{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T03:16:44Z","timestamp":1783999004799,"version":"3.55.0"},"reference-count":74,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2022,11,23]],"date-time":"2022-11-23T00:00:00Z","timestamp":1669161600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,11,23]],"date-time":"2022-11-23T00:00:00Z","timestamp":1669161600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"TruBlo","award":["Grant Agreement Number 957228"],"award-info":[{"award-number":["Grant Agreement Number 957228"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2023,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The worldwide software ecosystem is a trust-rich part of the world. Throughout the software life cycle, software engineers, end-users, and other stakeholders collaboratively place their trust in major hubs in the ecosystem, such as package managers, repository services, and software components. However, as our reliance on software grows, this trust is frequently violated by bad actors and crippling vulnerabilities in the software supply chain. This study aims to define software trust in the worldwide SECO, that is, to determine what signifies a trustworthy system, actor, or hub. We conduct a systematic literature review on the concept of trust in the software ecosystem. We acknowledge that trust is something between two actors in the software ecosystem, and we examine what role trust plays in the relationships between end-users and (1) software products, (2) package managers, (3) software producing organizations, and (4) software engineers. Two major findings emerged from the systematic literature review. To begin, we define trust in the software ecosystem by examining the definition and characteristics of trust. Second, we provide a list of trust factors that can be used to assemble an overview of software trust. Trust is critical in the communication between actors in the worldwide software ecosystem, particularly regarding software selection and evaluation. With this comprehensive overview of trust, software engineering researchers have a new foundation to understand and use trust to create a trustworthy software ecosystem.<\/jats:p>","DOI":"10.1007\/s10664-022-10238-y","type":"journal-article","created":{"date-parts":[[2022,11,24]],"date-time":"2022-11-24T13:59:35Z","timestamp":1669298375000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":40,"title":["A systematic literature review on trust in the software ecosystem"],"prefix":"10.1007","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8042-3278","authenticated-orcid":false,"given":"Fang","family":"Hou","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Slinger","family":"Jansen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,11,23]]},"reference":[{"issue":"3","key":"10238_CR1","doi-asserted-by":"publisher","first-page":"28","DOI":"10.3390\/systems8030028","volume":"8","author":"GM Alarcon","year":"2020","unstructured":"Alarcon GM, Gibson AM, Walter C, Gamble RF, Ryan TJ, Jessup SA, Boyd BE, Capiola A (2020) Trust Perceptions of Metadata in Open-Source Software: The Role of Performance and Reputation. Systems 8(3):28","journal-title":"Systems"},{"key":"10238_CR2","unstructured":"Amoroso Ed, Nguyen Thu, Weiss Jon, Watson John, Lapiska Pete, Starr Terry (1991) Toward an approach to measuring software trust. In: Proceedings. 