentation Template
AI & Machine Learning Presentation Template
 
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
 
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
 
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
 
Direct Style Effect Systems - The Print[A] Example - A Comprehension Aid
Direct Style Effect Systems -The Print[A] Example- A Comprehension AidDirect Style Effect Systems -The Print[A] Example- A Comprehension Aid
Direct Style Effect Systems - The Print[A] Example - A Comprehension Aid
 
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
 
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
%+27788225528 love spells in Colorado Springs Psychic Readings, Attraction sp...
 
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
 
%in Soweto+277-882-255-28 abortion pills for sale in soweto
%in Soweto+277-882-255-28 abortion pills for sale in soweto%in Soweto+277-882-255-28 abortion pills for sale in soweto
%in Soweto+277-882-255-28 abortion pills for sale in soweto
 
8257 interfacing 2 in microprocessor for btech students
8257 interfacing 2 in microprocessor for btech students8257 interfacing 2 in microprocessor for btech students
8257 interfacing 2 in microprocessor for btech students
 
WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?
 
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
 
Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...
Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...
Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...
 

Software Supply Chains

  • 1. Gail Murphy
 Univ. of British Columbia Tasktop Technologies
 Software Supply Chains @gail_murphy Photo copyright Wierink/Shutterstock With exception of pictures and icons
  • 2. 2 ○ ○○ ○ ○○ ○ ○ ○ iPhone Supply Chain Source: Supply Chain 24/7, 09/14 California:
 Design TI:
 Touchscreen Micron:
 Flash memory Cirrus Logic:
 Audio Murata:
 Bluetooth/
 Wifi Infineon:
 Phone network Dialog Semiconductors:
 Power mngmt Samsung:
 Processors ST
 Microelectronics:
 Accelerometers/
 Gysroscope
  • 4. 4 Loose Software Supply Chain component
 requests 17.2B suppliers total 
 components >105K >834K 2014: Central Repository of Java open source components 2015 State of the Software: Supply Chain Report (Sonatype)
  • 7. 7 Outline Reality: Loose Supply Chain Naïve View Reality: Tight Supply Chain „ ä "
  • 8. 8 Open Problems Key points: (re)use is not free controlled transparency Caveats: challenges over solutions "
  • 10. 10 specialized excellence lower costs higher quality 
 Supply Chain: suppliers, parts, manufacturers, finished goods… Naïve View
  • 11. 11 Software Supply Chain Spectrum Naïve View Loose Tight Bouncy Castle
 used >> 10K organizations
  • 12. 12Naïve View Loose (vast) majority of developers are part of a software supply chain suppliers components YOU! software
  • 13. 13Naïve View Loose suppliers total 
 components >105K >834K central repository GitHub project dependences
  • 14. 14Naïve View Loose build products (and other components) faster
 higher-quality components low cost to (re)use ongoing updates { { { {
  • 15. 15Naïve View Tight multiple tiers of contractually-obligated suppliers Boeing General Electric Hydro-Aire
  • 16. 16Naïve View Tight higher-quality components on-time production lower overall product cost { { {
  • 17. 17 Software Supply Chains Loose Tight faster, better, cheaper open closed
  • 18. Reality View:
 
