{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T16:07:23Z","timestamp":1784218043828,"version":"3.55.0"},"reference-count":41,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key R&amp;D Program of China","award":["2022YFB3103900"],"award-info":[{"award-number":["2022YFB3103900"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2024,1]]},"DOI":"10.1109\/tdsc.2023.3253572","type":"journal-article","created":{"date-parts":[[2023,3,7]],"date-time":"2023-03-07T19:26:46Z","timestamp":1678217206000},"page":"403-418","source":"Crossref","is-referenced-by-count":23,"title":["Ambush From All Sides: Understanding Security Threats in Open-Source Software CI\/CD Pipelines"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0700-6571","authenticated-orcid":false,"given":"Ziyue","family":"Pan","sequence":"first","affiliation":[{"name":"Zhejiang University, Hangzhou, Zhejiang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2899-6121","authenticated-orcid":false,"given":"Wenbo","family":"Shen","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, Zhejiang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xingkai","family":"Wang","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, Zhejiang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2899-0117","authenticated-orcid":false,"given":"Yutian","family":"Yang","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, Zhejiang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0178-0171","authenticated-orcid":false,"given":"Rui","family":"Chang","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, Zhejiang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3382-798X","authenticated-orcid":false,"given":"Yao","family":"Liu","sequence":"additional","affiliation":[{"name":"University of South Florida, Tampa, FL, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1175-2753","authenticated-orcid":false,"given":"Chengwei","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1969-2591","authenticated-orcid":false,"given":"Kui","family":"Ren","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, Zhejiang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSA-C.2019.00026"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833803"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3529320.3529325"},{"key":"ref4","doi-asserted-by":"crossref","DOI":"10.31274\/td-20240329-487","article-title":"Making secure software insecure without changing its code: The possibilities and impacts of attacks on the devops pipeline","author":"Pecka","year":"2022"},{"key":"ref5","article-title":"CI\/CD","year":"2021"},{"key":"ref6","article-title":"Gitstar ranking - top github users and repositories","year":"2022"},{"key":"ref7","article-title":"How we found vulnerabilities in github actions ci\/cd pipelines - cycode","year":"2022"},{"key":"ref8","article-title":"Exploiting continuous integration (CI) and automated build systems","year":"2017"},{"key":"ref9","article-title":"Attacking CI\/CD tools the crown jewels \u2014 series 1","author":"Chinnipilli","year":"2020"},{"key":"ref10","article-title":"A hackerone employees github personal access token exposed in travis ci build logs","author":"Vyshnevskyi","year":"2017"},{"key":"ref11","article-title":"CI knew there would be bugs here\u201d \u2014 exploring continuous integration services as a bug bounty hunter","author":"Justin Gardner","year":"2019"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/SANER48275.2020.9054818"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/2786805.2786850"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2017.8115619"},{"key":"ref15","article-title":"Features \u2022 github actions","year":"2022"},{"key":"ref16","article-title":"Understanding github actions","year":"2022"},{"key":"ref17","article-title":"atlassian\/gajira-create","year":"2022"},{"key":"ref18","article-title":"Github rest api - github docs","year":"2001"},{"key":"ref19","article-title":"Finding and customizing actions - github docs","year":"2022"},{"key":"ref20","article-title":"Github marketplace \u00b7 actions to improve your workflow","year":"2022"},{"key":"ref21","article-title":"NVD - vulnerabilities","year":"2022"},{"key":"ref22","article-title":"CVE - CVE","year":"2022"},{"key":"ref23","article-title":"Github checkout script","year":"2021"},{"key":"ref24","article-title":"Commit, tag, and push your action to github","year":"2021"},{"key":"ref25","article-title":"super linter","year":"2021"},{"key":"ref26","article-title":"2020 United States federal government data breach","year":"2021"},{"key":"ref27","article-title":"Make - gnu project - free software foundation","year":"2022"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/358198.358210"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-67383-7_2"},{"key":"ref30","article-title":"Codeql - github","year":"2022"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev.2018.00039"},{"key":"ref32","article-title":"Continuous intrusion: Why CI tools are an attackers best friends","author":"Mittal","year":"2015"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP52600.2021.00037"},{"key":"ref34","first-page":"34","article-title":"Managing security work in scrum: Tensions and challenges","volume":"2017","author":"T\u00fcrpe","year":"2017","journal-title":"SecSE, ESORICS"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2019.00044"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/MSR52588.2021.00054"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2017.2685629"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3359981"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3236033"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2017.62"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-019-09695-9"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/10400751\/10061526.pdf?arnumber=10061526","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,15]],"date-time":"2024-10-15T23:05:27Z","timestamp":1729033527000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10061526\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,1]]},"references-count":41,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2023.3253572","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,1]]}}}