1991 IEEE Computer Society Symposium on Research in Security and Privacy, pp 198\u2013198"},{"key":"10238_CR3","first-page":"187","volume":"4.3-4","author":"S Androutsellis-Theotokis","year":"2011","unstructured":"Androutsellis-Theotokis S, Spinellis D, Kechagia M, Gousios G (2011) Open source software: a survey from 10,000 feet. Found Trends Technol Inf Oper Manag 4.3-4:187\u2013347","journal-title":"Found Trends Technol Inf Oper Manag"},{"key":"10238_CR4","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1016\/j.jss.2016.07.027","volume":"121","author":"Deepika Badampudi","year":"2016","unstructured":"Badampudi Deepika, Wohlin Claes, Petersen Kai (2016) Software component decision-making: in-house, OSS, COTS or outsourcing-A systematic literature review. J Syst Software 121:105\u2013124","journal-title":"J Syst Software"},{"key":"10238_CR5","doi-asserted-by":"crossref","unstructured":"Bennett K, Layzell P, Budgen D, Brereton P, Macaulay L, Munro M (2000) Service-based software: the future for flexible software. In: Proceedings seventh Asia-Pacific software engeering conference, APSEC 2000. IEEE, pp 214\u2013221","DOI":"10.1109\/APSEC.2000.896702"},{"key":"10238_CR6","unstructured":"Berander P, Damm LO, Eriksson J, Gorschek T, Henningsson K, J\u00f6nsson P, Wohlin C (2005) Software quality attributes and trade-offs. In: Blekinge Institute of Technology 97.98, p. 19"},{"key":"10238_CR7","doi-asserted-by":"crossref","unstructured":"Bogart C, K\u00e4stner C, Herbsleb J, Thung F (2016) \u2018How to break an API: cost negotiation and community values in three software ecosystems\u2019. In: Proceedings of the 2016 24th ACM SIGSOFT International Symposium on Foundations of Software Engineering, pp. 109\u2013120","DOI":"10.1145\/2950290.2950325"},{"key":"10238_CR8","doi-asserted-by":"crossref","unstructured":"Boyes HA, Norris P, Bryant I, Watson T (2014) Trustworthy Software: lessons from goto fail\u2019& Heart- bleed bugs. In: 9th IET International Conference on System Safety and Cyber Security, pp. 17.","DOI":"10.1049\/cp.2014.0970"},{"key":"10238_CR9","doi-asserted-by":"crossref","unstructured":"Bugiel S, Davi LV, Schulz S (2011) Scalable trust establishment with software reputation, pp 15\u201324. In: Proceedings of the sixth ACM workshop on Scalable trusted computing","DOI":"10.1145\/2046582.2046587"},{"key":"10238_CR10","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1016\/j.dss.2016.08.004","volume":"91","author":"Y Cai","year":"2016","unstructured":"Cai Y, Zhu D (2016) Reputation in an open source software community: Antecedents and impacts. Decis Support Syst 91:103\u2013112","journal-title":"Decis Support Syst"},{"key":"10238_CR11","doi-asserted-by":"publisher","first-page":"144","DOI":"10.1016\/j.jss.2010.09.004","volume":"84.1","author":"E Capra","year":"2011","unstructured":"Capra E, Francalanci C, Merlo F, Rossi-Lamastra C (2011) \u2018Firms\u2019 involvement in Open Source projects: a trade-off between software structural quality and popularity. J Syst Software 84.1:144\u2013161","journal-title":"J Syst Software"},{"key":"10238_CR12","first-page":"377","volume":"17.2","author":"L Catuogno","year":"2017","unstructured":"Catuogno L, Galdi C, Persiano G (2017) Secure dependency enforcement in package management systems. IEEE Trans Dependable Secure Comput 17.2:377\u2013390","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"10238_CR13","doi-asserted-by":"publisher","first-page":"473","DOI":"10.3745\/JIPS.2011.7.3.473","volume":"7.3","author":"JS Challa","year":"2011","unstructured":"Challa JS, Paul A, Dada Y, Nerella V, Srivastava PR, Singh AP (2011) Integrated software quality evaluation: a fuzzy multi-criteria approach. J Inf Process Syst 7.3:473\u2013518","journal-title":"J Inf Process Syst"},{"key":"10238_CR14","doi-asserted-by":"publisher","first-page":"292","DOI":"10.1057\/ejis.1994.34","volume":"3.4","author":"P Chau","year":"1994","unstructured":"Chau P (1994) Selection of packaged software in small businesses. European J Inf Syst 3.4:292\u2013302","journal-title":"European J Inf Syst"},{"key":"10238_CR15","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2815595","volume":"48.2","author":"J-H Cho","year":"2015","unstructured":"Cho J-H, Chan K, Adali S (2015) A survey on trust modeling. ACM Comput Surveys (CSUR) 48.2: 1\u201340","journal-title":"ACM Comput Surveys (CSUR)"},{"key":"10238_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3277666","volume":"51.6","author":"J-H Cho","year":"2019","unstructured":"Cho J-H, Xu S (2019) Stram: measuring the trustworthiness