 Loose Supply Chain Photo copyright Gniot/Shutterstock
  • 19. 19Reality View / Loose Supply Chain Two Parts Social S Quality Q
  • 20. 20Reality View / Loose Supply Chain Social Implications of OSS Library Use S How often does the use of an OSS library lead to a social link between projects? Do social contributions occur before or after a dependence is introduced on a library? What kind of social contributions occur? #1 #2 #3 Palyart and Murphy, 2015, under review
  • 21. 21 Terminology Reality View / Loose Supply Chain S A B technical dependence social interactions issue comments pull request commit Palyart and Murphy, 2015, under review user
 project/ repository library
 project/ repository
  • 22. 22 Data Reality View / Loose Supply Chain S 23,059 - not a fork - public - forked at least twice - use Maven 17,900 - depend on GitHub 1,227 - high confidence in 
 correct library dependences 1,409 - > 20 issues - issues > 5% pull requests - handle account deletions =1,125 GitHub repos Palyart and Murphy, 2015, under review
  • 23. 23 Data Reality View / Loose Supply Chain S A B Library / Date Technical Link Dev / Date / Contrib issue comments pull request commit Social Link Palyart and Murphy, 2015, under review
  • 24. 24 #1 - How often does library use lead to social links? Reality View / Loose Supply Chain S Guava mcMMO Vault Netty Assertj Junit AppsgateJSONassert 0% 25% 50% 75% 100% 4 32 256 2048 Number of user repositories Rs:Ratioofuserrepositorieshavingasociallink Palyart and Murphy, 2015, under review
  • 25. 25 #1 - How often does library use lead to social links? Reality View / Loose Supply Chain S Guava mcMMO Vault Netty Assertj Junit AppsgateJSONassert 0% 25% 50% 75% 100% 4 32 256 2048 Number of user repositories Rs:Ratioofuserrepositorieshavingasociallink projects that often have a social link (28%) Palyart and Murphy, 2015, under review
  • 26. 26 #1 - How often does library use lead to social links? Reality View / Loose Supply Chain S Guava mcMMO Vault Netty Assertj Junit AppsgateJSONassert 0% 25% 50% 75% 100% 4 32 256 2048 Number of user repositories Rs:Ratioofuserrepositorieshavingasociallink projects that sometimes have a social link (23%) Palyart and Murphy, 2015, under review
  • 27. 27 #1 - How often does library use lead to social links? Reality View / Loose Supply Chain S Guava mcMMO Vault Netty Assertj Junit AppsgateJSONassert 0% 25% 50% 75% 100% 4 32 256 2048 Number of user repositories Rs:Ratioofuserrepositorieshavingasociallink projects that rarely have a social link (49%) Palyart and Murphy, 2015, under review
  • 28. 28 #1 - How often does library use lead to social links? Reality View / Loose Supply Chain S Guava mcMMO Vault Netty Assertj Junit AppsgateJSONassert 0% 25% 50% 75% 100% 4 32 256 2048 Number of user repositories Rs:Ratioofuserrepositorieshavingasociallink generally…
 the more popular the library, 
 the less likely developers of a user project are to get involved Palyart and Murphy, 2015, under review
  • 29. 29 #2 - When do social contributions occur related to library use? Reality View / Loose Supply Chain S A B Technical Link Social Link in only 61% of pairs, 
 did technical precede social Palyart and Murphy, 2015, under review
  • 30. 30 #2 - When do social contributions occur related to library use? Reality View / Loose Supply Chain S Palyart and Murphy, 2015, under review July August September October November in 39% of pairs, social preceded technical social before technical http://www.cs.ubc.ca/~mpalyart/stc_timeline/
  • 31. 31 #2 - When do social contributions occur related to library use? Reality View / Loose Supply Chain S 0 1000 2000 3000 Social before technical Technical before social Numberofdays social before technical 
 most interactions within a few months
 
 technical before social
 
 more interactions span a longer time time to involvement Palyart and Murphy, 2015, under review 0 1000 2000 3000 Social before technical Technical before social Numberofdays 10 1000 Social before technical Technical before social Numberofdays 1 10 100 1000 10000 Social before technical Technical before social Numberofcontributions
  • 32. 32 #2 - When do social contributions occur related to library use? Reality View / Loose Supply Chain S 0 1000 2000 3000 Social before technical Technical before social Numberofdays 10 1000 Social before technical Technical before social Numberofdays social before technical 
 either short involvement or
 quite long
 
 technical before social
 
 most involvement under 5 days duration of involvement Palyart and Murphy, 2015, under review 10 1000 Social before technical Technical before social Numberofdays 1 10 100 1000 10000 Social before technical Technical before social Numberofcontributions
  • 33. 1 10 100 1000 10000 Social before technical Technical before social Numberofcontributions 33 #2 - When do social contributions occur related to library use? Reality View / Loose Supply Chain S social before technical 
 more contributions, stronger
 communities?
 
 technical before social
 
 mostly < 10 contributions number of contributions 1 10 100 1000 10000 Social before technical Technical before social Numberofcontributions Palyart and Murphy, 2015, under review 0 1000 2000 3000 Social before technical Technical before social Numberofdays 10 1000 Social before technical Technical before social Numberofdays
  • 34. 34 #2 - When do social contributions occur related to library use? Reality View / Loose Supply Chain S 0 1000 2000 3000 Social before technical Technical before social Numberofdays 10 1000 Social before technical Technical before social Numberofdays 1 10 100 1000 10000 Social before technical Technical before social Numberofcontributions when social before technical (39%)…
 
