[1]中华人民共和国中央人民政府. 互联网政务应用安全管理规定[EBOL]. [20240523]. https:www.gov.cnlianbobumen202405content_6952956.htm[2]纪守领, 王琴应, 陈安莹, 等. 开源软件供应链安全研究综述[J]. 软件学报, 2023, 34(3): 13301364[3]王江, 姜伟, 张璨. 开源软件供应链安全风险分析研究[J]. 信息安全研究, 2024, 10(9): 862869[4]蒋艳, 赵冉, 张格. 国外开源软件安全治理模式研究及工作建议[J]. 中国信息安全, 2023, 14(3): 7679[5]Synopsys. 2024年开源安全和风险分析报告[EBOL]. [20241201]. https:www.blackduck.comzhcnresourcesanalystreportsopensourcesecurityriskanalysis.html[6]Liang L, Wu X, Deng J, et al. Research on risk analysis and governance measures of opensource components of information system in transportation[J]. Interactive Systems and Applications, 2022 (7): 106110 [7]SLSA. Supplychain levels for software artifacts[EBOL].[20241120]. https:slsa.dev[8]IBM. What is the Log4j vulnerability? [EBOL]. [20241115]. https:www.ibm.comthinktopicslog4j[9]Aqua. SolarWinds attack: play by play and lessons learned[EBOL]. [20230118]. https:www.aquasec.comcloudnativeacademysupplychainsecuritysolarwindsattack