logo

NDSS 2025 – Attributing Open-Source Contributions Is Critical But Difficult

ID: d4b4490a-2228-5a61-a83c-3e755862f5a9

STIX ID: report--d4b4490a-2228-5a61-a83c-3e755862f5a9

Feed Name: Security Boulevard

Date Published: 2026-01-23

Date Updated: 2026-04-22

Author: Marc Handelman

...
...

A highlight of an NDSS 2025 paper examines how manipulable Git author metadata and GitHub’s email handling enable contributor spoofing and trust manipulation in critical open-source projects. The mixed-method study of 50,328 GitHub projects shows 85.9% are susceptible to workflow abuse and identifies 573,043 emails that could be hijacked to claim historic contributions; commit signing is uncommon (95.4% of users never sign, 72.1% of projects have no signed commits), and existing guidance often overlooks GitHub-specific email risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.