 more often closely tied to technical and often more contributions when technical before social (61%)… may take a long time for interaction and then the interactions are often quick
 Palyart and Murphy, 2015, under review
  • 35. 35 #3 - What kind of social contributions occur? Reality View / Loose Supply Chain S A B Technical Link Social Link Forward User Library 35% of pairs seeking help, feature requests, pull requests Palyart and Murphy, 2015, under review
  • 36. 36 #3 - What kind of social contributions occur? Reality View / Loose Supply Chain S A B Technical Link Social Link Backward User Library 30% of pairs existing social community between projects Palyart and Murphy, 2015, under review
  • 37. 37 #3 - What kind of social contributions occur? Reality View / Loose Supply Chain S A B Technical Link Social Link Forward & Backward User Library 35% of pairs user developers contribute to library library developers later do pull-request to user project to update library Palyart and Murphy, 2015, under review
  • 38. 38 #3 - What kind of social contributions occur? Reality View / Loose Supply Chain S ● ●●● ●●● ● ●● ●● ● ● ● ● ● ● ● ● ● ● ● ●●● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ●●●●●● ● ●●●● ● ●●●●●●●●● ● ●● ● ● ● ● ● ● ●● ● ●●● ● ● ●● ● ●●●●●●●●● ● ● ●●●●● ● ●●● ● ●●● ● ● ●●● ● ●●● ● ● ● ● ●●● ● ●●● ● ●●● ● ●●●● ● ●●●●●● ● ● ● ● ● ● ● ●●● ● ● 0 10 20 30 40 BO F&B FO Numberofdevelopers ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ●● ●●● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● 0 200 400 600 BO F&B FO Numberofdays ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ●● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ●● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●●● ● ● ● ● ● ●● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ●●● ● ● ● ● ● ●● ● ● ● ● ● ●●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● 0 500 1000 1500 2000 BO F&B FO Numberofcontributions = backward only = forward & backward = forward only # developers # social contributions Palyart and Murphy, 2015, under review
  • 39. 39 #3 - What kind of social contributions occur? Reality View / Loose Supply Chain S ● ●●● ●●● ● ●● ●● ● ● ● ● ● ● ● ● ● ● ● ●●● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ●●●●●● ● ●●●● ● ●●●●●●●●● ● ●● ● ● ● ● ● ● ●● ● ●●● ● ● ●● ● ●●●●●●●●● ● ● ●●●●● ● ●●● ● ●●● ● ● ●●● ● ●●● ● ● ● ● ●●● ● ●●● ● ●●● ● ●●●● ● ●●●●●● ● ● ● ● ● ● ● ●●● ● ● 0 10 20 30 40 BO F&B FO Numberofdevelopers ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ●● ●●● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● 0 200 400 600 BO F&B FO Numberofdays ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ●● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ●● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●●● ● ● ● ● ● ●● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ●●● ● ● ● ● ● ●● ● ● ● ● ● ●●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● 0 500 1000 1500 2000 BO F&B FO Numberofcontributions = backward only = forward & backward = forward only Palyart and Murphy, 2015, under review involvement time
  • 40. 40 #3 - What kind of social contributions occur? Reality View / Loose Supply Chain S ● ●●● ●●● ● ●● ●● ● ● ● ● ● ● ● ● ● ● ● ●●● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ●●●●●● ● ●●●● ● ●●●●●●●●● ● ●● ● ● ● ● ● ● ●● ● ●●● ● ● ●● ● ●●●●●●●●● ● ● ●●●●● ● ●●● ● ●●● ● ● ●●● ● ●●● ● ● ● ● ●●● ● ●●● ● ●●● ● ●●●● ● ●●●●●● ● ● ● ● ● ● ● ●●● ● ● 0 10 20 30 40 BO F&B FO Numberofdevelopers ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ●● ●●● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● 0 200 400 600 BO F&B FO Numberofdays ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ●● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●● ● ● ● ●● ● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ●●● ● ● ● ● ● ●● ● ● ● ●● ● ● ● ● ● ● ● ● ● ● ● ●●● ● ● ● ● ● ●● ● ● ● ● ● ●●● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● ● 0 500 1000 1500 2000 BO F&B FO Numberofcontributions = backward only = forward & backward = forward only # developers # social contributions Palyart and Murphy, 2015, under review more backward social contributions than expected and their presence indicates a strong social link
 involvement time
  • 41. 41 Loose Software Supply Chain Reality View / Loose Supply Chain often a social cost to using a library more often than expected cost to being a library
  • 42. 42Reality / Tight Supply Chain Two Parts Social S Quality Q
  • 43. 43Reality View / Loose Supply Chain Quality Implications of OSS Library Use Q component
 requests 17.2B suppliers total 
 components >105K >834K 2014: Central Repository of Java open source components 2015 State of the Software: Supply Chain Report (Sonatype) constant updating ~ 3.5 times / yr
  • 44. 44Reality View / Loose Supply Chain Quality Implications of OSS Library Use Q Almost too Big to Fail, Geer and Corman, USENIX 2014 A B direct (1-hop) only 41% of vulnerable dependencies remediated mean-time-to-repair of these was 390 days CVSS level 10 - still 224 days to repair B’
  • 45. 45Reality View / Loose Supply Chain Quality Implications of OSS Library Use Q CVE-2013-2251
 CVSS 9.3
 Exploitability 10 since identification… 4,076 organizations have downloaded the vulnerable component 179,050 times 2015 State of the Software: Supply Chain Report (Sonatype)
  • 46. 46Reality View / Loose Supply Chain Quality Implications of OSS Library Use Q CVE-2007-6721
 CVSS 10
 Exploitability 10 since identification… 11,236 organizations have downloaded the vulnerable component 214,484 times 2015 State of the Software: Supply Chain Report (Sonatype)
  • 47. 47Reality View / Loose Supply Chain Quality Implications of OSS Library Use Q 2015 State of the Software: Supply Chain Report (Sonatype) 7.5% 66% of 240,757 component downloads by large financial or technology firms in 2014… were of known defective part and or those with a defective part, the defects were older than 2013
  • 48. 48 Loose Software Supply Chain Reality View / Loose Supply Chain (re)use is not free social and upgrade costs to use
  • 49. Reality View: Tight Supply
 Chain Photo copyright Gniot/Shutterstock
  • 50. 50Reality / Tight Supply Chain Two Parts Social S Quality Q
  • 51. 51 Tight Software Supply Chain Reality / Tight Supply Chains S contractual agreement contractual agreement
  • 52. 52 Tight Software Supply Chain Reality / Tight Supply Chains Boeing General Electric Hydro- Aire S contractual agreement contractual agreement
  • 53. 53 Communication Reality / Tight Supply Chains S contractual agreement contractual agreement restricted information flow restricted information flow
  • 54. 54 Communication Reality / Tight Supply Chains S contractual agreement contractual agreement Req Change #2 Req Change #1 Test Result #3
  • 55. 55 Communication Reality / Tight Supply Chains S contractual agreement contractual agreement Req Change #2 Req Change #1 Test Result #3
  • 56. 56 Communication Reality / Tight Supply Chains S contractual agreement contractual agreement
  • 57. 57 Communication Reality / Tight Supply Chains S Doors
 RTC HP Quality Center Blueprint RTC HP Quality Center VersionOne Eclipse HP Quality Center
  • 58. 58 Communication Reality / Tight Supply Chains S Doors
 RTC HP Quality Center Blueprint RTC HP Quality Center VersionOne Eclipse HP Quality Center Schema Mappings Schema Mappings
  • 59. 59 Tight Software Supply Chain Reality View / Loose Supply Chain need tools to facilitate appropriate communication
  • 60. 60Reality / Tight Supply Chain Two Parts Social S Quality Q
  • 61. 61 Tight Software Supply Chain Reality / Tight Supply Chains Boeing General Electric Hydro- Aire Q ability to verify the brake software wasn’t built in
  • 62. 62 Tight Software Supply Chain Reality / Tight Supply Chains Boeing General Electric Hydro- Aire Q full transparency
 full opacity
  • 63. 63 Tight Software Supply Chain Reality / Tight Supply Chains Q controlled transparency balance need to share with protection of intellectual property
  • 65. 65Open Problems Loose Software Supply Chains 
 