of computer-based systems. ACM Comput Surveys (CSUR) 51.6:1\u201347","journal-title":"ACM Comput Surveys (CSUR)"},{"key":"10238_CR17","unstructured":"Crowston K, Annabi H, Howison J (2003) Defining open source software project success. In: Proceedings of the International Conference on Information Systems (ICIS)"},{"key":"10238_CR18","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1002\/spip.257","volume":"11.2","author":"D Cruz","year":"2006","unstructured":"Cruz D, Wieland T, Ziegler A (2006) Evaluation criteria for free\/open source software products based on project analysis. Software Process: improvement and Practice 11.2:107\u2013122","journal-title":"Software Process: improvement and Practice"},{"key":"10238_CR19","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1177\/0170840601222004","volume":"22.2","author":"TK Das","year":"2001","unstructured":"Das TK, Teng B-S (2001) Trust, control, and risk in strategic alliances: an integrated framework. Organization studies 22.2:251\u2013283","journal-title":"Organization studies"},{"key":"10238_CR20","doi-asserted-by":"crossref","unstructured":"Decan A, Mens T, Constantinou E (2018) On the impact of security vulnerabilities in the npm package dependency network. In: Proceedings of the 15th international conference on mining software repositories, pp 181\u2013191","DOI":"10.1145\/3196398.3196401"},{"key":"10238_CR21","doi-asserted-by":"publisher","first-page":"67","DOI":"10.1109\/MS.2011.93","volume":"28.5","author":"V Del Bianco","year":"2011","unstructured":"Del Bianco V, Lavazza L, Morasca S, Taibi D (2011) A survey on open source software trustworthiness. IEEE Softw 28.5:67\u201375","journal-title":"IEEE Softw"},{"key":"10238_CR22","doi-asserted-by":"crossref","unstructured":"Donohue SK, Dugan JB, Brown CL (2005) Is my software good enough to release?-A probabilistic assessment. In: 29th annual IEEE\/NASA Software engineering workshop, pp 5\u201313","DOI":"10.1109\/SEW.2005.30"},{"key":"10238_CR23","doi-asserted-by":"crossref","unstructured":"Duan R, Alrawi O, Kasturi RP, Elder R, Saltaformaggio B, Lee W (2021) Towards measuring supply chain attacks on package managers for interpreted languages. In: Network and distributed systems security (NDSS) symposium 2021","DOI":"10.14722\/ndss.2021.23055"},{"key":"10238_CR24","doi-asserted-by":"crossref","unstructured":"Ellison R, Nichols W, Woody C (2016) Measuring software assurance. In: 2016 IEEE 40th Annual Computer Software and Applications Conference (COMPSAC), vol 2, pp 359\u2013364","DOI":"10.1109\/COMPSAC.2016.231"},{"key":"10238_CR25","doi-asserted-by":"crossref","unstructured":"Gefen D, Keil M (1996) Developer responsiveness and perceived usefulness. In: Academy of management proceedings, Academy of management Briarcliff Manor, NY 10510. vol 1996, pp 313\u2013317","DOI":"10.5465\/ambpp.1996.4980832"},{"key":"10238_CR26","doi-asserted-by":"publisher","first-page":"285","DOI":"10.1080\/10580530.2015.1079999","volume":"32.4","author":"AH Ghapanchi","year":"2015","unstructured":"Ghapanchi AH, Tavana M (2015) A longitudinal study of the impact of open source software project characteristics on positive outcomes. Inf Syst Manag 32.4:285\u2013298","journal-title":"Inf Syst Manag"},{"key":"10238_CR27","doi-asserted-by":"crossref","unstructured":"Godse M, Mulik S (2009) An approach for selecting software-as-a-service (SaaS) product. In: 2009 IEEE international conference on cloud computing. IEEE, pp 155\u2013158","DOI":"10.1109\/CLOUD.2009.74"},{"key":"10238_CR28","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1016\/j.dss.2014.12.005","volume":"70","author":"S Goode","year":"2015","unstructured":"Goode S, Lin C, Tsai JC, Jiang JJ (2015) Rethinking the role of security in client satisfaction with software-as-a-service (SaaS) providers. Decision Support Syst 70:73\u201385","journal-title":"Decision Support Syst"},{"key":"10238_CR29","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1109\/COMST.2000.5340804","volume":"3.4","author":"T