| [1]纪守领, 王琴应, 陈安莹, 等. 开源软件供应链安全研究综述[J]. 软件学报, 2023, 34(3): 13301364[2]高恺, 何昊, 谢冰, 等. 开源软件供应链研究综述[J]. 软件学报, 2024, 35(2): 581603[3]Zimmermann M, Staicu C A, Tenny C, et al. Small world with high risks: A study of security threats in the npm ecosystem[C] Proc of the 29th USENIX Security Symposium. Berkeley, CA: USENIX Association, 2020: 118[4]张晓玉, 陈河. 从SolarWinds事件看软件供应链攻击的特点及影响[J]. 网信军民融合, 2021 (4): 3740[5]Ohm M, Sykosch A, Meier M, et al. Backstabber’s knife collection: A review of open source software supply chain security[J]. IEEE Security & Privacy, 2023, 21(4): 6876[6]王江, 姜伟, 张璨. 开源软件供应链安全风险分析研究[J]. 信息安全研究, 2024, 10(9): 862869[7]陈克豪, 程伟, 丁荪, 等. 开源组件安全面对安全左移带来的挑战研究[J]. 软件导刊, 2022, 21(11): 3238[8]The Linux Foundation. SPDX specification version 2.3[EBOL]. San Francisco: The Linux Foundation, (20220810) [20260306]. https:spdx.github.iospdxspecv2.3[citation:2][citation:5][9]National Telecommunications and Information Administration (NTIA). Software bill of materials (SBOM) minimum elements[EBOL]. Washington, DC: NTIA, (20210712) [20260306]. https:www.ntia.govreport2021minimumelementssoftwarebillmaterialssbom[citation:8][citation:10][10]Wang M, Wu P, Luo Q. Construction of software supply chain threat portrait based on chain pPerspective[J]. Mathematics, 2023, 11(23): 4721[11]张蕾, 闻书韵. 基础软件供应链安全现状分析与对策建议[J]. 信息安全研究, 2024, 10(8): 780784[12]Google LLC. OSVscanner: Vulnerability scanner for open source[EBOL]. Mountain View: Google LLC, (20230921) [20260306]. https:github.comgoogleosvscanner[13]Microsoft Corp. CodeQL: Analyze code to find vulnerabilities[EBOL]. Redmond: Microsoft Corp, (20240220) [20260306]. https:codeql.github.comdocs[14]Open Source Security Foundation (OpenSSF). Supplychain Levels for Software Artifacts (SLSA)[EBOL]. San Francisco: Open Source Security Foundation, (20230910) [20260306]. https:slsa.devspecv1.0[15]GitHub, Inc. Securing GitHub Actions[EBOL]. San Francisco: GitHub, Inc, (20241018) [20260306]. https:docs.github.comenactionssecurityforgithubactionsguidessecurityguidesforgithubactions[16]窦克勤, 宋昱光, 焦铸金, 等. 基于成熟度视角的数字化供应链评价研究[J]. 新型工业化, 2024, 14(7): 2535[17]李彦峰, 张卫博, 赵新强, 等. 美国软件供应链安全政策的演进及对我国的启示[J]. 中国信息安全, 2024 (7): 3337[18]刘井强, 田星, 舒钰淇, 等. 大模型赋能软件供应链开发环节安全研究综述[J]. 信息安全学报, 2024, 9(5): 87109[19]杨丽蕴, 于昕, 子芽. 开源软件供应链安全评价国外实践[J]. 保密科学技术, 2024 (2): 1015[20]郭雪. 全球开源生态发展现状、趋势与对策建议[J]. 中国科学院院刊, 2025, 40(3): 471476[21]Bahl S, Wali P O. An empirical analysis of perceived significance of information security service quality to predict the organisational performance in software service industry[J]. CSI Transactions on ICT, 2013, 1(3): 221230[22]郭敏, 倪辰, 陆琳. 交互式应用安全测试在等级测评中的实践[COL] 2019中国网络安全等级保护和关键信息基础设施保护大会论文集. 2019: 6063 [20260306]. https:kns.cnki.netkcms2arti[23]杨胜蓝, 邓家磊, 黄太奇, 等. 美军软件工厂关键技术分析及启示[J]. 指挥信息系统与技术, 2025, 16(1): 18, 14[24]Gital Y, Bilgen B. Biomass supply chain network design under uncertainty, risk and resilience: A systematic literature review[J]. Computers & Industrial Engineering, 2024, 193: 110270[25]全国信息安全标准化技术委员会. GBT 43698—2024 网络安全技术 软件供应链安全要求[S]. 北京: 中国标准出版社, 2024[26]中国软件评测中心. 软件供应链安全能力评估规范[S]. 北京: 中国软件测评中心, 2024[27]李晓东, 毕冉. 智能体AI应用新浪潮人机协作新图景[N]. 人民邮电, 20250313(005) |