 
 assess when a component upgrade is needed? 
 
 lower the cost of quality and security upgrades? 
 
 
 measure
 and predict
 social cost of
 component use? 
 
 
 
 
 
 determine when backward social
 contributions are
 needed? can we…. ä ä ä ä
  • 66. 66Open Problems Tight Software Supply Chains 
 
 
 
 
 cost-effectively manage multi-tiered supply chains? 
 
 effectively handle arrangements of tight and loose supply chains? 
 
 
 automatically apply IP filters to information exchange? 
 
 
 provide white-box information without revealing secret sauce? can we…. ä ä ä ä
  • 68. 68Summary Thanks to many post-docs, students and industrial collaborators over the years for their insights.
 
 Thanks to NECSIS colleagues (particularly Jo Atlee, Marsha Chechik and Mark Lawford)
 for conversations. Thanks to Sonatype for an analysis of the Central Repository. Marc Palyart Mik Kersten Dave West
  • 69. 69Summary Software Supply Chains Naïve Better, faster, cheaper Loose Supply Chain Reuse is not free Tight Supply Chain Controlled transparencyNaïve Tight Loose Open Open Problems Technical and ecosystem
  • 70. 70Summary Software Supply Chains “supply chain” conjures up thoughts of organized, managed flows for software supply chains, the reality is different (chaotic? brittle?) (re)use is not free controlled transparency @gail_murphy Loose Tight Photo copyright Wierink/Shutterstock
  • 71. 71Summary Software Supply Chains “supply chain” conjures up thoughts of organized, managed flows for software supply chains, the reality is different (chaotic? brittle?) (re)use is not free controlled transparency @gail_murphy Loose Tight Photo copyright Wierink/Shutterstock
  • 72. Gail Murphy
 Univ. of British Columbia Tasktop Technologies
 Software Supply Chains @gail_murphy Photo copyright Wierink/Shutterstock With exception of pictures and icons