Grandison","year":"2000","unstructured":"Grandison T, Sloman M (2000) A survey of trust in internet applications. IEEE Commun Surveys Tutorials 3.4:2\u201316","journal-title":"IEEE Commun Surveys Tutorials"},{"key":"10238_CR30","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1007\/s10676-010-9255-1","volume":"13.1","author":"FS Grodzinsky","year":"2011","unstructured":"Grodzinsky FS, Miller KW, Wolf MJ (2011) Developing artificial agents worthy of trust: would you buy a used car from this artificial agent? Ethics Inf Technol 13.1:17\u201327","journal-title":"Ethics Inf Technol"},{"key":"10238_CR31","doi-asserted-by":"crossref","unstructured":"Guo G, Zhang J, Thalmann D, Basu A, Yorke-Smith N (2014) From ratings to trust: an empirical study of implicit trust in recommender systems. In: Proceedings of the 29th annual acm symposium on applied computing, pp 248\u2013253","DOI":"10.1145\/2554850.2554878"},{"key":"10238_CR32","doi-asserted-by":"publisher","first-page":"180","DOI":"10.1287\/mnsc.1070.0748","volume":"54.1","author":"S Haefliger","year":"2008","unstructured":"Haefliger S, Von Krogh G, Spaeth S (2008) Code reuse in open source software. Manag Sci 54.1:180\u2013193","journal-title":"Manag Sci"},{"key":"10238_CR33","doi-asserted-by":"crossref","unstructured":"Haenni N, Lungu M, Schwarz N, Nierstrasz O (2013) Categorizing developer information needs in software ecosystems. In: Proceedings of the 2013 international workshop on ecosystem architectures, pp 1\u20135","DOI":"10.1145\/2501585.2501586"},{"key":"10238_CR34","doi-asserted-by":"crossref","unstructured":"Haenni N, Lungu M, Schwarz N, Nierstrasz O (2014) A quantitative analysis of developer information needs in software ecosystems. In: Proceedings of the 2014 European conference on software architecture workshops, pp 1\u20136","DOI":"10.1145\/2501585.2501586"},{"key":"10238_CR35","doi-asserted-by":"crossref","unstructured":"He J, Hou H, Song Q, Hao K (2009) Reference model of trustworthy proof for trusted components. In: 2009 second international conference on future information technology and management engineering. IEEE, 136\u2013139","DOI":"10.1109\/FITME.2009.39"},{"key":"10238_CR36","doi-asserted-by":"publisher","first-page":"268","DOI":"10.1016\/j.jsis.2008.10.001","volume":"17.4","author":"A Heiskanen","year":"2008","unstructured":"Heiskanen A, Newman M, Eklin M (2008) Control, trust, power, and the dynamics of information system outsourcing relationships: a process study of contractual software development. J Strategic Inf Syst 17.4:268\u2013286","journal-title":"J Strategic Inf Syst"},{"key":"10238_CR37","doi-asserted-by":"crossref","unstructured":"Hejderup J, van Deursen A, Gousios G (2018) Software ecosystem call graph for dependency management. In: 2018 IEEE\/ACM 40th international conference on software engineering: new ideas and emerging technologies results (ICSE-NIER). IEEE, pp 101\u2013104","DOI":"10.1145\/3183399.3183417"},{"key":"10238_CR38","doi-asserted-by":"crossref","unstructured":"Hillebrand C, Coetzee M (2013) Towards reputation-as-a-service. In: 2013 Information Security for South Africa. IEEE, pp 1\u20138","DOI":"10.1109\/ISSA.2013.6641047"},{"key":"10238_CR39","doi-asserted-by":"crossref","unstructured":"Hong H, Chang-hui W, Ben W (2011) Research on management scheme of trusted application software. In: 2011 international conference on network computing and information security. Vol. 1. IEEE, pp. 311\u2013315","DOI":"10.1109\/NCIS.2011.70"},{"key":"10238_CR40","first-page":"115","volume":"17.1","author":"JA Hoxmeier","year":"2000","unstructured":"Hoxmeier JA (2000) Software preannouncements and their impact on customers perceptions and vendor reputation. J Manag Inf Syst 17.1:115\u2013139","journal-title":"J Manag Inf Syst"},{"key":"10238_CR41","doi-asserted-by":"crossref","unstructured":"Hunter P, Walli S (2013) The rise and evolution of the open source software foundation. In: International Free and Open Source Software Law Review 5, p. 31","DOI":"10.5033\/ifosslr.v5i1.64"},{"key":"10238_CR42","doi-asserted-by":"crossref","unstructured":"Immonen A, Palviainen M (2007) Trustworthiness evaluation and testing of open source components. In: Seventh international conference on quality software (QSIC 2007). IEEE, pp 316\u2013321","DOI":"10.1109\/QSIC.2007.4385514"},{"key":"10238_CR43","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1145\/1498765.1498787","volume":"52.4","author":"D Jackson","year":"2009","unstructured":"Jackson D (2009) A direct path to dependable software. Commun ACM 52.4:78\u201388","journal-title":"Commun ACM"},{"key":"10238_CR44","doi-asserted-by":"publisher","first-page":"555","DOI":"10.1016\/j.infsof.2008.09.003","volume":"51.3","author":"AS Jadhav","year":"2009","unstructured":"Jadhav AS, Sonar RM (2009) Evaluating and selecting software packages: a review. Information and software technology 51.3:555\u2013563","journal-title":"Information and software technology"},{"key":"10238_CR45","doi-asserted-by":"publisher","first-page":"1394","DOI":"10.1016\/j.jss.2011.03.034","volume":"84.8","author":"AS Jadhav","year":"2011","unstructured":"Jadhav AS, Sonar RM (2011) Framework for evaluation and selection of the software packages: a hybrid knowledge based system approach. J Syst Software 84.8:1394\u20131407","journal-title":"J Syst Software"},{"key":"10238_CR46","doi-asserted-by":"publisher","first-page":"1508","DOI":"10.1016\/j.infsof.2014.04.006","volume":"56.11","author":"S Jansen","year":"2014","unstructured":"Jansen S (2014) Measuring the health of open source software ecosystems: beyond the scope of project health. Inf Software Technol 56.11:1508\u20131519","journal-title":"Inf Software Technol"},{"key":"10238_CR47","first-page":"31","volume":"19.2","author":"S Koch","year":"2008","unstructured":"Koch S, Neumann C (2008) Exploring the effects of process characteristics on products quality in open source software development. J Data Manag (JDM) 19.2:31\u201357","journal-title":"J Data Manag (JDM)"},{"key":"10238_CR48","doi-asserted-by":"crossref","unstructured":"Kula RG, German DM, Ishio T, Inoue K (2015) Trusting a library: A study of the latency to adopt the latest maven release. In: 2015 IEEE 22nd International Conference on Software Analysis, Evolution, and reengineering (SANER). IEEE, pp 520\u2013524","DOI":"10.1109\/SANER.2015.7081869"},{"key":"10238_CR49","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1016\/j.elerap.2010.07.001","volume":"10.1","author":"IK Lai","year":"2011","unstructured":"Lai IK, Tong VW, Lai DC (2011) Trust factors influencing the adoption of internet-based interorganizational systems. Electr Commerce Res Appl 10.1:85\u201393","journal-title":"Electr Commerce Res Appl"},{"issue":"4","key":"10238_CR50","doi-asserted-by":"publisher","first-page":"559","DOI":"10.1109\/TSE.2010.2","volume":"36","author":"N Limam","year":"2010","unstructured":"Limam N, Boutaba R (2010) Assessing software service quality and trustworthiness at selection time. IEEE Trans Software Eng 36(4):559\u2013574","journal-title":"IEEE Trans Software Eng"},{"key":"10238_CR51","unstructured":"Liu X, Iyer B (2007) Design architecture, developer networks and performance of open source software projects. In: International Conference on Information Systems 2007 Proceedings, p. 90"},{"key":"10238_CR52","doi-asserted-by":"publisher","first-page":"1294","DOI":"10.1016\/j.jss.2012.12.026","volume":"86.5","author":"K Manikas","year":"2013","unstructured":"Manikas K, Hansen KM (2013) Software ecosystems\u2013a systematic literature review. J Syst Software 86.5:1294\u20131306","journal-title":"J Syst Software"},{"key":"10238_CR53","first-page":"329","volume":"7","author":"DH McKnight","year":"2005","unstructured":"McKnight DH (2005) Trust in information technology. Blackwell Encyclopedia Manag 7:329\u2013331","journal-title":"Blackwell Encyclopedia