Package Dashboard: A Cross-Ecosystem Framework for Dual-Perspective Analysis of Software Packages
Ziheng Liu, Runzhi He, Minghui Zhou

TL;DR
Package Dashboard offers a comprehensive cross-ecosystem platform for analyzing software supply chain risks by integrating package metadata, vulnerability data, and community health metrics, thereby enhancing transparency and risk assessment.
Contribution
It introduces a novel unified framework that combines dependency resolution and repository analysis across multiple ecosystems for holistic supply chain risk analysis.
Findings
Analyzed 374,000 packages across five Linux distributions.
Uncovered risks like archived or inaccessible repositories.
Improved risk detection beyond traditional vulnerability assessments.
Abstract
Software supply chain attacks have revealed blind spots in existing SCA tools, which are often limited to a single ecosystem and assess either software artifacts or community activity in isolation. This fragmentation across tools and ecosystems forces developers to manually reconcile scattered data, undermining risk assessments. We present Package Dashboard, a cross-ecosystem framework that provides a unified platform for supply chain analysis, enabling a holistic, dual-perspective risk assessment by integrating package metadata, vulnerability information, and upstream community health metrics. By combining dependency resolution with repository analysis, it reduces cognitive load and improves traceability. Demonstrating the framework's versatility, a large-scale study of 374,000 packages across five Linux distributions shows its ability to uncover not only conventional vulnerabilities…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware Engineering Research · Advanced Malware Detection Techniques · Information and Cyber Security
