Dagstuhl Seminar 27241
Software Supply Chain Security
( Jun 13 – Jun 18, 2027 )
Permalink
Organizers
- Benoit Baudry (University of Montreal, CA)
- Mira Mezini (TU Darmstadt, DE)
- Martin Monperrus (KTH Royal Institute of Technology - Stockholm, SE)
- Laurie Williams (North Carolina State University - Raleigh, US)
Contact
- Andreas Dolzmann (for scientific matters)
- Susanne Bach-Bernhard (for administrative matters)
Modern software is built on a vast web of reused components: packages, libraries, build tools, and runtime environments that collectively form the software supply chain. This model of development accelerates delivery and reduces duplicated effort, but it also expands the attack surface in ways that are difficult to observe and control. Supply chain attacks have grown nearly exponentially since 2019. High-profile incidents such as Log4Shell, the xz-utils backdoor, and the CrowdStrike faulty update have demonstrated that a single compromised or defective component can cascade across millions of systems and cause billions of dollars in damage. Humans, as maintainers and contributors, are them-selves links in the chain and an established attack vector through social engineering and insider threats.
This Dagstuhl Seminar aims to bring together leading academic researchers and senior industry practi-tioners to consolidate the state of the field, identify open problems, and define a shared research agen-da for the next five to ten years.
The seminar will discuss the most pressing open questions and prioritizes directions for future work. Second, it is intended to lay the groundwork for a community-driven benchmark suite, including cu-rated datasets of vulnerable dependencies and standardized evaluation formats for tools such as soft-ware bill of materials (SBOM) generators. Third, it is expected to catalyze new collaborations across the software engineering and security communities, and between academic and industrial participants.
Discussion topics will span the full breadth of the supply chain problem space, including:
- Software provenance and software bill of materials (SBOM): tracking component origins and enabling rapid vulnerability identification.
- Attack vectors and defenses: methods by which adversaries compromise dependencies, devel-oper infrastructure, and build pipelines.
- Software integrity and reproducibility: verifying that deployed software matches its source and that build infrastructure has not been infiltrated.
- Automated vulnerability discovery and remediation: static analysis, software composition analysis, and program repair techniques.
- Human and social factors: insider threats, social engineering, and the role of security culture in organizational resilience.
- Third-party dependency management: tracking known vulnerabilities across open-source and commercial libraries and prioritizing remediation.
- Container and infrastructure security: securing the runtime environments in which software operates.
- AI-enabled software supply chains: integrity, provenance, and security challenges introduced by pre-trained models and AI-generated code.
- Regulatory frameworks and compliance: meeting obligations imposed by emerging standards and government mandates.
- Domain-specific challenges: understanding how threat models and compliance requirements differ across healthcare, finance, and critical infrastructure.
Benoit Baudry, Mira Mezini, Martin Monperrus, and Laurie Williams
Classification
- Cryptography and Security
- Software Engineering
Keywords
- software engineering
- cybersecurity

Creative Commons BY 4.0