Manag"},{"key":"10238_CR54","first-page":"1","volume":"2.2","author":"DH Mcknight","year":"2011","unstructured":"Mcknight DH, Carter M, Thatcher JB, Clay PF (2011) Trust in a specific technology: an investigation of its components and measures. ACM Trans Manag Inf Sys (TMIS) 2.2:1\u201325","journal-title":"ACM Trans Manag Inf Sys (TMIS)"},{"key":"10238_CR55","doi-asserted-by":"publisher","first-page":"895","DOI":"10.1016\/j.jss.2011.11.010","volume":"85.4","author":"V Midha","year":"2012","unstructured":"Midha V, Palvia P (2012) Factors affecting the success of Open Source Software. J Syst Software 85.4:895\u2013905","journal-title":"J Syst Software"},{"key":"10238_CR56","doi-asserted-by":"publisher","first-page":"309","DOI":"10.1145\/567793.567795","volume":"11.3","author":"A Mockus","year":"2002","unstructured":"Mockus A, Fielding RT, Herbsleb JD (2002) Two case studies of open source software development: apache and mozilla. ACM Trans Software Eng Method (TOSEM) 11.3:309\u2013346","journal-title":"ACM Trans Software Eng Method (TOSEM)"},{"key":"10238_CR57","doi-asserted-by":"publisher","first-page":"471","DOI":"10.1007\/s10664-007-9040-x","volume":"12.5","author":"P Mohagheghi","year":"2007","unstructured":"Mohagheghi P, Conradi R (2007) Quality, productivity and economic benefits of software reuse: a review of industrial studies. Empirical Software Eng 12.5:471\u2013516","journal-title":"Empirical Software Eng"},{"key":"10238_CR58","doi-asserted-by":"publisher","first-page":"134","DOI":"10.1016\/j.jnca.2016.04.018","volume":"69","author":"F Moyano","year":"2016","unstructured":"Moyano F, Fernandez-Gago C, Lopez J (2016) A model-driven approach for engineering trust and reputation into software services. J Netw Comput Appl 69:134\u2013151","journal-title":"J Netw Comput Appl"},{"key":"10238_CR59","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1109\/MS.2004.1259211","volume":"21.1","author":"JS Norris","year":"2004","unstructured":"Norris JS (2004) Mission-critical development with open source software: lessons learned. IEEE Softw 21.1:42\u201349","journal-title":"IEEE Softw"},{"key":"10238_CR60","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1016\/j.infoandorg.2007.05.001","volume":"17.3","author":"N Pollock","year":"2007","unstructured":"Pollock N, Williams R (2007) Technology choice and its performance: towards a sociology of software package procurement. Inf Org 17.3:131\u2013161","journal-title":"Inf Org"},{"key":"10238_CR61","doi-asserted-by":"crossref","unstructured":"Qian H, Zhu X, Ma J, Cao X (2009) Quality process-oriented software credibility measurement and assessment. In: 2009 international conference on computational intelligence and software engineering. IEEE, pp 1\u20136","DOI":"10.1109\/CISE.2009.5364824"},{"key":"10238_CR62","doi-asserted-by":"publisher","first-page":"256","DOI":"10.1016\/j.jss.2016.12.006","volume":"125","author":"Y Roumani","year":"2017","unstructured":"Roumani Y, Nwankpa JK, Roumani YF (2017) Adopters trust in enterprise open source vendors: an empirical examination. J Syst Software 125:256\u2013270","journal-title":"J Syst Software"},{"key":"10238_CR63","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.advengsoft.2013.12.001","volume":"69","author":"M Sarrab","year":"2014","unstructured":"Sarrab M, Rehman OMH (2014) Empirical study of open source software selection for adoption, based on software quality characteristics. Adv Eng Software 69:1\u201311","journal-title":"Adv Eng Software"},{"key":"10238_CR64","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1016\/S0065-2458(06)69005-0","volume":"69","author":"W Scacchi","year":"2007","unstructured":"Scacchi W (2007) Free\/open source software development: recent research results and methods. Adv Comput 69:243\u2013295","journal-title":"Adv Comput"},{"key":"10238_CR65","unstructured":"Schuur Hvd, Jansen S, Brinkkemper S (2011) The power of propagation: on the role of software operation knowledge within software ecosystems. In: Proceedings