NDSS 2025 – Attributing Open-Source Contributions Is Critical But Difficult
ID: d4b4490a-2228-5a61-a83c-3e755862f5a9
STIX ID: report--d4b4490a-2228-5a61-a83c-3e755862f5a9
Feed Name: Security Boulevard
A highlight of an NDSS 2025 paper examines how manipulable Git author metadata and GitHub’s email handling enable contributor spoofing and trust manipulation in critical open-source projects. The mixed-method study of 50,328 GitHub projects shows 85.9% are susceptible to workflow abuse and identifies 573,043 emails that could be hijacked to claim historic contributions; commit signing is uncommon (95.4% of users never sign, 72.1% of projects have no signed commits), and existing guidance often overlooks GitHub-specific email risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