of the international conference on management of emergent digital ecosystems, pp 76\u201384"},{"key":"10238_CR66","doi-asserted-by":"publisher","first-page":"364","DOI":"10.1016\/j.dss.2011.09.003","volume":"52.2","author":"R Sen","year":"2012","unstructured":"Sen R, Singh SS, Borle S (2012) Open source software success: measures and analysis. Decision Support Syst 52.2:364\u2013372","journal-title":"Decision Support Syst"},{"key":"10238_CR67","doi-asserted-by":"crossref","unstructured":"Van Den Berk I, Jansen S, Luinenburg L (2010) Software ecosystems: a software ecosystem strategy assessment model. In: Proceedings of the fourth european conference on software architecture: companion volume, pp 127\u2013134","DOI":"10.1145\/1842752.1842781"},{"key":"10238_CR68","unstructured":"Vargas EL, Aniche M, Treude C, Bruntink M, Gousios G (2020) Selecting third-party libraries: the practitioners\u2019 perspective. In: Proceedings of the 28th ACM joint meeting on european software engineering conference and symposium on the foundations of software engineering."},{"key":"10238_CR69","doi-asserted-by":"publisher","first-page":"60199","DOI":"10.1109\/ACCESS.2019.2892518","volume":"7","author":"B Wang","year":"2019","unstructured":"Wang B, Chen Y, Zhang S, Wu H (2019) Updating model of software component trustworthiness based on users feedback. IEEE Access 7:60199\u201360205","journal-title":"IEEE Access"},{"key":"10238_CR70","doi-asserted-by":"crossref","unstructured":"Wang H (2011) TRUSTIE: design of a trustworthy software production environment. In: 2011IEEE 10th international conference on trust, security and privacy in computing and communications. IEEE, pp 3\u20134","DOI":"10.1109\/TrustCom.2011.2"},{"key":"10238_CR71","doi-asserted-by":"crossref","unstructured":"Wang H, Yin G, Li X, Li X (2015) TRUSTIE: a software development platform for crowdsourcing. In: Crowdsourcing. Springer, pp 165\u2013190","DOI":"10.1007\/978-3-662-47011-4_10"},{"key":"10238_CR72","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.infsof.2015.06.002","volume":"67","author":"J Wang","year":"2015","unstructured":"Wang J, Shih PC, Wu Y, Carroll JM (2015) Comparative case studies of open source software peer review practices. Inf Software Technol 67:1\u201312","journal-title":"Inf Software Technol"},{"key":"10238_CR73","doi-asserted-by":"crossref","unstructured":"Yan Z (2008) A comprehensive trust model for component software. In: Proceedings of the 4th international workshop on security, privacy and trust in pervasive and ubiquitous computing, pp 1\u20136","DOI":"10.1145\/1387329.1387330"},{"key":"10238_CR74","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1016\/j.ins.2011.07.046","volume":"191","author":"M-X Zhu","year":"2012","unstructured":"Zhu M-X, Luo X-X, Chen X-H, Wu DD (2012) A non-functional requirements tradeoff model in trustworthy software. Inf Sci 191:61\u201375","journal-title":"Inf Sci"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-022-10238-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-022-10238-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-022-10238-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,10]],"date-time":"2023-01-10T04:40:31Z","timestamp":1673325631000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-022-10238-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,23]]},"references-count":74,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2023,1]]}},"alternative-id":["10238"],"URL":"https:\/\/doi.org\/10.1007\/s10664-022-10238-y","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,23]]},"assertion":[{"value":"9 September 2022","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 November 2022","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Author Slinger Jansen is an Associate Editor at the Empirical Software Engineering Journal.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"<!--Emphasis Type='Bold' removed-->Conflict of Interests"}}],"article-number":"8"}}